French Cybersecurity Agency ANSSI and Tracfin Hit by Data Breach
The French cybersecurity agency ANSSI, along with the interministerial digital department DINUM and the anti-money laundering service Tracfin, have suffered a data breach. According to an operation REACTIV report published on September 30, 118 user accounts at the ANSSI innovation laboratory were compromised. The breach was caused by an SQL injection vulnerability in Metabase, identified as CVE-2026-72898, which allows attackers to gain administrative access. While a patch has been available since August 6, nine ministerial instances were affected. ANSSI has since updated its systems, reset passwords, and deactivated dormant accounts.
Summaries are written by AI from the original article. Not investment advice.