Another cybersecurity incident has been added to the long list of attacks that have hit the French public administration in 2026. INSEE , France's National Statistics and Economic Service , announced that it had fallen victim to a cyberattack , which resulted in the leakage of personal data of approximately 12,800 current and former employees , as well as members of the civil service associated with the organization.

The breach was detected on June 19, immediately triggering security incident response procedures. Although the size of the leak is considered limited compared to other major cyberattacks, the fact that it concerns one of the most important statistical data management bodies in France is deeply concerning.
See also: DDoS attack targeted France's National Postal Service
INSEE: What data was exposed?
According to the official INSEE update, the stolen data includes names, identity details and professional contact information which came from an internal staff directory.
The agency clarified that there was no exposure of passwords, banking information or social security numbers. Equally important, based on the investigations, no access was found to databases containing business and citizen statistics.
For an organization that manages the demographic and economic footprint of an entire country, this assurance is particularly important. The breach concerns a limited set of internal data and not the critical information bases used for public policy-making and statistical analysis of the French economy.
The internal directory found on a cybercrime forum
The exposed files came from trombi.insee.fr, an internal personnel directory that functions more as a corporate employee directory than a repository of sensitive information.
See also: France: France Travail fined for data breach
The database was reportedly posted on a cybercrime forum by a user using the pseudonym “Saturne”. This development reflects a new reality in the world of cyberattacks. Many breaches are no longer accompanied by ransom or blackmail messages. Instead, stolen data is immediately turned into a commodity and offered for sale on underground cyber markets.

Why a "small" leak can create big risks
Individually, a business email or employee name may not seem like a particularly important piece of information. But when thousands of such data are collected and combined with other leaks, they create an extremely valuable tool for cybercriminals.
Staff lists are often used as raw material for attacks and social engineering. Attackers can create convincing messages that appear to come from colleagues, managers, or other public figures, significantly increasing the chances of an attack being successful.
Cybersecurity experts point out that modern attacks are increasingly based on correlating small data sets. Tens of thousands of corporate email addresses can form the basis for a large-scale phishing campaign or targeted attacks on government agencies.
Another blow to French cybersecurity
The INSEE breach comes as France struggles to manage a growing wave of cyberattacks. In 2026, several public institutions have been targeted, including the Interior Ministry, the national secure document service and the government communication platform Tchap.
See also: France Travail: Data breach affects 43 million people
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Analysts attribute the situation to chronic underinvestment in cybersecurity infrastructure, but also to the increasing effectiveness of social engineering attacks that exploit human errors and inadequate protection procedures.

The situation becomes even more interesting considering that Paris is actively promoting the concept of digital sovereignty, encouraging the transition of government services to more independent technological platforms, including the use of Linux instead of Windows.
However, this particular attack proves that cybersecurity is not solely dependent on the software an organization uses. Protecting even a seemingly insignificant internal directory can be just as critical. In an era where data breaches are becoming an everyday occurrence, the greatest risk is not always the value of the information lost, but the frequency with which these losses occur and how they can be exploited in subsequent, more targeted attacks.
