Cybersecurity & Regulatory Governance  ·  17 August 2026

No Mention From France

Five breaches, two ministries hit twice, and a regulatory clock the state set for itself and still hasn't beaten.
By Alan Wright  ·  The Haunted Lighthouse Limited  ·  Peel, Isle of Man

On 12 August 2026, someone using the handle "ZeroBytes" listed a database on PwnForums and, almost as an aside, complained that France hadn't said a word about it. Five days later the French Ministry of the Economy and Finance confirmed the breach: 678,000 individuals and professionals, tax data including reference income and withholding rates, and for businesses, company names and SIREN numbers. Cadastral records, addresses and property sizes, were also accessed. The attacker's own line, paraphrased from the forum post, was that they weren't bothering to finish the extraction because it was tedious, and that as usual there'd be no acknowledgement from the French state.

That complaint is worth sitting with, because it's wrong in an interesting way. France did eventually say something, on schedule, in the standard format: DGFiP notified CNIL, shut down the affected access points, brought in ANSSI, promised letters next week. Every box ticked. What ZeroBytes was actually describing, without quite having the vocabulary for it, is the gap between disclosure as a compliance ritual and disclosure as something that changes what happens next. Trace the same eight months backward and this DGFiP disclosure is the fifth major breach of a French government system, not the fourth, and it lands inside a pattern where two ministries were each hit twice, and where the specific control gap behind three of the five incidents was named out loud, on the record, twice before it recurred a third time.


The five, in order

Ministry of the Interior, breach began end of November 2025, disclosed 17 December. Attackers compromised several police officers' inboxes at the Place Beauvau ministry (roughly 300,000 employees) and, searching by keyword, found a password exchanged in plain text between two agents. That credential got them into a police applications portal that had no second-factor protection. Of the roughly 150 police applications reachable from it, the suspect accessed seven, among them TAJ, the criminal records database, and FPR, the wanted-persons file, along with an Interpol record. A hacking group claimed 16 million people's data had been stolen; the ministry's own later accounting, given to the Senate, put confirmed extraction at 72 TAJ files, 23 FPR files, and one Interpol file. Interior Minister Laurent Nuñez told press the intrusion did not endanger citizens' safety. A 22-year-old suspect was subsequently arrested and placed in pre-trial detention.

Senate hearing, 13 January 2026. A month on, Nuñez appeared before the Senate's law commission to account for the breach. Senator Laurence Harribey put it plainly: even the Senate's own JULIA accounts run on two-factor authentication, so what was going on inside the ministry beforehand. Nuñez didn't dispute the gap, he laid out the scale instead: a thousand information systems, 300,000 agents, second-factor rollout happening gradually because, in his words, you can't move from a password to double authentication "with a wave of a magic wand." He committed to generalising it across the ministry's applications going forward, alongside password resets and the deletion of roughly a thousand dormant accounts. It's a specific, dated, on-the-record commitment, and also a specific, dated, on-the-record admission that the timeline for it was going to be measured in ministry-wide rollout terms, not weeks.

France Travail, fine announced 22 January 2026, breach dated Q1 2024. Nine days after Nuñez's Senate appearance, CNIL fined the employment agency €5 million for GDPR Article 32 failures tied to a 2024 breach that exposed roughly 43 million people, current and former jobseekers going back twenty years. Attackers social-engineered CAP EMPLOI advisers into handing over credentials, and CNIL's decision specifically found the authentication protecting those accounts wasn't robust enough. This is a second, independent, regulatory finding naming the identical control gap, in a completely different ministry, within the same fortnight.

FICOBA, breach window 28 January to 13 February 2026. Fifteen days after Nuñez's pledge, six days after the CNIL fine, France's national bank account registry, operated by DGFiP under the Ministry of Economy and Finance, a third ministry entirely, was accessed for sixteen days using a stolen civil servant's credentials. No second factor was in place. 1.2 million of the roughly 300 million records on the register were exposed: IBANs, names, addresses, sometimes tax identifiers. The same gap, named twice already that month in two other parts of government, recurring in a third.

France Titres (ANTS), detected 15 April 2026. ANTS operates under the Interior Ministry, the same ministry Nuñez had testified for in January. An IDOR vulnerability in the ants.gouv.fr API, the platform behind passports, national ID cards and driving licences, let a three-actor group (breach3d, ExtaseHunters, EvilDump) pull data later confirmed by the agency at 11.7 million citizen accounts, though the sellers claimed 18 to 19 million, roughly a third of France's population. This one is a different failure mode, an API vulnerability rather than a credential gap, but it lands inside the same ministerial umbrella Nuñez had just spent a Senate hearing defending.

DGFiP tax and cadastral data, disclosed 17 August 2026. Covered above. 678,000 individuals and professionals, no stated technical root cause beyond "access points," user account credentials confirmed untouched. DGFiP's second confirmed incident of the year, after FICOBA.


Two ministries, twice each

Line these up by ministry and the shape sharpens further. DGFiP was hit in February via FICOBA and again in August via its own tax and cadastral portal: same directorate, two systems, seven months apart. The Interior Ministry was hit directly in December via its own email and law-enforcement systems, then again in April via ANTS, an agency it oversees: same ministerial umbrella, four months apart. Only France Travail, under the Ministry of Labour, is a single incident here. Five breaches, three ministries, and two of the three took a second hit inside the same eight-month window.


Three ministries, one gap, three weeks

The tightest thread in this timeline isn't the repeat ministries, it's the credential-and-MFA gap that shows up in three of the five incidents, named on the public record twice before it produced a third breach. On 13 January, before the Senate, the Interior Minister personally confirmed the exact failure, a sensitive application with no second factor, reachable via a plaintext-shared password, and personally committed to fixing it in his own ministry. On 22 January, CNIL delivered an independent regulatory finding naming the same gap as the root cause of a different ministry's 2024 breach. On 28 January, six days later, DGFiP's bank registry was compromised by precisely that gap: a stolen credential, no second factor, in a third ministry that had no formal reason to have absorbed either warning, because neither the Senate testimony nor the CNIL fine created an obligation reaching outside the ministry it was addressed to. Whatever "strengthened access controls" or "generalising double identification" meant operationally inside the Interior Ministry after 13 January, there's no public evidence it, or anything like it, was treated as a cross-government lesson. It stayed exactly where it was said.


The clock the state set for itself

None of this was a surprise sitting in a drawer somewhere. CNIL adopted a formal recommendation on multi-factor authentication, deliberation n° 2025-019, on 20 March 2025, after a public consultation that had run since March 2024. The recommendation sets MFA as the expected baseline under GDPR Article 32 for sensitive data and high-risk processing; it isn't a blanket legal mandate for every system, but CNIL's own later ruling against France Travail leaned on it directly, citing 2025-019 by number as part of the reasoning for the €5 million fine. By the time the Interior Ministry's portal and FICOBA were breached, the expectation had already existed, in writing, on the regulator's own site, for the better part of a year.

The state's own operational answer to all of this arrived later and slower. ANSSI published its State Cyber Roadmap for 2026-2027 on 9 April 2026, validated by COSINUS, the interministerial digital security steering committee, and its opening page names the 2025 wave of ministerial breaches directly as the reason the roadmap exists. Its MFA timeline: mandatory for all administrator accounts by 31 December 2026, for "SI à enjeux," the systems judged to carry the highest stakes, by 28 February 2027, and for the rest of the state's IT estate by 28 February 2028. Six days after that roadmap was published, ANTS was breached, a different failure mode, an API vulnerability rather than a credential gap, but still inside the same ministry the roadmap was meant to be protecting.

The identity layer underneath most of this is in the same position. ProConnect, the government's professional single sign-on system, and the identity providers that plug into it are themselves officially classified as "SI à enjeux," which puts them on the February 2027 deadline rather than anything sooner. ProConnect's own developer documentation states plainly that most identity providers don't yet support MFA natively, that compliance will arrive gradually through autumn 2026, and that in the meantime ProConnect is covering the gap with an email one-time-passcode as an interim second factor. The system a large share of government services rely on to verify who's logging in is, by its own documentation, still mid-rollout on the exact control that FICOBA and the Interior Ministry portal were breached for lacking.

Put the three together and the sequence reads: a regulator flags the specific gap in March 2025; two ministries are breached through that exact gap by February 2026; the state's own coordinated response, arriving in April 2026, still gives every ministry until the end of that year just to cover administrator accounts, and until 2028 to cover everything else, while the shared identity layer underneath it all runs on an email-OTP stopgap in the meantime. The DGFiP breach this piece opened with landed in August 2026, four months before even the earliest of those deadlines comes due.


What ZeroBytes actually got right

The attacker's complaint about French silence was wrong on the facts, disclosure happened, on schedule, each time, and in the Interior Ministry's case with unusually specific numbers given voluntarily to a Senate committee. But it was reaching for something real: none of these five disclosures functions as an admission that the underlying pattern exists. Each is handled as a discrete, self-contained incident, notified to CNIL, handed to ANSSI or the cybercrime unit, closed, and in one case followed by a genuinely specific ministerial commitment. The pieces to fix it were already public before most of these breaches happened, a CNIL recommendation from March 2025, a named failure mode from a Senate hearing in January 2026, a state roadmap in April. What's missing isn't awareness. It's a timeline where the fix arrives before the next incident rather than governing the one after that.


Sources


Cross-reference: The Theatre Pulldown


Questions about this analysis, or interested in working with The Haunted Lighthouse?
consultancy@haunted.lighthouse.co.im

The Sovereign Auditor covers digital sovereignty, cybersecurity governance, and data protection policy—with particular focus on Isle of Man jurisdiction and Crown Dependency issues.

Support independent analysis. Subscribe directly—or scan on your phone.

Payments via PayPal. Credentials delivered by email. No Substack. No Stripe. No middlemen.