[International] French Government Agencies Face Frequent Cyberattacks, Exposing Vulnerabilities; France Acknowledges Security Issues and Seeks to Rectify
RtiTalk 小編2h ago
France's Directorate General of Public Finance (DGFiP) experienced a massive data breach earlier this year, but this is just the latest in a series of cyberattacks targeting government departments. The government has launched an emergency plan to strengthen information security and will establish a new agency responsible for national digital affairs.
French media last week revealed a large-scale theft of tax data affecting up to 678,000 individuals. Prior to this, more than a dozen cyberattacks on government agencies have occurred since 2026, leading to the leakage of millions of personal data records.
This data includes personal contact information, reference tax income amounts, and business registration numbers. Not only public departments are suffering, but businesses and individuals are also affected, raising questions about whether the national information system has adequate protective measures.
Le Figaro reported that in recent months, the French Ministry of National Education alone has suffered three cyberattacks. This includes the HR database being compromised in March, with the identities and contact details of 243,000 individuals, mostly teachers, stolen. In April, a technical vulnerability dating back to December 2025 was exposed, leading to the theft of accounts related to student digital space access rights. At the end of July, another cyberattack resulted in the leakage of employee personal data.
Days ago, the hacker group ZeroBytes, which infiltrated the DGFiP system, admitted to also carrying out the Ministry of Education attack at the end of July. They claimed to have stolen "346 million lines" of data, stating, "You detected me, but you didn't stop me. I infiltrated right before your eyes."
One of the most significant victims of cyberattacks this year is the National Agency for Secure Documents (ANTS), responsible for issuing ID cards and driver's licenses. Personal identification data, contact information, and account details of up to 12 million people may have been leaked. The perpetrator was a 19-year-old French man, whose method was reportedly surprisingly simple: by changing just one digit in a personal account URL, he could access others' accounts.
In early January this year, the inter-ministerial Directorate for Digital Affairs (Dinum)'s file exchange platform HubEE was attacked by hackers, resulting in the leakage of 160,000 documents. In March, the National Police's online training platform was compromised, leading to the theft of police officers' personal data. Also in March, the appointment platform for social and housing services of the University Service Centers (Crous) was attacked, leaking data of approximately 774,000 individuals.
Besides exploiting security vulnerabilities, hackers also launched attacks through third-party platforms or by impersonating users. In January, the French social insurance agency Urssaf discovered hackers accessing interface data through stolen partner accounts.
In January, a database of a contractor for the French Immigration and Integration Office (OFII) was attacked, leading to the theft of personal data of foreign residents, including contact information, entry dates, and reasons for entry.
French Prime Minister Sébastien Lecornu stated that an emergency plan comprising 40 measures was launched at the end of April this year. This includes an additional allocation of 200 million euros (approximately NT$7.44 billion) to strengthen national information system security, the establishment of a new agency responsible for national digital affairs, and a requirement for 5% of each ministry's digital budget to be allocated to cybersecurity starting next year. (Editor: Song Wanyuan)
How does this article make you feel?
0 people reacted