A massive leak targeting the Ministry of Culture
The French Ministry of Culture is among the latest victims of a major data leak affecting the public administration. According to information gathered by the BreachHistory platform, no fewer than 45,362 records of agents have reportedly been exposed following a compromise whose details were published on a specialized forum.
The claim, attributed to a threat actor identified by the pseudonym "misere", remains unofficially verified by French authorities at this time. However, the volume of data involved and the nature of the exposed information raise serious concerns about the security of government information systems.
Highly sensitive data
The exfiltrated data would include sensitive personal and professional information, among which:
- Full names (first and last names) of the agents
- Email addresses personal and professional
- Phone numbers
- Exact postal addresses
- Positions and departments of assignment
This type of data, seemingly innocuous when taken in isolation, becomes extremely dangerous once aggregated. It provides cybercriminals with a prime material to conduct targeted phishing campaigns, social engineering, or even extortion against the affected officials.
A context of widespread cyberattacks against the French State
This leak occurs in a particularly tense context for French government cybersecurity. In March 2026, a threat actor named HexDex had already published on a forum the data of about 60,000 agents of the French State, affecting several ministries. This group had presented the leak as a "welcome gift," signaling a desire to make a name for itself in the cybercriminal community.
The governmental domains most affected by this previous wave included:
| Ministry / Domain | Relevant Records |
|---|---|
| @developpement-durable.gouv.fr | 9,466 |
| @justice.fr | 5,823 |
| @dgfip.finances.gouv.fr | 4,804 |
| @interieur.gouv.fr | 4,617 |
| @intradef.gouv.fr (Defense) | 3,164 |
At the same time, the ANTS (National Agency for Secure Documents) confirmed in April 2026 a breach affecting up to 19 million French citizens via its portal ants.gouv.fr, in what constitutes one of the largest data exposures in the French public sector.
Concrete risks for the affected agents
The exposure of data from 45,362 agents of the Ministry of Culture should not be underestimated. Cybersecurity experts warn of several risk scenarios:
- Personalized phishing: Fraudulent emails impersonating the administration to extract credentials or banking information.
- Smishing: Malicious SMS exploiting knowledge of the victim's name and position to gain credibility.
- Reconnaissance for targeted attack: Information on roles and departments allows the identification of high-value targets for subsequent attacks.
- Identity theft: The combination of names, addresses, and phone numbers facilitates administrative fraud.
French authorities under pressure
In the face of the increasing number of these incidents, French cybersecurity organizations are mobilized. The ANSSI (National Cybersecurity Agency) and the CNIL (National Commission on Informatics and Liberty) are systematically engaged as part of the procedures mandated by the GDPR and the Code of Criminal Procedure.
The Paris prosecutor's office has also opened several investigations aimed at identifying those responsible for these leaks. French law reminds us that the distribution, purchase, or sale of stolen data constitutes a criminal offense severely punished.
Recommendations for affected agents
If you are an agent of the Ministry of Culture, here are the recommended precautionary measures:
- Monitor your communications: Be particularly vigilant against unexpected emails or SMS, even if they seem to come from the administration.
- Never disclose credentials, passwords, or banking information via email or phone.
- Enable two-factor authentication (2FA) on all your accounts, especially professional ones.
- Report any suspicious message to your IT department and the cybermalveillance.gouv.fr platform.
The claim of this leak remains unofficially verified to date. CyberBar.fr will continue to monitor this case and publish any updates as soon as they become available.
Sources: