Mesh Talk to us
Timeline · updated 2 October 2026

Data breaches in France in 2026: the timeline, with a source for every fact

In short

Two sequences followed one another within weeks, and they do not tell the same story. First, stolen legitimate credentials in public information systems. Then a flaw in the tool used to look at the data, exploitable without authentication. Every line below points to its source. Private organizations are identified by their role; technical and institutional references are named.

On this page

First wave: public information systems

What these events have in common is not technical brilliance. The attacker walks through a door designed to be opened, with credentials that are his without belonging to him, and finds gathered data behind it.

DateFactSource
June and July Access to the French tax administration's information system through stolen credentials belonging to a civil servant and to an authorised third party. Written question no. 17797, National Assembly
Night of 25 July Intrusion into a staff training system of the Ministry of Education, announced by the ministry on 31 July. franceinfo
12 and 13 August Public claim of the tax data theft on a cybercrime forum. The same author claims both intrusions. franceinfo
14 August The tax administration confirms the theft of data belonging to roughly 678,000 individuals and businesses. impots.gouv.fr
18 August First official breakdown at a press conference: about 350,000 individuals and 250,000 business accounts. franceinfo
18 and 26 August Two arrests in the Paris prosecutor's investigation, handled by the national anti-cybercrime office. franceinfo
10 September The CNIL announces an on-site inspection of the tax administration. CNIL
29 September ANSSI publishes its incident report, listing numerous weaknesses and ruling out a sophisticated attack. Figures narrowed to close to 353,000 individuals and 252,000 businesses, plus a land registry data breach. Acteurs publics

Second wave: the analytics layer

The second sequence no longer targets the system that holds the data, but the one used to look at it. An SQL injection rated 10 out of 10 in Metabase, a widely used dashboard tool, exploitable without any authentication, granting administrator rights on the instance.

DateFactSource
3 August First observed exploitation, before any patch existed. LeMagIT, 31 August
6 August Vendor advisory and patches published, active exploitation confirmed. CERT-FR opens its alert the same day. GHSA-vwf4-m7j8-wcjf · CERTFR-2026-ALE-010
8 August Two confirmed exploitations on the internal analytics instance of a French hosting provider. The provider's own security bulletin SSB-2026-004
10 August Publication of CVE-2026-72898: SQL injection without authentication, severity 10 out of 10. CVE Record
10 and 11 August The provider discovers the compromise, takes the instance offline and notifies the CNIL. Around 90,000 people concerned. Production databases were not touched: exfiltration happened from the analytics warehouse. The provider's own security bulletin SSB-2026-004
11 August Added to the Known Exploited Vulnerabilities Catalog, remediation required by 14 August. CISA KEV Catalog
31 July to 17 August Unauthorised access at a delivery tracking provider, through the same vulnerability. INCYBER, 10 September
3 and 9 September The provider confirms the incident, then five retail chains notify their own customers within the same week. INCYBER, 10 September
10 September CERT-FR updates its alert: it is aware of numerous compromises in France, without putting a number on them. CERTFR-2026-ALE-010
What the CISA catalog describes. An attacker with administrator rights on the instance can change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export that data. The analytics tool holds the keys to the databases it queries. Compromising it means inheriting its access.

September: what was added

DateFactSource
3 September The CNIL publishes a 500,000 euro penalty against a private healthcare provider for inadequate security: a single compromised account gave access to the records of 524,867 patients. CNIL, decision of 21 July
Night of 14 to 15 September Intrusion into the corporate mail server of a Normandy inter-municipal authority. The number of people concerned is unknown. LeMagIT, 18 September
15 September 45% of French residents say they were notified of a personal data breach in 2026, against 30% last year. Cybermalveillance.gouv.fr and Ipsos Digital
23 September A mail-sending service owned by a postal group suspends all of its operations after unauthorised access to customer accounts. No data exfiltration announced. LeMagIT, 25 September
26 to 28 September A sixth retail chain notifies its customers of an incident at a provider: name, surname, email address, phone number. Clubic, 28 September
28 September CERT-FR opens an alert on eight vulnerabilities in a widely deployed remote access appliance, two of which allow unauthenticated remote code execution, exploited before a patch existed. CERTFR-2026-ALE-011
29 September The August alert on the analytics tool is still open, in its 10 September revision. CERTFR-2026-ALE-010
30 September ANSSI discloses that it was itself hit by the same vulnerability: 118 accounts of one of its innovation labs, including around thirty external accounts, along with instances belonging to the interministerial digital directorate. Exposed data: usage statistics, usernames, email addresses, password hashes. Its production databases are not involved. IT-Connect, 30 September

What is not established

No figure has been published for the cascade at the delivery tracking provider, and a provider's customer portfolio is not the scope of a breach. CERT-FR writes "numerous compromises" without quantifying them, and the totals circulating elsewhere come from aggregators, not from a primary source. The sixth retail chain has not named its provider, and nothing links it to those already cited.

The tax breach figures have moved: 678,000 on 14 August, close to 353,000 individuals and 252,000 businesses on 29 September, plus a land registry breach. The August figure is not the final one.

The 15 September barometer is a declarative survey: it measures notifications received, not breaches observed. It reports that 45% of French residents say they were notified, which is not the same thing as 45% of French residents having suffered a breach.

Attacker claims that the targeted organisation has not confirmed do not appear in this timeline.

What the two waves have in common

In the first sequence, the attacker obtains credentials that open a door designed to be opened. In the second, he does not even need credentials. In both cases, what he finds behind it is the same thing: a place where data had been gathered.

The French hosting provider case is the clearest, because the company published its own bulletin: production databases were not touched, exfiltration happened from the analytics warehouse. The national cybersecurity agency says the same about itself: its production databases are not involved, its analytics instance is what fell.

Hence a question that coverage of these events rarely asks: why must data be gathered in order to be analysed?

FAQ: the 2026 French data breaches

How many people were affected by the 2026 French tax data theft?

The figure changed. On 14 August 2026 the French tax administration confirmed the theft of data belonging to roughly 678,000 individuals and businesses. The ANSSI incident report published on 29 September narrowed the scope to close to 353,000 individuals and 252,000 businesses, and added a land registry breach. The August figure is not the final one.

What is CVE-2026-72898?

An SQL injection exploitable without any authentication in Metabase, a widely used dashboard tool. It is rated 10 out of 10 and grants administrator rights on the instance. The CISA Known Exploited Vulnerabilities Catalog describes the impact: steal stored credentials for the connected databases, read any data accessible through those connections, and export it. The vendor patch dates from 6 August 2026, and CERT-FR opened alert CERTFR-2026-ALE-010 the same day.

Was the French national cybersecurity agency itself affected?

Yes. On 30 September 2026, ANSSI disclosed that 118 accounts of one of its innovation labs had been compromised through the same vulnerability, along with instances belonging to the interministerial digital directorate. The exposed data consists of usage statistics, usernames, email addresses and password hashes. The agency's production databases are not involved.

Why does this page not name the affected organizations?

Private organizations are identified by their role, not by their name. Technical and institutional references are named and linked: vulnerability identifiers, CERT-FR alerts, the CISA catalog, CNIL decisions, and statements from public administrations. Every line points to a source you can check.

How often is this page updated?

It is reviewed every month, and whenever a new fact is documented by a primary source. The date of the last update appears at the top of the page.

Analysing without building the copy

Mesh (Mesh Universe) trains models where the data lives, without gathering a copy of it. If that question comes up on your side, let's talk about your case.

contact (at) meshuniverse.fr