Mesh Talk to us
Context

The breach no longer comes from the database, it comes from the copy built to look at it

In short

Ten years were spent hardening the database, and right next to it we built a place where every access converges: the copy gathered for analysis. It holds the credentials of everything it queries, it often lives at a provider serving hundreds of customers, and it falls without a single password being stolen. Two organisations documented this about themselves in 2026: a French hosting provider, then the national cybersecurity agency.

On this page

Two waves, two stories

The summer of 2026 chained two sequences of French data breaches that do not tell the same story, and the move from one to the other is the subject.

The first targets public information systems. The attacker enters with stolen legitimate credentials, those of a civil servant and of an authorised third party, and the incident report published on 29 September rules out a sophisticated attack in favour of weaknesses in identity, architecture and detection.

The second no longer targets the system that holds the data, but the one used to look at it. An SQL injection rated 10 out of 10 in a widely used dashboard tool, exploitable without any authentication. The facts and dates are in the sourced timeline.

What the copy holds

An analytics tool does not just hold charts. It stores the connection credentials of the databases it queries, because that is the condition for producing a dashboard at three in the morning without anyone typing a password.

The official description of the impact. The CISA Known Exploited Vulnerabilities Catalog states that an attacker who gains administrator rights on the instance can change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export that data. This is not an analyst's reading, it is the impact record of the American cybersecurity agency.

The best documented case of the wave is documented because the affected company published its own security bulletin. At a French hosting provider, an internal analytics instance was compromised on 8 August, around 90,000 people were concerned, the CNIL was notified on 11 August. And the point that matters: the contents of the production databases remained intact. Exfiltration happened from the analytics warehouse.

The database held. The copy gave way.

When the national cybersecurity agency finds it at home

On 30 September 2026, ANSSI disclosed that it had been hit by the same vulnerability: 118 accounts of one of its innovation labs, including around thirty external accounts, along with instances belonging to the interministerial digital directorate. The exposed data consists of usage statistics, usernames, email addresses and password hashes. Its production databases are not involved. Its analytics instance is what fell.

The national cybersecurity authority knew this vulnerability better than anyone, since it had opened the alert on 6 August. That is what gives this case its demonstrative value: when an organisation whose job this is finds the same pattern at home, the problem is no longer a failure of diligence. It is the shape of the architecture.

Why one instance reaches many companies

The analytics copy does not only live with the party that holds the data. It often lives at a provider, which delivers the same service to hundreds of customers and therefore gathers, in one place, what each of them entrusts to it.

In 2026, a single compromised instance at a delivery tracking provider was enough for five retail chains to notify their customers within the same week. None of those five companies had been attacked. The convergence point moved one step upstream, and the reach of a single intrusion was multiplied by five.

What this does not say

An architecture without a convergence point does not change the probability that a piece of software will fall. A vulnerable tool stays vulnerable, an unapplied patch stays unapplied, a stolen credential stays stolen. Nothing above describes protection against intrusion.

What changes is what is reachable when something falls. If no gathered copy exists, there is no gathered copy to exfiltrate. That is a reduction in surface, not protection against intrusion.

Two further points. Distributed analysis does not remove the need for classic security on each site, it relocates it. And it does not cover every use: some work still requires direct, row-by-row access to the records.

The question coverage rarely asks

Both waves were covered extensively, incident by incident. The upstream question appears far less often: why must data be gathered in order to be analysed?

For a great many uses, it does not have to be. Training a model on data spread across several sites, or across several organisations, can be done by moving the computation instead of the data: each holder trains locally, and only the learned parameters travel, encrypted. That is the principle of federated learning, and it is what Mesh (Mesh Universe) builds. The page on analysing without centralising sets out what it covers, and what it does not.

FAQ: the breach through the analytics layer

Why can a data breach come from an analytics tool?

Because it stores the credentials of the databases it queries, and because it usually works on a copy gathered for analysis. The CISA catalog describes this for CVE-2026-72898: an attacker with administrator rights on the instance can steal stored credentials for the connected databases, read any data accessible through those connections, and export it. The production database can remain intact while the data is gone.

What is a data convergence point?

The place where several sources are brought together to be analysed as one: an analytics warehouse, a data lake, a dashboard instance. It concentrates both the data and the access to the systems it came from. Its value to the organisation and its value to an attacker grow for exactly the same reason.

Would federated learning have prevented these breaches?

No. An architecture without a convergence point does not change the probability that a piece of software will fall. What it changes is what is reachable when it falls: if no gathered copy exists, there is no gathered copy to exfiltrate. That is a reduction in surface, not protection against intrusion.

Why must data be gathered in order to be analysed?

For many uses, it does not have to be. Training a model on distributed data can be done by moving the model instead of the data: each holder trains locally, and only the learned parameters travel. Some uses, such as ad hoc row-by-row exploration, still require direct access to the records.

Would encrypting the database have been enough?

Not in this pattern. The analytics tool connects with valid credentials and reads decrypted data, because that is its job. An attacker who inherits that access reads what the tool reads. Encryption at rest protects against theft of the storage medium, not against legitimate use of a stolen connection.

A copy that does not exist does not leak

Mesh (Mesh Universe) trains a shared model where the data lives. Let's look at whether your case fits.

contact (at) meshuniverse.fr