Loading news...
199A Consulting - L'IT sur mesure
Publications
Back to articles
The State's Technical Debt: An Organized Bankruptcy
FR EN ZH
Listen

The State's Technical Debt: An Organized Bankruptcy

A chronicle of a personal data haemorrhage

A date of birth, a social security number, an IBAN, an address, a France Travail identifier. Taken in isolation, each of these fragments seems innocuous. Correlated with one another, cross-referenced across the France Travail, DGFIP, Viamedis, Free or ANTS breaches, they become the raw material of a falsification industry. A malicious actor with enough datasets can today reconstruct a complete, coherent, seemingly verifiable identity. Enough to open a line of credit, hijack an administrative account, or feed a synthetic profile tailored for a targeted social engineering operation.

The threat has become statistical, industrial, cumulative — each new leak enriching an already colossal data graph, where cross-referencing three compromised sources is enough to profile, target and manipulate millions of citizens in large-scale influence or fraud strategies. This is no longer about exposing one individual's privacy: it is the credibility of an entire national digital identification system that collapses, leak after leak, sanction after sanction, crisis statement after crisis statement.

A chronicle that should no longer surprise anyone

It must be said with the coldness of numbers, because indignation alone is no longer enough. In 2024, the CNIL recorded 5,629 data breach notifications, up 20% year on year. In 2025, the counter exploded again: 6,167 notified violations, 9.5% more, with nearly 80 incidents affecting more than one million French citizens over the last two fiscal years — a doubling in one year of the number of massive attacks. France became, in the first half of 2025, the most affected European country and the second in the world behind the United States, with 1.8 million accounts compromised between January and June.

fuites-de-donnees-en-france-trajectoire-hors-de-controle

The catalogue of public disasters is truly staggering. France Travail, in March 2024, exposed up to 43 million job seekers, with the CNIL ultimately recording 36.8 million compromised files — sanctioned with a 5 million euro fine in January 2026 for a failing information system, the same operator having already been hit in 2023. Viamedis and Almerys, health third-party payment operators, leaked in January-February 2024 the data of more than 33 million insured persons — civil status, social security numbers, contract guarantees. Free and Free Mobile, in October 2024, let slip the contracts of nearly 19 to 24 million subscribers, including 5.11 million IBANs, earning the operator a record fine of 42 million euros in January 2026. The Agence nationale des titres sécurisés (ANTS), a sovereign portal if ever there was one, saw nearly 12 million accounts affected in April 2025. At the end of 2025, 16 million young people tracked by local missions and 15 million medical records via Cegedim were added to the pile. In total, more than 145 million records have leaked since 2023 in public services, healthcare, telecoms and retail alone — several violations per French resident. INSEE itself, the nation's statistical guardian, saw 12,800 employees exposed. Even the National Museum of Natural History was paralyzed by a cyberattack in 2025. According to ANSSI, ministries and local authorities alone account for 24% of security incidents handled in 2025, alongside education and health.

A technical debt knowingly ignored

There is no bad luck here. This is the mechanical result of an accumulated, documented, known and never settled technical debt. Application security vendors' reports are damning: in French public administrations, vulnerabilities identified and sometimes patched by the vendor years ago still linger on the servers of local authorities, ministries and institutions, with patching delays reaching five, seven, ten years. This is not about inevitable technological obsolescence, but about repeated budgetary and political choices consisting in sacrificing the security of information systems for the rapid production of showcase digital services.

The CNIL itself notes that 55% of violations notified in 2024 result directly from hacking, a 21% increase in one year, overwhelmingly due to infrastructure security flaws: compromised credentials, lack of segmentation, poorly audited third-party providers.

These are exactly the symptoms of untreated technical debt, of security by design never applied, of patches never budgeted, of audits never followed up.

Ministerial negligence elevated to a system

Faced with this haemorrhage, the State should have opposed a stable doctrine, continuous steering, an identified political authority. It offered the opposite: a waltz of digital portfolio holders worthy of a second-rate ministry. Since 2017, Mounir Mahjoubi, Cédric O, Jean-Noël Barrot, Marina Ferrari, Clara Chappaz, then, in October 2025, Naïma Moutchou, whose tenure lasted less than twenty-four hours (the most ephemeral Digital Minister of the Fifth Republic), before Anne Le Hénanff took over the portfolio.

Seven holders in eight years, no doctrinal continuity, a position regularly downgraded from a full ministry to a mere state secretariat drowned in a large Economy ministry, despite a tribune signed by eighty digital personalities demanding a real ministry with resources and a voice in the Council of Ministers. How can one demand a long-term cybersecurity strategy, courageous budgetary arbitrations on technical debt remediation, a coherent digital sovereignty doctrine, when the top of the state apparatus changes face every twelve to eighteen months, sometimes within hours?

From isolated leaks to the collapse of trust

The real tipping point is qualitative. When the CNIL observes that the number of violations affecting more than one million people doubled in one year, from around twenty to around forty, this is a change in the scale of the threat. A synthetic identity built from authentic fragments (real civil status, real social security number, real administrative history) is infinitely harder to detect than crude fraud. It enables methodical impersonation, the targeting of vulnerable profiles, the manufacture of credible influence campaigns built on verifiable public data. Each additional leak does not only add victims: it enriches a cumulative, permanent attack repository, exploitable by any actor, state or criminal. And when the record fines imposed by the CNIL (55.2 million euros in 2024, 42 million for Free alone in 2026) are paid to the public Treasury and not to the victims, the message sent to citizens is unequivocal: the State sanctions, but does not repair, and above all does not structurally correct the causes.

This accumulation of technical negligence, disposable ministerial portfolios and endlessly postponed patches can no longer be considered a mere accident. It is a debt knowingly contracted, carried by a succession of political leaders whose digital competence rarely exceeded the level of crisis communication. The bill, however, will not be paid by the ministers who succeed one another, but by every citizen whose digital identity is now scattered, recombinable, and durably compromised.

Frequently asked questions

What is the core argument of the article about France's cybersecurity crisis?

The article argues that France's wave of massive data breaches is not a series of accidents but the mechanical result of accumulated, known, and never-settled technical debt in public information systems. It highlights repeated budgetary and political choices that sacrificed security for rapid digital service delivery, leading to an 'organized bankruptcy' of the state's digital infrastructure.

Why does the cross-referencing of leaked data pose a systemic risk to citizens?

Isolated data fragments like birth dates, social security numbers, or IBANs seem innocuous, but when correlated across breaches at France Travail, DGFIP, Viamedis, Free, and ANTS, they enable the industrial fabrication of synthetic identities. This allows malicious actors to open credit lines, hijack administrative accounts, and run targeted social engineering or influence campaigns, undermining trust in the entire national digital identification system.

What are the key figures and dates illustrating the scale of data leaks in France?

In 2024, the CNIL recorded 5,629 breach notifications, rising to 6,167 in 2025. Major incidents include France Travail (36.8 million files, March 2024), Viamedis and Almerys (33 million insured, early 2024), Free (up to 24 million subscribers, October 2024), and ANTS (12 million accounts, April 2025). In total, over 145 million records have leaked since 2023, making France the most affected European country in the first half of 2025.

What consequences do the CNIL fines and ministerial instability have on the crisis?

Record fines, such as 42 million euros for Free and 55.2 million euros in 2024, are paid to the public Treasury, not to victims, signaling that the state sanctions but does not repair or structurally fix root causes. Additionally, seven digital ministers in eight years, including a tenure of less than 24 hours, prevent any long-term cybersecurity strategy or coherent doctrine, leaving the system vulnerable to repeated failures.

What are the limits of current state responses, according to the article?

The state's response is limited by a focus on crisis communication rather than structural correction, with patching delays of five to ten years in public administrations. The article notes that 55% of 2024 violations stem from hacking due to infrastructure flaws like compromised credentials and lack of segmentation, and that fines do not compensate victims, leaving citizens with permanently compromised, recombinable digital identities.

How can 199A Consulting help an organization frame or execute on cybersecurity and technical debt issues?

199A Consulting, with over 20 years of experience, acts as a trusted partner in framing and executing cybersecurity strategies. We provide strategic audits, governance and risk assessments to identify and prioritize technical debt, then execute robust solutions through architecture, build, integration, and training, all aligned with digital sovereignty principles. Our 'IT by design' approach ensures security is embedded from the start, not patched after crises. Contact us at business@199a.agency.
Propulsé par Algolia

About this tool

199A Cms, V0.1 - Lightweight - NoDB - AI enabled - Multilingual & SEO by design.