The essentials
- Since 1 August 2026, ANSSI has received 99 reported data breaches across French government services; 67 incidents are confirmed, with 32 still being handled as of 30 September.
- Metabase flaw CVE-2026-72898 (SQL injection, patch available since 6 August) hit nine ministry instances—and ANSSI’s own innovation lab (118 compromised accounts).
- The same levers recur in the report: credentials stolen via infostealers, portals without multi-factor authentication, IDOR flaws, and exposed applications without enough hardening.
Why REACTIV exists
On 1 September 2026, the Prime Minister asked ANSSI to stand up REACTIV (REponse & ACTion Interministérielle face aux Violations de données): a capability to react faster to leaks affecting public administrations. The agency can require emergency measures within tight deadlines and centralise technical crisis communications. The 30 September 2026 status report is the first public scorecard for that operation.
The document stresses that figures shift: investigations are ongoing and the operational picture is not frozen at a single date.
Scale of reporting
Since 1 August 2026, 99 data breaches have been reported to ANSSI. Across those security events, 67 are confirmed, with 32 still being processed by the agency at publication time. Behind those totals lie very different datasets: tax and cadastre data, training platforms, inter-ministry messaging, Bloctel phone numbers, and more.
Metabase: one flaw, many victims
The technical through-line is CVE-2026-72898 in Metabase: an SQL injection that lets an unauthenticated user reach the application database and gain administrator rights on the instance. ANSSI describes mass exploitation since early August; nine instances in ministries were compromised. A fix has been available since 6 August 2026; the agency asked all ministries to inventory their instances and verify patching.
ANSSI itself was hit: exploitation on the innovation lab compromised 118 Metabase accounts, including roughly thirty external users (usage statistics, identifiers, email addresses, hashed passwords). Hardening followed—updates, password resets, and disabling accounts unused for more than three months.
Beyond Metabase: MFA, IDOR, infostealers
The report lists other recurring patterns: credentials stolen by infostealers on personal devices used for work; IDOR vulnerabilities enabling enumeration or bulk exfiltration; missing MFA or weak second factors (email) on exposed services; and incidents via compromised subcontractors. These are not threats unique to government: the same entry points show up at SMBs with a customer portal, a self-hosted BI tool, or a poorly segmented SaaS vendor.
- Inventory analytics tools (Metabase, Grafana, Kibana, etc.) exposed on the internet or on internal networks without hardening.
- Critical patches: patch release date, actual deployment date, evidence for audits.
- Mandatory MFA on any remote access to personal or sensitive data—not email alone as the second factor.
- Vendor accounts: least privilege, logging, fast revocation if the supplier is breached.
Sources
This note was drafted with AI tools from the cited sources, then reviewed and published under the responsibility of Jordan FOUASSIER, publication director. We summarise the facts and add our reading; source text and images are not reproduced. An error? Write to contact@aigyrosgroup.com.