A France Under Cyber Pressure
Since the beginning of 2026, France has been facing an unprecedented wave of cyberattacks and data breaches. Government institutions, healthcare facilities, critical infrastructures: no sector is spared. The pace of incidents is accelerating, and threat actors seem to be deliberately targeting the Hexagon.
January 2026: Four Major Breaches in 72 Hours
Between January 3 and 5, 2026, no less than four major data breaches were claimed on dark web forums:
- NordVPN: API keys and source code were reportedly exfiltrated by an actor named "1011," including Jira tokens and Salesforce keys.
- Doctolib / Vivalto Santé: over 153,000 patient records exposed, including data from the private Miotte hospital (103,082 records) and an ophthalmology practice in Sallanches (49,726 records).
- LAPSUS$ GROUP: the group claimed the exfiltration of 60.9 GB of data from the Ministry of Agriculture, comprising 1,654,111 unique email addresses. The attackers stated: “This is just the beginning of our attacks against France.”
- AXYON: a breach impacting critical infrastructures, with internal documents from EDF, Renault, and elements related to the French Air Force.
This barrage of attacks in just three days immediately alerted the French cybersecurity community to the determination of the attackers.
The National Bank Accounts File Compromised
In February 2026, the Ministry of Economy revealed that an unknown attacker gained access to the government database listing all bank accounts in the country. The attack, which occurred in January, was carried out using stolen credentials.
Although access was quickly restricted after discovery, the attacker managed to view personal information of 1.2 million accounts on a database containing over 300 million. The exposed data includes account numbers, account holder addresses, and tax identification numbers.
The government mobilized specialized agencies and warned account holders about the risks of identity theft and phishing.
Cyberattack on ANTS: The Heart of the French Administration Hit
On April 15, 2026, the National Agency for Secure Documents (ANTS), a platform managing applications for passports, national identity cards, residence permits, and driving licenses, was the victim of a cyberattack.
According to the Ministry of Interior, the breach led to the disclosure of data related to personal and professional accounts on the ants.gouv.fr portal:
- Names, email addresses, dates of birth
- Login credentials and unique account identifiers
- In some cases: postal addresses, places of birth, and phone numbers
However, authorities clarified that the sensitive documents uploaded during administrative procedures (attachments) were not compromised, and the disclosed data do not allow access to user accounts. The exact number of affected individuals has not been communicated. A criminal complaint has been filed with the Paris prosecutor's office.
The National Education Also Struck
Additionally, there was a data breach affecting the Ministry of National Education, which occurred in late 2025 and was revealed in early 2026. An attacker accessed a system connected to the ÉduConnect platform by posing as an authorized staff member. Student accounts were exposed, highlighting the vulnerability of authentication chains in public educational services.
The Immigration Agency Targeted
In early January 2026, a cyberattack also hit the French immigration agency, exposing personal data of foreign residents. This type of breach is particularly sensitive as it can expose vulnerable populations to risks of extortion or harassment.
An Alarming Observation
The table below summarizes the main reported incidents:
| Date | Target | Estimated Volume | Type of Data |
|---|---|---|---|
| Jan 2026 | NordVPN | Source code + API keys | Technical secrets |
| Jan 2026 | Doctolib / Vivalto Santé | 153,000 patients | Medical records |
| Jan 2026 | Ministry of Agriculture | 1.6M emails | Administrative data |
| Jan 2026 | AXYON / EDF / Renault | Not disclosed | Internal documents |
| Jan 2026 | National bank accounts file | 1.2M accounts | Banking and tax data |
| Jan 2026 | Immigration agency | Not disclosed | Data of foreign residents |
| Jan 2026 | National Education / ÉduConnect | Not disclosed | Student accounts |
| Apr 2026 | ANTS (France Titres) | Not disclosed | Identity data |
Recommendations
In light of this proliferation of attacks, security recommendations remain the same but have become more urgent:
- Enable two-factor authentication (2FA) on all sensitive accounts
- Use unique passwords for each service
- Monitor bank statements and administrative accounts
- Beware of phishing emails exploiting these breaches
- Report any incident to the CNIL and the cybermalveillance.gouv.fr portal
France is not an exception in the global landscape, but the concentration and diversity of attacks since January 2026 make it a prime target for cybercriminals and extortion groups. The question of the digital resilience of French public services is now more pressing than ever.