A date of birth, a social security number, an IBAN, an address, a France Travail identifier. Taken in isolation, each of these fragments seems innocuous. Correlated with one another, cross-referenced across the France Travail, DGFIP, Viamedis, Free or ANTS breaches, they become the raw material of a falsification industry. A malicious actor with enough datasets can today reconstruct a complete, coherent, seemingly verifiable identity. Enough to open a line of credit, hijack an administrative account, or feed a synthetic profile tailored for a targeted social engineering operation.
The threat has become statistical, industrial, cumulative — each new leak enriching an already colossal data graph, where cross-referencing three compromised sources is enough to profile, target and manipulate millions of citizens in large-scale influence or fraud strategies. This is no longer about exposing one individual's privacy: it is the credibility of an entire national digital identification system that collapses, leak after leak, sanction after sanction, crisis statement after crisis statement.
A chronicle that should no longer surprise anyone
It must be said with the coldness of numbers, because indignation alone is no longer enough. In 2024, the CNIL recorded 5,629 data breach notifications, up 20% year on year. In 2025, the counter exploded again: 6,167 notified violations, 9.5% more, with nearly 80 incidents affecting more than one million French citizens over the last two fiscal years — a doubling in one year of the number of massive attacks. France became, in the first half of 2025, the most affected European country and the second in the world behind the United States, with 1.8 million accounts compromised between January and June.
The catalogue of public disasters is truly staggering. France Travail, in March 2024, exposed up to 43 million job seekers, with the CNIL ultimately recording 36.8 million compromised files — sanctioned with a 5 million euro fine in January 2026 for a failing information system, the same operator having already been hit in 2023. Viamedis and Almerys, health third-party payment operators, leaked in January-February 2024 the data of more than 33 million insured persons — civil status, social security numbers, contract guarantees. Free and Free Mobile, in October 2024, let slip the contracts of nearly 19 to 24 million subscribers, including 5.11 million IBANs, earning the operator a record fine of 42 million euros in January 2026. The Agence nationale des titres sécurisés (ANTS), a sovereign portal if ever there was one, saw nearly 12 million accounts affected in April 2025. At the end of 2025, 16 million young people tracked by local missions and 15 million medical records via Cegedim were added to the pile. In total, more than 145 million records have leaked since 2023 in public services, healthcare, telecoms and retail alone — several violations per French resident. INSEE itself, the nation's statistical guardian, saw 12,800 employees exposed. Even the National Museum of Natural History was paralyzed by a cyberattack in 2025. According to ANSSI, ministries and local authorities alone account for 24% of security incidents handled in 2025, alongside education and health.
A technical debt knowingly ignored
There is no bad luck here. This is the mechanical result of an accumulated, documented, known and never settled technical debt. Application security vendors' reports are damning: in French public administrations, vulnerabilities identified and sometimes patched by the vendor years ago still linger on the servers of local authorities, ministries and institutions, with patching delays reaching five, seven, ten years. This is not about inevitable technological obsolescence, but about repeated budgetary and political choices consisting in sacrificing the security of information systems for the rapid production of showcase digital services.
The CNIL itself notes that 55% of violations notified in 2024 result directly from hacking, a 21% increase in one year, overwhelmingly due to infrastructure security flaws: compromised credentials, lack of segmentation, poorly audited third-party providers.
These are exactly the symptoms of untreated technical debt, of security by design never applied, of patches never budgeted, of audits never followed up.
Ministerial negligence elevated to a system
Faced with this haemorrhage, the State should have opposed a stable doctrine, continuous steering, an identified political authority. It offered the opposite: a waltz of digital portfolio holders worthy of a second-rate ministry. Since 2017, Mounir Mahjoubi, Cédric O, Jean-Noël Barrot, Marina Ferrari, Clara Chappaz, then, in October 2025, Naïma Moutchou, whose tenure lasted less than twenty-four hours (the most ephemeral Digital Minister of the Fifth Republic), before Anne Le Hénanff took over the portfolio.
Seven holders in eight years, no doctrinal continuity, a position regularly downgraded from a full ministry to a mere state secretariat drowned in a large Economy ministry, despite a tribune signed by eighty digital personalities demanding a real ministry with resources and a voice in the Council of Ministers. How can one demand a long-term cybersecurity strategy, courageous budgetary arbitrations on technical debt remediation, a coherent digital sovereignty doctrine, when the top of the state apparatus changes face every twelve to eighteen months, sometimes within hours?
From isolated leaks to the collapse of trust
The real tipping point is qualitative. When the CNIL observes that the number of violations affecting more than one million people doubled in one year, from around twenty to around forty, this is a change in the scale of the threat. A synthetic identity built from authentic fragments (real civil status, real social security number, real administrative history) is infinitely harder to detect than crude fraud. It enables methodical impersonation, the targeting of vulnerable profiles, the manufacture of credible influence campaigns built on verifiable public data. Each additional leak does not only add victims: it enriches a cumulative, permanent attack repository, exploitable by any actor, state or criminal. And when the record fines imposed by the CNIL (55.2 million euros in 2024, 42 million for Free alone in 2026) are paid to the public Treasury and not to the victims, the message sent to citizens is unequivocal: the State sanctions, but does not repair, and above all does not structurally correct the causes.
This accumulation of technical negligence, disposable ministerial portfolios and endlessly postponed patches can no longer be considered a mere accident. It is a debt knowingly contracted, carried by a succession of political leaders whose digital competence rarely exceeded the level of crisis communication. The bill, however, will not be paid by the ministers who succeed one another, but by every citizen whose digital identity is now scattered, recombinable, and durably compromised.
