A week of data breaches in France: the file nobody wanted
Between 15 and 22 August 2026, some thirty disclosed incidents assembled a file on French citizens that no authority would have approved. Why it is happening, why now, and what to fear next.

We know her address, the phone number she gives her bank and the IP address of her router. We know her reference tax income to the euro, her family quotient and her withholding rate. We know she saw a specialist last month, we have the date, the practitioner's name and the reason, with her social security number beside it. We know which gym she goes to and on what plan, and her child's age follows effortlessly from a pushchair order. If we want to go back further, her schooling is available as far as 2002.
This file existed nowhere eight days ago. No administration built it, no company sold it, and the French regulator would have refused in three minutes any processing that crossed one person's taxation, health, schooling and shopping habits. It was assembled between 15 and 22 August 2026 from a dozen breaches that have nothing to do with one another, by people who do not know each other, and it cost less than a second-hand car.
That is what happened this week. Not a wave of attacks. An assembly.
Where the pieces come from
I have sorted the week not by severity nor by status, but by the only question that matters for understanding what happened: who held your data at the moment it left.
What the state let go
| Organisation | Announced volume | Status |
|---|---|---|
| DGFiP, the tax authority | 678,000 individuals and businesses. Around 200,000 land registry accounts in the initial statement, since raised to 1.8 million, more than 2 million claimed | Confirmed. Intrusions from 26 June to late July, vacant estates portal shut down on 17 August |
| Ministry of Education | 43 GB, 2,500 files, 346 million raw rows, from 2002 to July 2026 | Claimed on 17 August. On 31 July the ministry had acknowledged an intrusion on a far narrower scope |
| Civil protection federation (FNPC) | more than 525,000 profiles and 15,000 photographs, minors included | Confirmed on 21 August. eProtec platform, intrusion dating from March 2026, volume disputed by the federation |
| Research institute for development | 7,500 people, social security numbers included | Confirmed |
What the companies you actually deal with let go
| Organisation | Announced volume | Status |
|---|---|---|
| SFR | 2,104,093 rows claimed, volume unconfirmed | Confirmed. Intrusion detected on 2 July on NOVA, the internal fibre connection tool |
| Beauty Success | 5,169,727 unique records out of 10.27 million raw rows | Claimed on 21 August |
| Bureau Vallée | roughly 4.82 million records | Claimed on 21 August, separate from a first claim on 9 August covering 21,921 people |
| Allobébé and Made in Bébé | 1,136,058 and 960,000 people | Claimed on 21 August. Both brands belong to the same group, Lulilo |
| Sport 2000, Réserver.fr, Foodtrack, SamBoat, WiziShop, KparK | from 1,194 to 19,495 depending on the case, invoices and prospecting files | Confirmed or claimed between 16 and 20 August |
What suppliers you had never heard of let go
| Organisation | Announced volume | Status |
|---|---|---|
| Alaxione, medical appointment platform | 6.8 million profiles, 10.1 million appointments, around 70,000 social security numbers | Intrusion acknowledged, scope disputed: the company refers to a test server |
| Xplor Resamania, gym management | 5,273,884 records, more than 1,200 clubs including Fitness Park, Gigafit, Magic Form, Domyos | Access confirmed on an older version. Credentials, bank details and health data in some cases |
| BlgCloud, ERP vendor | 159 client environments claimed out of roughly 230. Serial publications: Lenormant, Taveau, Clenet, Actis Location, Bergerat Rent | Compromise confirmed in late July, but on 13 exfiltrated instances according to the vendor |
| Technical supplier to Suez Eau France | not disclosed. Bank details, identity documents, contractual papers | Confirmed |
| Concierge provider to John Paul | 4,179 Visa Infinite and Platinum clients | Confirmed |
To which must be added five ransomware claims in the same week, including Experts Entreprendre and Capgemini Engineering by the Everest group, and Philippe Hottinguer Finance by Qilin.
One thing stands out when you look at the perpetrators. ZeroBytes claims the tax authority, the education ministry, SFR and Sport 2000, but Xplor Resamania is 84City, Beauty Success is « misere », Allobébé is ChimeraZ, Alaxione is Angel_Batista, without counting four distinct ransomware groups. So this is not a campaign. It is an ecosystem in which uncoordinated actors produce, by accumulation, a result nobody planned.
Nobody knows how to count
Go back to the table and look at the volume column. Almost all these figures come from the attackers themselves, and they count database rows, not human beings. Someone who placed four orders appears four times. Bureau Vallée has become the canonical example: on 9 August the attacker specified that their 55,949 records corresponded to 21,921 distinct people, and the media coverage kept the first figure.
When an organisation confirms, the gap is often brutal. BlgCloud acknowledges thirteen exfiltrated client instances where the attacker claims one hundred and fifty-nine.
Yet no French source is able to settle the matter. The most complete public inventory of this country's breaches is kept by two independent sites, FrenchBreaches and Fuites Infos, not by an authority. The regulator counts notifications, which is not the same thing: 6,167 in 2025, but its own report specifies that the Weda and Harvest incidents alone generated more than 11,600 notifications from client companies for what was, each time, a single incident, so much so that it excluded them from the count. And the 43.4 million compromised French accounts in the first half of 2026, quoted everywhere, are email addresses counted at each reappearance, one address featuring on average in three separate breaches.
No French figure today answers the question: how many people, how many times, and which ones. That is the first symptom, and it precedes all the others.
No door was forced
There is not one zero-day in this list. Not one.
At the tax authority, the attacker walked in with an officer's credentials and those of an authorised third party; in February already, on the bank account register, they were those of a civil servant from outside the department holding inter-ministerial access. At the education ministry, a hijacked professional account. At SFR, a compromised account on an internal portal. At Bureau Vallée and Réserver.fr, an API that answered without checking anything. At Clenet, an extranet account creation form that accepted disposable addresses.
The technical skill needed to reproduce the entire week is close to zero, and that is precisely the problem. When no rare competence is required, the only remaining variable is how many people try.
You never chose BlgCloud
You had not heard that name ten days ago. Nor had you heard of Xplor Resamania, or Alaxione, or your bank's concierge provider, or the company handling connections for your water utility. They hold your data all the same, because the organisation you actually had a relationship with entrusted it to them, and because pooling an ERP or a booking platform is perfectly rational from each individual company's point of view.
The consequence is far less so. A compromise at the vendor mechanically produces dozens of simultaneous victims, and you had no way of knowing, nor any way of objecting. The regulator now writes it plainly in its report: breaches are increasingly massive and often involve suppliers, smaller and less well equipped.
In the assessments we run for our clients, the question that almost always goes unanswered is not « are you compliant ». It is « what exactly would come out if a legitimate account were compromised tonight, and from how many places ». The perimeter you defend is no longer the one holding your data.
This is not now
For eight days people have been asking me why this is happening now. The honest answer is that it is not now.
SFR detected the intrusion on 2 July and told its subscribers on 20 August. The civil protection federation was attacked in March and found out in mid-August. The extractions at the tax authority run from late June to late July, and the country learned of it on 12 August because a criminal announced it. What you are watching this summer are the events of spring finally surfacing. It is not the wave that started, it is the delay between theft and admission that collapsed.
What has changed, on the other hand, is the price. The ZeroBytes duo claims to have sold the tax file to two buyers for an amount in the thousands of euros. The Alaxione database, with its medical appointments and social security numbers, is offered at five thousand dollars. Bureau Vallée was released for free. When the complete tax profile of 678,000 taxpayers is worth less than a second-hand saloon, the attacker stops targeting and simply collects.
Asked about their method, one of the two ZeroBytes members summed it up in four words: « I find and I do ». The ethical hacker Baptiste Robert describes them as young people operating from home with the help of artificial intelligence tools. A former world power had its files emptied by two bored boys and an automated scanner.
Add to this the fact that the NIS2 directive, which should have been transposed before 17 October 2024, is still waiting for its public session at the National Assembly, now hoped for in September 2026. Twenty-two months during which fifteen thousand organisations prepare at their own expense for a law that the country imposing it has not found time to pass.
The file with no data controller
The immediate risk is known and it has already begun. The tax authority wrote to 678,000 people from 17 August, SFR to its subscribers on the 20th. The fraudsters know the pretext, the timing, and now hold their targets' exact tax income. A fake message announcing an overpayment, with the right figures at the right moment, cannot be caught by common sense.
But the real danger of this week lies in none of these breaches taken alone, and I have seen this point made nowhere in ten days. It lies in their recomposition.
Go back to the file at the start of this article. Each of its pieces comes from a different organisation, unaware of the others' existence, and none of them ever held the complete combination. None would have been authorised to. That file exists nonetheless, it has no declared purpose, no retention period, no data controller, and nobody in the world can request its deletion.
This is a change in kind, not in scale. A leak of contact details produces spam. A recomposed data set produces targeting, that is, the ability to write someone a message that no reasonable vigilance can distinguish from a legitimate one. Continuing to ask citizens to be careful therefore amounts to asking them to detect the undetectable, then holding them responsible for failing.
The institutional sequel is predictable because we have seen it three times this year. On 17 August the Prime Minister requested an in-depth audit from the national cybersecurity agency, then on the 19th the creation of a new cyber unit, acknowledging that « few ministries are at the required level » and posting on X that we should « stop discovering the moon at every cyberattack », which would carry more force had it not come after the secure documents agency, after the bank account register, after the schools identity system and after the tax authority. The agency will deliver its conclusions, and they will say strong authentication, review of entitlements, extraction quotas, monitoring of abnormal volumes. Nothing that has not featured in parliamentary reports for ten years. Then will come a budget, and an organisation that does not arbitrate will turn it into projects, therefore into applications, interfaces and service accounts, that is, into additional attack surface.
The downgrade
The downgrade at stake here is not measured by the number of files stolen, but by the position a country finds itself in with regard to its own data. France holds files it cannot protect, imposes on fifteen thousand organisations a text it has not voted, learns of its losses through criminal forums, and effectively entrusts the tally of those losses to two sites run by enthusiasts. It is no longer the author of its files. It has become their subject.
On a personal level, honesty requires saying that individual hygiene repairs none of this. A password manager, two-factor authentication on your mailbox before anything else, and the reflex of never acting on an incoming message but going back to the official route yourself: none of these would have stopped a single row leaving this week, all of them reduce what can be done with it against you.
The most complete file on French citizens no longer belongs to the Republic. It trades for a few thousand euros, and it will never be deleted.
Sources
- FrenchBreaches, directory of French data breaches, accessed 22 August 2026, https://frenchbreaches.com/
- Fuites Infos, https://fuitesinfos.fr/articles/
- French Ministry of the Economy, FICOBA statement of 18 February 2026, https://www.economie.gouv.fr/actualites/ficoba-tout-savoir-lacces-illegitime-au-fichier-national-des-comptes-bancaires
- CNIL, annual report 2025, published 18 May 2026, https://www.cnil.fr/fr/rapport-annuel-2025
- France 24 and AFP, on the new cyber unit requested on 19 August 2026, https://www.france24.com/fr/france/20260819-piratage-du-fisc-l-ex%C3%A9cutif-veut-une-nouvelle-unit%C3%A9-pour-lutter-contre-les-cyberattaques
- IT-Connect, on the SFR incident and the NOVA tool, https://www.it-connect.fr/sfr-fuite-donnees-abonnes-fibre-nova/
- Cyberattaque.org, BlgCloud and Alaxione analyses, https://www.cyberattaque.org/
- Ostraca, « Reading a data breach claim », https://blog.ostraca.fr/blog/lire-une-revendication-de-fuite-de-donnees/
- Surfshark, Global Data Breach Map, first half of 2026
- ANSSI, progress of the NIS2 transposition, https://aide.monespacenis2.cyber.gouv.fr/
Frequently asked questions
How do I know if I am affected?
Check your address on Have I Been Pwned and switch on alerts. Organisations must notify individuals where the risk is high, but the delays observed this week ran from seven weeks to five months. Receiving no letter proves nothing.
Are the announced figures reliable?
Rarely. Almost all come from the attackers and count rows, not people. When the organisation confirms, the figure is generally far lower.
What should I do if my tax data is in the set?
Never act on an incoming message. No administration asks for bank details by email or phone. Log in to your own account yourself. For card fraud, report through Perceval; for guidance, cybermalveillance.gouv.fr.
Is the same group behind all of this?
No. At least five distinct handles and four ransomware groups in a single week. ZeroBytes is the most visible because it communicates, not because it is the most active.
Would NIS2 have changed anything?
On these specific incidents, probably little. Over time, yes: supply chain security, notification within 24 hours, personal liability for executives. The French text still has not been voted through.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
