Data Breaches: Why France Became Europe’s Most Affected Country in 2026

Written by: Adel Khelifi on August 22, 2026

Tax authorities, bank accounts, large-scale retail, schools, hospitals, and local communities: since the start of 2026, France has been chaining data breaches and leaks at a spectacular pace.

According to data compiled by Surfshark, 43.4 million French accounts have been compromised in the first half of 2026, i.e., an increase of 62.3 % compared with the previous six months. France would now account for 58 % of compromised accounts recorded in Europe and would hold the second place globally behind the United States.

These statistics do not mean that 43.4 million distinct French people have necessarily fallen victim to a breach: a single person may own several accounts or appear in several compromised databases. They nevertheless measure the scale of a phenomenon that no longer touches only a few large companies.

Tax administration, bank accounts, National Education, commerce, local public services: behind very different incidents gradually emerges a common weakness. Attackers do not always need to “break” into a computer system. Sometimes they simply manage to impersonate someone who already has the right to enter.

France in Five Figures

43.4 million of French accounts compromised in the first half of 2026.

+62.3 % compared to the second half of 2025.

58 % of compromised accounts recorded in Europe would be French.

6,167 data breaches were notified to the CNIL in 2025, of which about one in two related to hacking.

2,209 reports were received by the ANSSI in 2025, for 1,366 incidents processed.

The Tax Administration: Symbol of a Dark Year

One of the most sensitive episodes concerns the tax administration.

In a press release published on August 14, 2026, the Direction générale des finances publiques (DGFiP) officially acknowledged intrusions that occurred in June and July.

The attackers had managed to impersonate the credentials of a DGFiP official and of an authorized third party, allowing them to access information concerning 678,000 individuals and professionals.

Among the data that may have been viewed or extracted are notably the reference taxable income, the family quotient, the rate of the income tax withholding, and certain cadastral data.

Bercy specifies, however, that taxpayers’ personal spaces and their passwords were not compromised. The Paris prosecutor’s office has opened an investigation.

But this case is all the more worrying as it represents the second major incident affecting the DGFiP in six months.

In February 2026, the administration had already confirmed that the credentials of a civil servant had been usurped to consult information related to about 1.2 million bank accounts listed in the FICOBA file.

In both cases, the mechanism is telling: the attacker did not necessarily force an electronic door. They used an identity that already had a key.

A Wave Affecting Almost All Sectors

The tax administration is far from being an isolated case. Large-scale retail, education, and local public services are also among the victims recorded since the start of the year.

Organization Date Official Scope Data Involved Known Entry Point Takeaway
DGFiP June–July 2026 678,000 individuals and professionals Reference income, family quotient, withholding tax rate, cadastral data Credentials of an agent and an authorized third party impersonated Officially confirmed by the Finance Ministry
DGFiP / FICOBA February 2026 1.2 million bank accounts Bank account information Credentials of a civil servant impersonated First major incident at the tax authorities in 2026
Intermarché Drive End of July 2026 287,605 clients Identity, date of birth, contact details, loyalty card Unauthorized access to customer files No banking data or passwords, according to the retailer
Education Nationale July 2026 Under evaluation Staff data, potentially dating back to 2001 Professional account impersonated Some affected employees were alerted
SDIS 51 – Marne 2026 Not disclosed Personal data Not disclosed Operational functioning of emergency services not affected
Regional Youth Program Early 2026 About 90,000 users Personal data Not specified Illustrates exposure of local public services

Viewed from above, the table reveals a constant: the stolen credential keeps coming back.

The accumulation is staggering. But it did not begin in 2026.

2026 Is an Acceleration, Not a Sudden Phenomenon

French official figures already showed strong pressure the previous year.

In 2025, the Commission nationale de l’informatique et des libertés (CNIL) had received 6,167 notifications of personal data breaches. About one breach in two resulted from hacking.

The Agence nationale de la sécurité des systèmes d’information (ANSSI) had, for its part, received 2,209 reports and processed 1,366 incidents.

Sectoral distribution was already revealing: 34 % concerned education and research, 24 % ministries and local authorities, 10 % health, and 9 % telecommunications.

The current wave is therefore not a January-made accident. It is rather the spectacular acceleration of a vulnerability already observed in public services, businesses, and their network of suppliers.

Why is France So Widely Affected?

It would be too simplistic to conclude that French computer systems are simply “less secure” than those of other countries. Several mechanisms combine.

Extremely Valuable Databases

France has widely digitized its administrative and private services. Taxation, bank accounts, health, education, insurance, consumption, commercial loyalty: millions of people are present in large databases.

Individually, an email address or a phone number may have limited value. But when an attacker manages to associate name, address, phone, family situation, income and banking information, they can build a far more convincing fraud.

A simple message saying “your account must be verified” easily evokes suspicion. A message mentioning your real name, your bank, your address, and authentic tax information can become significantly more credible.

This is what makes successive breaches particularly dangerous: their data can be cross-referenced.

Digital Identity Becomes the New Security Perimeter

For years, cybersecurity has been symbolized by the firewall: to prevent intruders from entering.

The model is changing. Attackers now very often seek to steal the digital identity of an already authorized person.

The DGFiP case illustrates this perfectly. In February as in the summer, incidents rely on the impersonation of credentials belonging to legitimate users.

Once connected with these rights, the attacker looks much less like a pirate in the system’s eyes. They look like an employee at work.

Comment voler des données sans « pirater » le système ?

1. An attacker obtains the credentials of an employee or a partner.

2. The system recognizes him as an authorized user.

3. He accesses the information to which this account normally has access.

4. He then repeatedly performs consultations or extractions.

5. If these abnormal behaviors trigger no alert, the data may exit even though no apparent “door” was forced.

The consequence: passwords and firewalls are no longer sufficient. Multi-factor authentication, rights limitation, monitoring of unusual behaviors, and access traceability become essential.

Public Administrations Are Particularly Attractive Targets

Public services accumulate several features that attackers search for: substantial databases, sensitive information, and a large number of employees, contractors, and interconnected applications.

The more users with access, the greater the potential number of accounts that could be compromised.

ANSSI figures also show that education, ministries and local authorities were already among the sectors most represented in incidents treated or reported in 2025.

The Weakest Link May Be the Supplier

A company can also invest heavily in its own security and remain vulnerable because its system no longer stops at its own walls.

HR software, IT service providers, SaaS applications, call centers, hosting providers, accounting firms, or business partners: every external connection can become a new entry point.

The question is no longer only: “Is our company protected?”

It becomes: “Are all those who have had access to our data as well protected?”

Data Leaks, Cyberattacks, Deepfakes: Don’t Mix Them Up

The French news also illustrates another difficulty: not all digital threats are of the same nature.

Three Threats Not to Confuse

Data leakage: information is viewed, copied, or extracted without authorization. It can then be used for phishing, fraud, extortion, resale, espionage, or made public.

Cyberattack: a broader term for a hostile action against a computer system: intrusion, sabotage, ransomware, data theft, denial of service, or data destruction.

Deepfake and information operations: the objective is not necessarily to penetrate a system, but to produce and disseminate false content to deceive or influence a population.

In recent days, false videos generated by artificial intelligence, notably targeting several French political leaders, have been denounced as possible interference operations.

These cases belong to the same general universe of digital threat, but they should not be confused with database compromises.

For Victims, Danger Sometimes Starts After the Breach

A breach does not necessarily entail immediate fraud.

The information can remain stored for months, be resold, cross-referenced with other databases, and used much later.

The main danger then becomes personalized phishing.

After a tax breach, a scammer may pose as the administration. After one from a retailer, as its customer service. After a banking breach, as the bank advisor.

The more precisely the fraudster has information, the less his call or message looks like a fraud attempt.

For victims, a few rules remain essential: never share a password or a code received by SMS, avoid clicking on links in an unsolicited message, and, if in doubt, contact the concerned organization directly through its official channels.

What a Tunisian Company or Administration Can Learn from the French Case

For Tunisia, the value of the French example is not to remark on the difficulties of another country. It is to look at what can happen to any economy gradually digitizing its services.

A Tunisian organization can already test its level of preparedness with six simple questions.

Six Questions to Ask in Your Organization

1. If a employee’s account is stolen today, what data could the attacker access?

2. Do sensitive accounts have truly robust multi-factor authentication?

3. If a user views or downloads 10,000 files in one hour while normally viewing only a few dozen, is an alert triggered?

4. Can a former employee or former contractor still have a forgotten access?

5. Are actions performed by subcontractors identified and logged?

6. Does everyone know precisely what to do during the first 60 minutes after the discovery of an intrusion?

If an organization cannot clearly answer these six questions, it already has a good indication of the priorities to address.

Because cybersecurity no longer depends solely on the quality of an antivirus or the strength of a firewall. It also depends on how access rights are distributed, monitored, and revoked.

The True Lesson of 2026

The great French lesson of 2026 may not be that computer systems have become easy to hack.

It is more worrying.

A system can be properly protected against classical intrusions and still allow hundreds of thousands of records to exit as soon as an attacker succeeds in impersonating an authorized user.

The central question then becomes less: “Did someone enter?” and more: “Who just connected, with what rights, to view which information, at what pace and for what purpose?”

After the firewall era, the era of digital identity follows.

Knowing who enters the system is no longer enough. It is now essential to know what they are doing there.

Adel Khelifi

Adel Khelifi

My name is Adel Khelifi, and I’m a journalist based in Tunis with a passion for telling local stories to a global audience. I cover current affairs, culture, and social issues with a focus on clarity and context. I believe journalism should connect people, not just inform them.