The ANTS hack and data leaks: the French State's cyber failure
The ANTS hack (11.7 million accounts), an IDOR flaw, 284 days to detect intrusions, cyber budgets at 1%: why the French State fails at cybersecurity in 2026.

The ANTS hack and data leaks: why the French State is failing at cybersecurity
The ANTS hack, revealed in spring 2026, exposed the identity data of 11.7 million French citizens. Yet it is only the most visible episode of a dark series: since the beginning of the year, France has recorded more than three major data thefts per day, to the point of becoming the second most affected country in the world by data leaks.
That observation clashes violently with political speeches about digital sovereignty. How can a country ranked seventh among world economies, with a 3,600 billion dollar GDP, be unable to stem the leak of our private lives? How could a single teenager fold a ministry with a flaw taught in the first week of computer science school?
This article analyses, with figures and sources, the structural causes of the failure of French State cybersecurity: the timeline of the ANTS fiasco, the exploited IDOR flaw, the 2026 breach massacre, slow detection, seized-up governance and the budgetary misery of the ministries. Without forgetting what still works, and what could change.
- 11.7 million ANTS accounts exfiltrated by a 15-year-old through an elementary IDOR flaw.
- One month of silence between detection (15 March 2026) and public confirmation (13 April).
- 43 million people affected at France Travail, 33 million at Viamedis and Almerys, 15 million at Cegedim Santé.
- 284 days on average to detect and contain an intrusion in France, against 186 in Italy.
- 1% to 5% of IT budgets devoted to cyber in ministries, against the 10% recommended by ANSSI.
- NIS2 still not transposed, two years after the European deadline.
The ANTS (France Titres) affair: chronicle of a State fiasco
France Titres, formerly the national agency for secure documents (ANTS), manages the most sensitive identity data of French citizens: passports, driving licences, vehicle registrations. It is precisely this agency that suffered, in March 2026, the most embarrassing breach of the year.
A month of silent drift
| Date | Event |
|---|---|
| 15 March 2026 | Engineers at France Titres detect an abnormal spike in network activity. The administration’s initial reflex: complete radio silence for a month while searching for the flaw internally. |
| 13 April 2026 | The axe falls: ANTS officially confirms that millions of citizen records have been exfiltrated. |
| 15 April 2026 | Official notification to the CNIL and referral to ANSSI. The agency sends a warning email to users, ending with a surreal sentence: “You therefore have no action to take”. |
| 16 April 2026 | The dark web shock: a cybercriminal operating as “breach3d” puts the database up for sale on a criminal forum and claims 18 to 19 million records. Researcher Seblatombe, founder of FrenchBreaches, publicly confirms the data is genuine. |
| 21 April 2026 | Official tally from the Ministry of the Interior: 11.7 million accounts compromised. Laurent Nuñez urgently refers the case to the General Inspectorate of Administration (IGA). |
| 25 April 2026 | The anti-cybercrime office (OFAC) traces “breach3d” digitally. End of the run: the hacker is arrested at home, in Corsica. |
The exposed data is exactly what fuels identity theft: last names, first names, dates and places of birth, email addresses, phone numbers and unique identifiers. Telling victims they have “no action to take” ignores the fact that this information now circulates in phishing and fraud circuits.
The hacker’s profile: a 15-year-old versus the Republic
The author’s profile is very far from Hollywood clichés. No agent of a foreign power, no military coding genius: a 15-year-old, in school and socially isolated, a self-taught “script kiddie” spending his days on Discord and Telegram channels.
His motivation is virtual ego: the search for adrenaline, buzz and peer recognition. A lawyer’s metaphor sums up the phenomenon: “For these kids, hacking a State infrastructure is like getting a Top 1 on Fortnite”. The phenomenon is national: SIRASCO counts 31 similar arrests of young men aged 13 to 23 over the period. Indicted on 29 April 2026 by the Paris prosecutor, the teenager faces, despite his age, up to seven years in prison and a 300,000 euro fine.
The technical flaw: IDOR, the absolute shame of cybersecurity
How did a teenager fold a ministry? No sophisticated zero-day was used. The breach relies on an elementary logic flaw: an IDOR (Insecure Direct Object Reference), a direct reference to an object without any authorisation check.
- The attacker logs into his own, perfectly legitimate user account.
- He observes the request sent to the server:
moncompte.ants.gouv.fr/api/usager?id=12345. - He manually changes the number in the URL:
id=12346. - The server instantly returns the private data of the next user, without checking whether he is entitled to it.
- A simple automated script then increments the identifiers and siphons 11.7 million records non-stop.
This architecture mistake is so basic that it is taught in the first week of any computer science school so that it can be avoided. It is also one of the very first checks of an application penetration test: verifying that every resource reachable through an identifier is protected by a server-side authorisation check.
The quantitative massacre: mass siphoning
The ANTS hack is not an isolated case, it is the climax of a dark series. Since early 2026, almost the entire French working population has had its basic personal information compromised.
The mega-leaks that floored France
- France Travail (formerly Pôle Emploi): 43 million people affected, the whole working population over twenty years.
- Viamedis and Almerys: 33 million French citizens had their social security number stolen through the third-party payment system.
- Cegedim Santé (February 2026): 15 million patients exposed, billing history and administrative data.
- ÉduConnect (April 2026): 3.5 million pupils and families hacked, with exactly the same IDOR flaw as ANTS.
- FICOBA (Bercy, January 2026): 1.2 million bank accounts compromised through the simple theft of an agent’s credentials.
The paradox of volumes and French slowness
France notifies fewer raw incidents than its neighbours, a sign of a missing detection culture. But once hit, it shows a dramatic slowness to react.
| State | Notified breaches (2024) | Notified breaches (2025) | Average time to detect and contain |
|---|---|---|---|
| Netherlands | 33,471 | 39,773 | Not specified |
| Germany | 27,829 | 34,467 | Not specified |
| France | about 4,700 | 5,629 | 284 days |
| Italy | Not specified | Not specified | 186 days |
| United Kingdom | Not specified | Not specified | 210 to 284 days |
Direct consequence of this 284-day delay: attackers have nine months to resell, exploit and spread the data before the State closes the valve.
ANSSI and the State’s seized-up governance
If the situation is what it is, the State is not blameless. It results from a chain of late or unfinished government decisions.
Vincent Strubel’s admissions before the Senate
On 4 May 2026, before a Senate inquiry committee, the director general of ANSSI broke the sovereignty taboo:
- he denounced major “blind spots” in national security;
- data encryption does not protect against US extraterritorial law (Cloud Act);
- ANSSI now considers the risk of a unilateral shutdown of critical cloud services by foreign giants as “credible”;
- the SecNumCloud label is no longer presented as a magic shield, but as a very partial tool.
The legislative fiasco of the NIS2 directive
The European NIS2 directive must impose strict security rules on more than 15,000 critical entities in France. Its calendar illustrates national inertia: transposition deadline missed on 17 October 2024, formal notice and reasoned opinion from the European Commission in May 2025, bill blocked at the National Assembly by political instability, final adoption pushed back to the end of 2026. That is two years behind schedule.
The budgetary misery of the ministries
The cyber budgets of French ministries hover between 1% and 5% of their IT envelopes, while ANSSI recommends a minimum floor of 10% to guarantee a modern defence. At the end of April 2026, Sébastien Lecornu announces the emergency release of 200 million euros to fund “flash audits” and deploy AI-based detection. By the very admission of the minister delegate for Digital Affairs, this is only a temporary bandage that will not make up for ten years of accumulated technical debt.
What works: a strong but stifled private ecosystem
Not everything is dark. The French private industrial ecosystem is one of the best in Europe and weighs more than 8 billion euros, with world-class players such as Orange Cyberdefense, Thales or Eviden, and sovereign champions able to encrypt and detect threats brilliantly: Stormshield, Wallix, Sekoia.
Regulation is formidable too. The CNIL is one of the toughest authorities in Europe: France ranks second in Europe for the total amount of GDPR sanctions, with more than one billion euros in cumulative fines. But the law punishes after the fact, and that does not make up for the lack of operational technical reflexes in administrations.
The human factor, the real weakest link
60% of security breaches in France directly involve human error: a weak password, one click too many on a phishing email, a forgotten configuration or a temporary administrator access never revoked. Social engineering remains the entry key of 80% of large-scale attacks. No technology will protect the State if its agents keep opening the door to attackers.
Why is French cybersecurity so bad? The key figures
| Number | What it says |
|---|---|
| 1% to 5% | Cyber budget of the ministries, against a recommended minimum standard of 10%: the State massively underinvests. |
| 284 days | Average time to detect and contain an intrusion, more than nine months, against 186 days in Italy. |
| 3 thefts a day | Pace of major leaks endured by France since the beginning of 2026. |
| 2nd most affected country | France’s rank for data leaks in the first quarter of 2026. |
| 43M, 33M, 11.7M | France Travail, health insurers, ANTS: no citizen has been spared. |
| 15,000 positions | Cyber experts missing in France by 2030. |
These statistics do not explain everything. The skills shortage is worsened by unattractive public salaries and outsized requirements, in direct competition with artificial intelligence. And nearly 60% of breaches come from a simple internal error or manipulation.
Frequently asked questions
Am I affected by the ANTS hack?
If you completed an online procedure on ants.gouv.fr (passport, identity card, driving licence, vehicle registration) and had a user account, your identity data is probably part of the 11.7 million exfiltrated records. Be extra vigilant about emails and text messages claiming to come from the administration.
What is an IDOR flaw?
An IDOR (Insecure Direct Object Reference) is an authorisation vulnerability: the application exposes resources through a predictable identifier (user, invoice or case number) without checking that the logged-in user is entitled to access them. It belongs to the “Broken Access Control” category, first in the OWASP Top 10 ranking.
What should you do after a data breach?
Change the passwords of the accounts concerned, enable two-factor authentication, monitor your bank statements and administrative procedures, and be wary of any request using the leaked data to look legitimate. Victims can also file a complaint and report the incident to the CNIL.
What is the NIS2 directive?
NIS2 is the European directive on the security of network and information systems. It imposes on essential and important entities (energy, health, transport, administrations, digital) risk management measures, incident notification obligations and sanctions of up to 2% of worldwide turnover.
Key takeaways
France lacks neither talent nor first-rate industrial players. It has cruelly lacked budget and strategic vision. A note of hope nonetheless: the 200 million euro emergency envelope released after the ANTS hack, and between 15,000 and 18,000 companies and administrations that will be legally forced to strengthen their defences under threat of colossal fines.
In 2026, cybersecurity is no longer a technical option or an administrative chore. It is a weapon of national sovereignty, and it is high time the State stopped enduring.
Sources
- RGPD Kit, Piratage ANTS 2026 : bilan complet, hacker, données et RGPD
- Mac4Ever, 200 millions débloqués pour la cybersécurité en France, mais ça ne suffira pas
- info.gouv.fr, France Titres : le point sur l’incident de sécurité
- France Titres (ANTS), Incident de sécurité relatif au portail ants.gouv.fr
- Leto, Cyberdélinquance française : un profil jeune et isolé derrière les fuites de données
- i-lead consulting, Cyberattaques France 2026 : la liste à jour
- All IT Network, Les fuites de données en France : les plus ciblés de l’UE ?
- ISI Sec, Cybersécurité news : menaces, acteurs et tendances clés en 2026
- Solutions Numériques, Commission d’enquête : l’ANSSI met en garde contre les angles morts de la souveraineté numérique
- Ornisec, Directive NIS 2 : point de situation
- Make IT Safe, NIS 2 : obligations, sanctions et stratégies de conformité
- Cybermalveillance.gouv.fr, Guide cybersécurité des communes et intercommunalités
- Groupe Factoria, Statistiques cyberattaques 2025
- Digitemis, Stratégie cybersécurité 2026 : décryptage du plan national