ORIGIN

Acteurs cybercriminels / Risque d'ingérence ciblée

TARGET

France, population, gouvernement, ministère, service spéciaux

CATEGORY

Російські втручання та гібридні загрози в Європі

SUMMARY

French judicial authorities have opened an investigation following confirmation of a major cyberattack against the Directorate General of Public Finances. Unauthorized access occurring in June and July 2026, involving compromised credentials, enabled the consultation and extraction of data relating to 678,000 individual and professional users. The incident is now under investigation by French judicial and cybersecurity authorities.

CEAS Assessment: beyond the initial compromise, the strategic value of the exfiltrated information represents a significant security concern. Such data may facilitate highly targeted fraud, sophisticated phishing, identity theft and the identification of sensitive or high-value individuals. Within the broader European hybrid-threat environment, a breach of this magnitude must therefore also be assessed for potential secondary exploitation by criminal or state actors. There is currently no publicly established attribution linking this operation to Russia.