PoliticalRepoPoliticalRepo

France · Question · Question écrite

15644

Question 15644 — digital

openFrance· National Assembly· FR

Introduced

2 June 2026

Last action

Status

posée

Sponsors

Subjects

Discovery layer

Source updated

2 June 2026

Summary

Mr. Jocelyn Dessigny draws the attention of the Minister of the Interior to the structural failures of the State in terms of cybersecurity, illustrated in a particularly serious manner by the hacking of the National Agency for Secured Titles (ANTS). On April 15, 2026, the moncompte.ants.gouv.fr portal, a sovereign platform centralizing requests for passports, identity cards, driving licenses and residence permits, was the victim of a cyberattack. Between 12 and 18 million lines of data were allegedly exfiltrated and then offered for sale on cybercriminal forums. The exploited flaw (a basic IDOR vulnerability on an API) was described by the hacker (only 15 years old) himself as “really stupid”: it was enough to modify a number in a request to access the data of another citizen. This is not a sophisticated attack by an enemy state. This is an elementary flaw, which should never have existed in a government system managing the identity documents of tens of millions of French people. Since the start of 2026, cyberattacks against French administrations have multiplied at an alarming rate: in January, the FICOBA file of the Ministry of the Economy was hacked with 1.2 million bank accounts compromised; in February, CAF was hit with approximately 70,000 RSA files exfiltrated; in March, the report cards of 3.5 million students were put up for sale on the dark web after the EduConnect hack. The digital space of the French state has become a sieve. The 2026-2030 national cybersecurity strategy, presented in January 2026, does not mention any budgetary figures, a point which crystallizes criticism from sector experts. The ANSSI report published on March 11, 2026 reveals that nearly 29% of vulnerabilities exploited in 2025 were exploited on the same day of their publication or before and that more than 6,200 assets in France still remained vulnerable at the end of 2025 to flaws known since 2023 or 2024. The slowness in applying patches is systemic. It is not inevitable: it is a management choice. Faced with the scandal, the Prime Minister described the situation as “the heist of the century” which would take place “ almost every month” and announced a budget of 200 million euros. However, reactive budget announcements, made after each scandal, do not constitute a security policy. The French have the right to demand better than post-incident patches on systems that manage their most sensitive data. He asks him what structural, and not cyclical, measures he intends to implement to guarantee the security of government information systems; what mandatory audit schedule is planned for all government platforms processing personal data and how the State intends to report to citizens whose data has been compromised on the follow-up given to these repeated incidents.

Machine translation from French. The official text remains authoritative.

Timeline

No timeline events have been ingested for this record yet.

Votes

No vote records are attached yet.

Versions

No version snapshots stored. Document URLs remain at the source.

Documents

No documents linked.

Sponsors

No sponsors or actors listed by the source.

Related records

No cross-record relationships stored yet.

Sources

PoliticalRepo is an index and interpretation layer, not the authoritative legal source.