BYOD, AI, professional social networks, industrial-use software… The latest “infiltration flashes” from the DGSI have often given pride of place to the digital realm.
The intelligence service established this format in 2012. It briefly presents real cases of economic interference and pairs them with recommendations. The most recent one (February 2026) addresses the risks of information capture during travel abroad.
Deepfakes, shadow AI… and due diligence without vigilance
The preceding “infiltration flash” (December 2025) is devoted to the use of AI in the professional world.
One of the cases described concerns a deepfake fraud attempt. It targeted the head of an industrial site belonging to a French group. The individual received a video call. The interlocutor bore the physical appearance and voice of the group’s CEO. He, however, did not comply with the request to transfer funds under the guise of a supposed acquisition project.
The other two cases concern the use of AI without authorization and without verification. The first involves the regular translation of confidential documents using a consumer-grade tool developed by a foreign company, without senior management approval. The second concerns the use of another tool of foreign origin for due diligence. The user company consistently steered its decisions based on the tool’s output, without any additional checks.
Des approches indésirables sur les réseaux sociaux professionnels
The preceding “infiltration flash” (November 2025) is dedicated to malicious approaches on professional social networks.
The DGSI outlines the case of a financially struggling startup operating in a sensitive sector. Its leader is approached by a supposed foreign consulting firm acting as an intermediary for an investment fund. Convinced, he reveals information, including a plan for designing a new product. The startup’s legal team ultimately uncovered the ruse. Neither the consulting firm nor the fund had a legitimate existence, and there was no trace of them in any official databases in their claimed countries of origin.
Another fake funding promise targeted the head of a research center. It came from the so‑called communications officer of an international celebrity. Its credibility was heightened by the celebrity’s recent publicly shared actions in the center’s field—activities widely circulated on social networks. The discussion did not go further when the individual demanded upfront payment of a local tax amounting to several thousand euros.
The third case concerns employees lured by a fake profile. The scammer initially posed as an internal accountant, unsuccessfully (the CEO had spotted the ruse). He fared better a few months later. With another fake profile, he managed to initiate discussions with employees, including one who disclosed strategic information about the development timeline of certain company activities and the state of its technological progress.
Les points faibles des logiciels industriels
In October, there had been a “infiltration flash” about the risks associated with the lack of protection for software used in industry.
The DGSI presents the case of a French company developing industrial systems. One of its clients, with the help of a foreign competitor, diverted the embedded software and installed it on a third-party machine. Yet neither the program nor the machine enjoyed patent protection. The French company had decided that patenting it would publicly expose its inventions. The client justified the move by citing allegedly long delivery times.
A second case concerns a French company marketing software to be integrated into machine tools. A foreign client, alleging a missing software update, performed a full backup of the data and the program, bypassing the French company’s procedures, which normally involve on-site updates.
With software as such not being patentable, the company fears a potential resale to a competitor.
The DGSI also notes a case of unprotected source code exfiltration at a company that had developed an application software for a cutting-edge industrial sector. Two former employees who had access to this source code in the course of their duties created a competing company to exploit it, even though their employment contracts included confidentiality and non-compete clauses.
Entre phishing et keyloggers, la DGSI n’oublie pas le « facteur humain »
Earlier in the year, a “infiltration flash” titled “The human factor, the main vector of information system compromise” was released.
The first case concerns an employee at a company hosting sensitive data. The individual accessed his professional email from personal devices, despite the employer’s IT policy prohibiting it. This enabled attackers to breach the information system and subsequently exploit a zero-day vulnerability.
In another company, a different employee was approached on a professional social network by a so‑called recruiter from a large foreign corporation. Invited to open an attachment in one of his emails, he opened the door to a virus that allowed hundreds of sensitive files to be extracted, including documents belonging to his former employer.
The DGSI adds a malicious action by an employee of a supplier to a large industrial group. He installed a keylogger on a personal USB drive and then made it available to colleagues as a professional storage device. This allowed him to recover the login credentials of people who connected to their computers.
Le BYOD, consultants compris
In March 2025, the DGSI published a “infiltration flash” on the risks associated with using personal digital tools for professional purposes.
First case described: an employee who repeatedly used his personal computer to connect to his company’s business platform. There was no anonymization or encryption of communications. A family member regularly used this computer. During a short period, its activity appeared unusual and unexplained. Months later, the company’s CISO found that the employee’s login and password were on the dark web. Without strong authentication on the business platform, third parties gained access to the customer database.
Another case: a consultant from an IT service provider for a sensitive company. At home, his personal computer was stolen. He had transferred company data from his professional workstation. The data were stored without special protection, and the computer was only secured by a password. The service provider had not notified the company about this file transfer.
The DGSI also notes a company that encouraged BYOD without clear governance. And without remote device management systems. It could not determine what happened to a employee’s phone during an airport check. Foreign authorities seized it, obtained its unlock, and moved it to another room…