body-container-line-1

Data-rich systems and weak security: why France is a target for cyberattacks

  Sat, 05 Sep 2026
Information Security France has become a major cybercrime target, because its interconnected public systems hold vast amounts of personal data while security gaps and a lack of resources have left vulnerabilities. -  Kacper Pempel/Reuters
SAT, 05 SEP 2026
France has become a major cybercrime target, because its interconnected public systems hold vast amounts of personal data while security gaps and a lack of resources have left vulnerabilities. - © Kacper Pempel/Reuters

“We may be one of the most targeted countries,” says Benoît Grünemwald, a cybersecurity expert with ESET, a Slovakia-based company that provides security services in France, Europe and beyond. “We are in the top five for sure.”

But he is careful not to suggest that France is unique.

“It's not only France that is targeted, it's all countries going digital,” he says. “European countries are going more and more digital, and being digital means having the opportunity to be breached.”

France's political and economic weight make it a target for foreign governments – notably its support for Ukraine, which has drawn attacks linked to Russia.

But attacks are increasingly going after personal data, exploiting systems that are centralised and interconnected, and not always as protected as they should be.

Cracks in the fortress

France's national cybersecurity agency, ANSSI, recorded 3,586 security events in 2025, up from 831 in 2022.

Incidents spiked at 4,386 in 2024, the year Paris hosted the Olympic and Paralympic Games and became a high-profile target for disruption

According to ANSSI's most recent figures, the use of ransomware – when attackers install malware to hold sensitive data or systems hostage until a ransom is paid – has gone down slightly from previous years. Yet data exfiltration – when attackers steal information without necessarily touching the systems themselves – increased significantly.

Attackers continue to exploit vulnerabilities in French systems that were designed for a different way of using computers, Grünemwald says.

“When you move from the fortress model, where all the people physically came to Bercy [the Economy Ministry] to work on a desktop and without access from outside, that model is constantly changing,” he says.

Covid-19 accelerated a shift in how systems are used and accessed.

“With Covid, we had the necessity to have some people working from home. And so the doors, in many ways, were opened, but with not enough budget or resources to secure them,” Grünemwald says, referring to remote access points into systems and databases that lack basic protections like two-factor authentication.

“These are basic things, which are not fulfilled. So there is an issue.”

Podcast: Working from home in France

'Easy to hack'

Work habits are changing, as are the demands for collaboration, as different parts of government increasingly need to share information.

ANSSI's 2025 annual report says the education and healthcare sectors, as well as ministries and local government, experienced the large majority of known incidents because of the sheer number of organisations operating in them.

But private entities may be less likely to report security events to the state, the agency points out, cautioning that its figures do not necessarily reflect all incidents impacting France's various industries.

ANSSI says attackers target systems linked to the internet and “edge devices” like firewalls and anti-spam gateways, often exploiting vulnerabilities using methods that are not particularly sophisticated.

ZeroBytes, the group that said it stole data belonging to nearly 700,000 individuals and businesses in attacks on the tax administration this summer, told the AFP news agency that French organisations are targets because they are “easy to hack”.

In 2024, a massive amount of personal data was stolen in a string of attacks on public organisations, including the employment agency France Travail and healthcare payment operators.

France, a centralised country, has systems that relate to each other, particularly as administrations share information to make public services more convenient for users. This multiplies the spoils once attackers get in.

“The interconnection of databases is an issue in regards to data privacy,” Grünemwald says. “In France, when you breach a system, you can access multiple databases.”

France probes unprecedented cyberattack after tax data of 678,000 users stolen

Rapid detection crucial

But Grünemwald does not believe interconnected databases make France a target in the first place. “We are not attacked because we have multiple databases. The success of these attacks is because there is not sufficient protection on one or more databases.”

Once an attacker gets inside a system, the speed of detection becomes critical.

“The most important is how long the attacker will be alone in the system,” Grünemwald explains. “One minute, two minutes, 20 minutes, one hour, three days, one week? You should be able to react to an attack.”

The objective is not to prevent every intrusion – it is to make sure that attackers who gain access cannot remain inside long enough to commit a serious breach. That's something France has struggled to do.

The French tax system was breached three times this summer, in June, July and August. The intrusions were detected, but not the data theft. That was only revealed when the attacker advertised the stolen data in August, more than a month later.

Warnings sent to French taxpayers after hackers allegedly sell stolen data

Lack of resources

The underlying problem, Grünemwald argues, is one of resources and priorities.

“We lack resources in controlling the breaches,” he says. Those resources are human and technical, with artificial intelligence tools maybe forming part of the solution.

France has invested in protecting critical national security systems and infrastructure, but the latest breaches suggest it has not done enough to safeguard personal data.

They are perhaps a wake-up call – much like a string of ransomware and other attacks that hit hospitals during and after the Covid pandemic, disrupting administrative systems and in some cases, clinical operations.

The government and ANSSI introduced a programme in 2021 to raise the security level of 135 healthcare establishments, including around 100 hospitals. While ransomware attacks have not disappeared since then, their impact has proven less critical.

French mayoral candidates targeted in foreign disinformation campaign

Perhaps the clearest example of what can be done with investment, preparation and coordination is the security put in place around the 2024 Olympics.

ANSSI warned of attacks motivated by money, espionage or attempts to damage France's reputation, while the organising committee expected eight to 10 times as many cyberattacks as during the Tokyo Games.

Yet despite a flurry of attempts, the Games were not disrupted.

“We were targeted with many attacks and no one succeed enough to interrupt the Games,” Grünemwald says.

“When we have the budget, the resources, the human, the cooperation between law enforcement, private companies, Olympic committees, it works. It's not 100 percent, but it works.”

RFI
RFI

All the news from France, Europe, Africa and the rest of the world.Page: rfi

Follow our WhatsApp channel for meaningful stories picked for your day.
Just in....
body-container-line