Skip to main content

Cybersecurity

France's unwritten .gouv.fr security standard: no rate limiting, no intrusion detection, no MFA, and a compulsory post-quantum deadline

· 14 min read · Paul-Antoine Tual

ANSSI cybersecurity data breach post-quantum PQC MFA intrusion detection patch management AI public sector CrowdStrike France

No French agency published a security standard called “no rate limiting, no intrusion detection, no MFA.” The phrase describes what 2026’s run of French public-sector data breaches actually revealed as the operating floor, not a real document, and mistaking the joke for a citation would miss what changed this year: post-quantum migration went from a recommendation to a dated, compulsory deadline, and AI widened the gap between how cheaply an intrusion starts and how expensively an organisation has to defend against it.

  • Five incidents through 2026 (a health-data leak the Ministry of Health had to confirm, the ANTS identity portal, the Tchap government messaging app, the DGFiP tax authority, and the Ministry for Ecological Transition) each trace back to a different missing control, not one shared root cause.
  • A dated ANSSI deadline (2027 for product qualification, 2030 for procurement) turns post-quantum cryptography into a near-term buying decision rather than a 2030s abstraction.
  • CrowdStrike’s own measured breakout times compressed from 84 minutes in 2022 to 29 minutes in 2025, the clearest publicly reported figure for how far AI-assisted attackers pulled ahead.
  • The one lever that keeps showing up in ANSSI’s own guidance, faster and more frequent patch deployment, is unglamorous, measurable, and cheaper than most of what gets sold as “AI security.”

1. What 2026’s breach wave actually shows

Five separate incidents through 2026 give a more precise picture than any single number, because each one exposed a different failure rather than confirming the same story twice.

  • Health-data leak, confirmed by the Ministry of Health on 27 February 2026: the exposure originated at Cegedim’s MonLogicielMedical software, used by doctors’ practices, not a .gouv.fr site itself. Cegedim reported detecting “abnormal application request behaviour” only at the end of 2025, after a database holding between three and fifteen years of history, depending on each practice’s install date, had already accumulated administrative data on up to 15 million patients [1].
  • ANTS / France Titres, disclosed mid-April 2026: the identity portal that manages French ID cards, passports and driving licences was compromised through an insecure direct object reference, a flaw the attacker who claimed responsibility, using the alias “breach3d”, called “elementary” [2]. Up to 19 million records were exposed; French authorities later detained a 15-year-old suspect [3].
  • Tchap, the DINUM-run government messaging app: a hacker using the alias “misere” hijacked a single Ministry of National Education account on 7 June 2026, then extracted 643,459 messages, roughly 13.5 gigabytes, from 876 public discussion rooms. DINUM confirmed 73,467 civil-servant accounts were affected; private, end-to-end encrypted rooms stayed protected [4].
  • DGFiP, the French tax authority, confirmed 12 to 14 August 2026: an attacker using the alias “ZeroBytes” obtained the identifiers of a DGFiP employee and an authorised third party, used them to reach the agency’s VPN, and then ran an internal tool to search for and extract taxpayer records [5]. DGFiP cut off that access in late June but did not establish that data had already been exfiltrated until the attacker advertised it for sale in mid-August, six weeks later. The agency confirmed about 678,000 individuals and businesses affected, a figure it described as still under investigation, covering reference taxable income, withholding rate and, for professionals, company identifiers and cadastral data; online “Finances publiques” account usernames and passwords were not compromised [6].
  • Ministry for Ecological Transition, 2 September 2026: several ministerial sites went down; a hacker claimed to have stolen a database covering 8,166 users, including emails, phone numbers and login identifiers [7].

Prime Minister Sébastien Lecornu put a number on the pattern at the end of April 2026, acknowledging an average of three data thefts a day in France and pointing to administrative systems, some dating back to the 1990s, that were never built for the current threat level [8].

Individuals or accounts affected by five 2026 French public-sector incidents Horizontal bar chart on a logarithmic scale: the Cegedim health-data leak up to 15 million patients, ANTS about 19 million records, Tchap 73,467 accounts, DGFiP about 678,000 taxpayers, and the Ministry for Ecological Transition 8,166 users. People or accounts affected, 2026 (log scale) Health data (Cegedim) ≤ 15,000,000 ANTS / France Titres ≈ 19,000,000 Tchap 73,467 DGFiP ≈ 678,000 Transition écologique 8,166 Bar length is proportional to log₁₀(people or accounts affected), not to the raw count.
Figure 1. The five incidents differ by more than three orders of magnitude, so bars use a logarithmic scale; exact figures are printed at each bar's end. Sources: [1], [2], [4], [6], [7].

2. Why “the basics” keep failing

Each incident above traces to a distinct gap, and treating them as one undifferentiated “lack of security” obscures which control would actually have helped.

  • Broken access control turns a small bug into a mass exfiltration. The ANTS flaw let the attacker in; nothing that throttled or flagged tens of millions of sequential requests is what let the extraction run to 19 million records instead of a handful. Rate limiting and request-pattern monitoring do not fix an insecure direct object reference, but they change how far an attacker gets before someone notices.
  • Detection lag turns a contained incident into a years-long exposure. Cegedim’s “abnormal request behaviour” alert fired at the end of 2025, on a database that had been accumulating patient records for years beforehand. A detection capability only earns its name if it catches the pattern while it is happening, not in a retrospective review.
  • Account takeover targets exactly where authentication is weakest. DGFiP is the clearest documented case: the attacker did not need a technical exploit, only the usurped identifiers of one employee and one authorised third party, to reach a VPN that led straight to an internal search tool over taxpayer records [6]. Tchap’s public disclosures do not specify how its compromised account was obtained, so that case cannot be cited as proof of a missing second factor, but it points at the same broader pattern: privileged or bulk-access accounts remain the highest-value target, and a second factor that a real-time relay attack can still intercept offers less protection than it appears to. Our companion article on 2026 cryptography choices for transport, storage and identity covers that mechanism, adversary-in-the-middle proxies against SMS and TOTP codes, and what WebAuthn’s origin binding actually guarantees, in full.

3. The post-quantum deadline is now dated, not hypothetical

ANSSI’s own FAQ on post-quantum cryptography states the trajectory in terms specific enough to plan against, which is new relative to the “start preparing at some point” guidance of the past few years.

  • 2027: “L’ANSSI vise la mise en place d’obligations PQC pour l’entrée en qualification de produits à partir de 2027” [9], meaning security products entering ANSSI qualification from 2027 will need to demonstrate post-quantum resistance. That mainly affects vendors selling to the French State and to critical-infrastructure operators, not every organisation directly.
  • 2030: the same FAQ states it “ne sera pas raisonnable d’acheter des produits qui n’intègrent pas de la PQC après 2030” [9], a procurement guideline rather than a blanket legal deadline for all organisations.
  • ANSSI reiterated the trajectory publicly at the France Quantum 2026 conference on 16 June 2026, closing what had been a recommendation phase since 2022 [10].
  • The building blocks are already stable: NIST finalised ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) in August 2024, while FN-DSA (FIPS 206, based on Falcon) remains under development [11].
  • Keep ANSSI’s dates separate from the European Union’s own coordinated roadmap, which targets 2030 for high-risk cases and 2035 for the rest: the two timelines come from different bodies and should not be merged into one deadline [12].

For the full transition playbook, inventorying algorithms, testing hybrid key exchange across TLS, IPsec and SSH, and choosing where key management sits, see the companion 2026 cryptography article, which this piece deliberately does not repeat.

4. AI did not just help attackers get in faster, it changed the unit economics

The clearest public evidence that AI is tilting cost asymmetry toward attackers comes from a measurement CrowdStrike has tracked consistently across several annual reports, not from a single vendor’s claim about one incident.

  • Average eCrime “breakout time”, the interval between initial compromise and an attacker’s first move to another system, fell from 84 minutes in 2022 to 62 minutes in 2023, 48 minutes in 2024 and 29 minutes in 2025 [13]. The fastest recorded breakout compressed even faster: 2 minutes 7 seconds in 2023, 51 seconds in 2024, 27 seconds in 2025 [13].
  • CrowdStrike reports AI-enabled adversary operations up 89% year over year, and genuine GenAI tools abused at more than 90 organisations through prompt injection to steal credentials or cryptocurrency [13].
  • Defence does not gain symmetrically. The World Economic Forum’s May 2026 findings show organisations that already use AI extensively in security operations cut average breach costs by up to $1.9 million and shorten the breach lifecycle by roughly 80 days, but that gain went to the smaller share, 77% of organisations reporting some operational AI use, that had already invested in it deliberately [14].
Average eCrime breakout time, 2022 to 2025 Line chart showing CrowdStrike's measured average breakout time falling from 84 minutes in 2022 to 62 in 2023, 48 in 2024 and 29 in 2025, with the steepest drop in the most recent year. Average minutes from compromise to lateral movement 2022: 84 min 2023: 62 min 2024: 48 min 2025: 29 min fastest observed: 27 seconds
Figure 2. The highlighted band marks 2024 to 2025, the year AI-enabled adversary operations rose 89% according to CrowdStrike's own report. Source: [13].

For a mid-sized organisation without a security team the size of a bank’s, the practical reading is blunt: an attacker’s tooling got faster largely for free, through commodity AI, while a comparable defensive gain still requires deliberate staffing, integration and measurement rather than a licence purchase.

5. What actually raises the floor: patch discipline as a daily practice, not a quarterly project

Of the measures available to an organisation without a large security budget, the one with the oldest and clearest evidence base is unglamorous: apply security patches without delay, a discipline ANSSI’s own 42-measure IT hygiene guide places among its foundational recommendations [15].

  • Patch-without-delay only works if it is operationally cheap. That means small, frequent, tested deployments rather than a rare, large, high-risk one. A release pipeline sized for daily changes turns a security patch into a routine event instead of one that needs a change-advisory meeting, which is the practical version of what the brief for this article called a “daily promote.”
  • A comparable international benchmark points the same direction, correctly attributed. Australia’s Cyber Security Centre credits the first four of its Essential Eight controls, application control, patching applications, restricting Microsoft Office macros and user application hardening, with preventing a large share of the intrusions it originally measured [16]. That figure comes from ACSC, not ANSSI; the two agencies publish separate guidance, and this article keeps that distinction rather than blending national sources into one round number.
  • A forced daily restart only earns the name “security control” if something changed behind it. A reboot with no patch applied, no secret rotated and no image rebuilt is uptime housekeeping, not hygiene, however disciplined the schedule looks on a dashboard.
  • None of this replaces the two gaps in section 2. Patch cadence closes a different, complementary problem: it shortens the window during which a known flaw stays exploitable, which is a separate question from whether access control is broken or whether a privileged account has phishing-resistant authentication.
A daily patch and promote loop, compared with a quarterly change window Boxes-and-arrows diagram of a four-step daily loop, patch released, build and test, promote to production, restart and rotate secrets, looping back to the next day, contrasted with a slower quarterly change window. Daily patch and promote loop Patch released Build and test Promote to production Restart, rotate next day Old default: a quarterly change window sized for rare, large releases leaves a known flaw exploitable for months, not hours
Figure 3. The loop only counts as a security control when the restart step forces a genuine change; a schedule with nothing behind it is uptime housekeeping. Source: [15].

Conclusion

The ironic title should stop feeling clever once the five 2026 incidents are on the table side by side, because each one names a specific, fixable gap rather than confirming a vague sense that public administration is insecure.

  • Broken access control, detection lag and weak credential hygiene are code, monitoring and identity problems, not budget problems, and ANTS, the Cegedim leak and DGFiP each show what happens when one of them goes unaddressed.
  • The 2027 and 2030 ANSSI dates turn post-quantum migration into a procurement question to raise with vendors now, not a project for the next decade.
  • CrowdStrike’s own breakout-time trend is the most concrete evidence available that AI shortened the attacker’s timeline faster than most organisations shortened their own detection and patch cycles.
  • A release pipeline built for small, frequent, tested changes is the one lever on this list that a mid-sized organisation can start moving this quarter without waiting on a vendor roadmap or a budget cycle.

Book the Junyr AI maturity audit: a free, no-commitment 30-minute video call to position where your organisation actually stands on these five gaps.


By Paul-Antoine TUAL, AI Transformation Leader, Croissance et Transitions, September 2026.

Sources

  1. Acuité, ‘Le ministère de la Santé confirme la fuite de données médicales de 15 millions de Français’
  2. Bleeping Computer, ‘French govt agency confirms breach as hacker offers to sell data’
  3. Help Net Security, ‘15-year-old detained over massive data breach at French government agency’
  4. DINUM, ‘Incident de sécurité sur Tchap’
  5. DGFiP / impots.gouv.fr, ‘Vol de données suite à des accès illégitimes au système d’information de la DGFiP’
  6. The Record, ‘French tax authority DGFiP confirms data breach’
  7. Generation-NT, ‘Panne au ministère de la Transition écologique, plusieurs sites gouvernementaux inaccessibles’
  8. ePlaque, ‘Cyberattaques ANTS, DGFiP et compagnie en 2026 : que faire ?’
  9. ANSSI, ‘FAQ sur la cryptographie post-quantique’
  10. IT Social, ‘À partir de 2027, l’ANSSI ne certifiera plus les produits de sécurité sans cryptographie post-quantique’
  11. NIST, ‘NIST Releases First 3 Finalized Post-Quantum Encryption Standards’
  12. European Commission, ‘Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography’
  13. CrowdStrike, ‘2026 Global Threat Report: AI Accelerates Adversaries and Reshapes the Attack Surface’
  14. World Economic Forum, ‘New report shows how AI gives cybersecurity a competitive advantage’
  15. ANSSI, ‘Guide d’hygiène informatique’
  16. Australian Cyber Security Centre, ‘Essential Eight’

Frequently asked questions

Is there an official .gouv.fr security standard that actually says no rate limiting, no intrusion detection and no MFA?

No: no such document exists. The phrase describes what 2026's run of French public-sector breaches revealed in practice as the operating floor, not a published requirement.

  • Five incidents in 2026 (the Cegedim health-data leak, ANTS, Tchap, DGFiP, the Ministry for Ecological Transition) each trace to a different missing control.
  • Treating the joke as literal would miss the point: the gap is between what ANSSI recommends and what got deployed, not an official rule.
  • ANSSI's own hygiene guide and cryptography recommendations already cover rate limiting, detection and phishing-resistant authentication.
Does the 2027 ANSSI deadline mean every French SME must adopt post-quantum cryptography by then?

No: ANSSI's own FAQ targets 2027 for bringing PQC obligations into product qualification, not a blanket compliance deadline for every organisation.

  • 2027 concerns products entering ANSSI qualification, which mainly affects vendors selling to the State and critical-infrastructure operators.
  • ANSSI considers it unreasonable to buy non-PQC products after 2030, which is a procurement guideline, not a universal legal deadline.
  • An organisation's actual priority depends on how long its data must stay confidential and its equipment renewal cycle.
If the ANTS breach was caused by a broken access control flaw, would rate limiting have prevented it?

Not on its own: the entry point was an insecure direct object reference, a coding flaw that rate limiting does not fix by itself.

  • Rate limiting and anomaly detection do not close a broken access control flaw; only fixing the authorisation check does that.
  • They do reduce the odds that a single flawed endpoint turns into a multi-million-record exfiltration before anyone notices.
  • The two controls solve different problems and are both needed: prevention at the code level, containment at the traffic level.
Does using AI for security automatically lower breach costs?

No: the World Economic Forum's 2026 findings apply to organisations that already use AI extensively and deliberately in security operations, not to AI adoption in general.

  • The reported gains (lower average breach cost, shorter breach lifecycle) went to the smaller share of organisations with mature, operational AI security use.
  • Attackers get comparable AI capability from commodity tools at far lower cost and integration effort.
  • Defensive AI needs the same investment discipline as any other security control: staffing, integration, measurement.
Is a daily reboot of production systems itself a security measure?

No: a restart with no patch, secret rotation or configuration change behind it is uptime housekeeping, not hygiene.

  • The security value comes from what the restart forces: a genuinely applied patch, a rotated credential, a rebuilt image.
  • A release pipeline sized for small, frequent, tested changes is what makes daily patching operationally realistic.
  • A quarterly change window sized for rare, large releases is the pattern that leaves a known flaw unpatched the longest.
Paul-Antoine Tual

Paul-Antoine Tual

AI Transformation Leader · Junyr Method™ · Transition manager specialising in AI for French SMEs and mid-caps. Engineer from the École des Mines de Nantes, lawyer, developer since 1993.