France · Question · Question écrite
15644
Question 15644 — digital
Introduced
2 June 2026
Last action
—
Status
posée
Sponsors
—
Subjects
Discovery layer
Source updated
2 June 2026
Summary
Mr. Jocelyn Dessigny draws the attention of the Minister of the Interior to the structural failures of the State in terms of cybersecurity, illustrated in a particularly serious manner by the hacking of the National Agency for Secured Titles (ANTS). On April 15, 2026, the moncompte.ants.gouv.fr portal, a sovereign platform centralizing requests for passports, identity cards, driving licenses and residence permits, was the victim of a cyberattack. Between 12 and 18 million lines of data were allegedly exfiltrated and then offered for sale on cybercriminal forums. The exploited flaw (a basic IDOR vulnerability on an API) was described by the hacker (only 15 years old) himself as “really stupid”: it was enough to modify a number in a request to access the data of another citizen. This is not a sophisticated attack by an enemy state. This is an elementary flaw, which should never have existed in a government system managing the identity documents of tens of millions of French people. Since the start of 2026, cyberattacks against French administrations have multiplied at an alarming rate: in January, the FICOBA file of the Ministry of the Economy was hacked with 1.2 million bank accounts compromised; in February, CAF was hit with approximately 70,000 RSA files exfiltrated; in March, the report cards of 3.5 million students were put up for sale on the dark web after the EduConnect hack. The digital space of the French state has become a sieve. The 2026-2030 national cybersecurity strategy, presented in January 2026, does not mention any budgetary figures, a point which crystallizes criticism from sector experts. The ANSSI report published on March 11, 2026 reveals that nearly 29% of vulnerabilities exploited in 2025 were exploited on the same day of their publication or before and that more than 6,200 assets in France still remained vulnerable at the end of 2025 to flaws known since 2023 or 2024. The slowness in applying patches is systemic. It is not inevitable: it is a management choice. Faced with the scandal, the Prime Minister described the situation as “the heist of the century” which would take place “ almost every month” and announced a budget of 200 million euros. However, reactive budget announcements, made after each scandal, do not constitute a security policy. The French have the right to demand better than post-incident patches on systems that manage their most sensitive data. He asks him what structural, and not cyclical, measures he intends to implement to guarantee the security of government information systems; what mandatory audit schedule is planned for all government platforms processing personal data and how the State intends to report to citizens whose data has been compromised on the follow-up given to these repeated incidents.
Machine translation from French. The official text remains authoritative.
Timeline
No timeline events have been ingested for this record yet.
Votes
No vote records are attached yet.
Versions
No version snapshots stored. Document URLs remain at the source.
Documents
No documents linked.
Sponsors
No sponsors or actors listed by the source.
Related records
No cross-record relationships stored yet.
Sources
PoliticalRepo is an index and interpretation layer, not the authoritative legal source.
- Official source: https://www.assemblee-nationale.fr/dyn/17/questions/QANR5L17QE15644
- Open data entity: https://www.assemblee-nationale.fr/dyn/opendata/QANR5L17QE15644