The DGFiP and Others: A Summer of Thefts

Warning: there is a critical vulnerability in Metabase that permits SQL injection without authentication.

On September 10, 2026, CERT-FR issued a security alert about this issue. It stated that it was aware of numerous breaches. Among them, the breach most likely affecting Zero Vacant Housing (Zéro Logement Vacant) was highlighted.

This service, used by local authorities to identify owners of homes that remain vacant over long periods and to contact them, apparently suffered a data breach. The act was claimed, according to the ANSSI, which says it was informed on August 28. “The entry point would be the compromise of a Metabase instance,” it now explains in its first situation update on the REACTIV framework.

The document lists about twenty incidents since the start of July. Their common thread: potential or confirmed data exfiltrations. Some are still being evaluated. For the others, the ANSSI provides, with varying degrees of certainty, quantified assessments. Sometimes these relate to the victims, sometimes to the volumes of data, and sometimes to both.

Incidents quantified with certainty

On August 12, an agency of the Ministry of Europe and Foreign Affairs was targeted. Specifically, the AEFE (Agency for French Education Abroad). A compromised account granted access to the internal directory. And the retrieval of information concerning “more than 30,000 people”: identities, contact details, professional certifications, qualifications, experiences, evaluations, and financing of VAE pathways.

Read also: Vis-à-vis the ministries, ANSSI increases its assistance… and its authority

On August 7, four days before its closure, the Bloctel service suffered a data exfiltration. The vector: a professional account from a company. The spoils: an archive containing the list of numbers submitted by that professional, as well as the list after Bloctel’s processing. The combination enabled the identification of around 600,000 numbers registered.

Also within the ministry of Economy and Finance sphere, a TRACFIN incident occurred. Trigger: the compromise of a subcontractor of the operator of the user-assistance module integrated into the declaration portal used by the professionals subject to this regime. The exfiltration stretched from late June to mid-July. It concerns 136 professionals. The spoils: names, first names, functions, email addresses, and telephone numbers. As well as the content of 213 support requests sent to technical support.

There was, of course, also the string of targeted attacks on August 12–13 against the DGFiP. A first attack exposed the tax data of about 353,000 individuals (civil status, contact details, tax number, family situation, reference income, withholding tax rate, and list of requests). And of 252,000 professionals (SIREN, designation, address, list of requests). A second attack allowed the retrieval, from the professional cadastral data server, of around 2 million records concerning some 434,000 users (names, birth dates, addresses, land parcel identifiers, nature of rights).

The ANSSI is affected as well

On August 25, more than 300 user accounts of BNUM (Bureau Numérique) were compromised. This application, used by the Ecological ministry’s department, provides public servants with a gateway to their work tools. It enabled the exfiltration of the contents of mailboxes and the shared files space.

Another portal affected: OISO (Tool for Monitoring Organizations). The Ecology Ministry uses it to verify that environmental norms are respected by private contractors. The compromise of an account belonging to a private organization allowed enumerating personal data of 22,000 agents and approved bodies.

The Qualicharge application helps the public sector manage electric vehicle charging infrastructure. Exploiting the Metabase vulnerability (CVE-2026-72898) led to the exfiltration of 102,000 charging sessions. And about one hundred technical accounts (identifiers, email addresses, hashed passwords).

This same vulnerability also permitted targeting… the ANSSI’s Innovation Lab. In the trap were 118 user accounts, including about thirty external ones. The loot: usage statistics, identifiers, email addresses, and hashed passwords.

Incidents quantified without certainty

ANSSI notes the attack at the end of July on the information system of the Ministry of National Education. It explains that the attacker “potentially could have exfiltrated” data for 4.35 million teachers (identity, assignment, rank, training, indemnities).

Read also: ANSSI and ACPR collaborate on cyber offense

These data partly fed another claim made on August 17… which also revealed a mass theft at the Créteil Academy: the base of one million students, their legal guardians, and teachers.

Also uncertain is the impact on Préférence Formations, a tool of the national network of EPLEFPA (Établissements publics locaux d’enseignement et de formation professionnelle agricoles). The leak would concern 5,265 people (identifier, surname, first name, email address, city, country, time zone).

An attack against the SNU portal (Service national universel) would have exposed the data of 275,000 users. More precisely: identifiers, names, email addresses, phone numbers, roles, statuses, geographic information, and activity. The culprit: an IDOR vulnerability (Insecure Direct Object Reference; improper access control by an application or API).

Incidents not quantified

Within DINUM as well, there were compromises of Metabase instances. Two instances, specifically linked to ProConnect and to Nuage Public. The information the operation exposed is already public, ANSSI assures. It concerns public sector bodies (SIREN, SIRET, budgets, headcounts). There are also metadata about contributions to open-source software projects, and anonymized login histories.

Dawn Liphardt

Dawn Liphardt

I'm Dawn Liphardt, the founder and lead writer of this publication. With a background in philosophy and a deep interest in the social impact of technology, I started this platform to explore how innovation shapes — and sometimes disrupts — the world we live in. My work focuses on critical, human-centered storytelling at the frontier of artificial intelligence and emerging tech.