Aller au contenu

Infrastructure & security

REACTIV: ANSSI’s tally of state data breaches—and what it means for your apps

ANSSI's first REACTIV update: 99 reported data breaches since August, with Metabase flaws and weak MFA in the lead. What SMBs should take from it.

  • 11 OCTOBER 2026
  • 3 MIN READ
  • CITED SOURCES

The essentials

  • Since 1 August 2026, ANSSI has received 99 reported data breaches across French government services; 67 incidents are confirmed, with 32 still being handled as of 30 September.
  • Metabase flaw CVE-2026-72898 (SQL injection, patch available since 6 August) hit nine ministry instances—and ANSSI’s own innovation lab (118 compromised accounts).
  • The same levers recur in the report: credentials stolen via infostealers, portals without multi-factor authentication, IDOR flaws, and exposed applications without enough hardening.

Why REACTIV exists

On 1 September 2026, the Prime Minister asked ANSSI to stand up REACTIV (REponse & ACTion Interministérielle face aux Violations de données): a capability to react faster to leaks affecting public administrations. The agency can require emergency measures within tight deadlines and centralise technical crisis communications. The 30 September 2026 status report is the first public scorecard for that operation.

The document stresses that figures shift: investigations are ongoing and the operational picture is not frozen at a single date.

Scale of reporting

Since 1 August 2026, 99 data breaches have been reported to ANSSI. Across those security events, 67 are confirmed, with 32 still being processed by the agency at publication time. Behind those totals lie very different datasets: tax and cadastre data, training platforms, inter-ministry messaging, Bloctel phone numbers, and more.

Metabase: one flaw, many victims

The technical through-line is CVE-2026-72898 in Metabase: an SQL injection that lets an unauthenticated user reach the application database and gain administrator rights on the instance. ANSSI describes mass exploitation since early August; nine instances in ministries were compromised. A fix has been available since 6 August 2026; the agency asked all ministries to inventory their instances and verify patching.

ANSSI itself was hit: exploitation on the innovation lab compromised 118 Metabase accounts, including roughly thirty external users (usage statistics, identifiers, email addresses, hashed passwords). Hardening followed—updates, password resets, and disabling accounts unused for more than three months.

Beyond Metabase: MFA, IDOR, infostealers

The report lists other recurring patterns: credentials stolen by infostealers on personal devices used for work; IDOR vulnerabilities enabling enumeration or bulk exfiltration; missing MFA or weak second factors (email) on exposed services; and incidents via compromised subcontractors. These are not threats unique to government: the same entry points show up at SMBs with a customer portal, a self-hosted BI tool, or a poorly segmented SaaS vendor.

  • Inventory analytics tools (Metabase, Grafana, Kibana, etc.) exposed on the internet or on internal networks without hardening.
  • Critical patches: patch release date, actual deployment date, evidence for audits.
  • Mandatory MFA on any remote access to personal or sensitive data—not email alone as the second factor.
  • Vendor accounts: least privilege, logging, fast revocation if the supplier is breached.

Sources

This note was drafted with AI tools from the cited sources, then reviewed and published under the responsibility of Jordan FOUASSIER, publication director. We summarise the facts and add our reading; source text and images are not reproduced. An error? Write to contact@aigyrosgroup.com.

Prendre contact

Does this affect your environment?

Describe your context. We reply with an analysis of what it means for you, not a catalogue.