On 22 January 2026, CNIL, the French data protection authority, fined France Travail, the national employment agency (formerly Pôle emploi), €5 million. The reason: the March 2024 attack exposed the data of 36.8 million people — names, social security numbers, login IDs, addresses, phone numbers — and the agency had identified the necessary measures in its own risk assessments without ever deploying them (Usine Digitale).
The same month, Urssaf, the body that collects social security contributions from every business, announced a breach affecting 12 million people. In February, the DGFiP, the French tax authority, admitted that 1.2 million records from FICOBA, the national register of every bank account opened in France, had been exposed: account holders' identity, address and bank details. In April, the ANTS, the agency that issues ID cards, passports, driving licences and vehicle registration documents, confirmed a cyberattack on 11.7 million accounts, and the Ministry of Education an intrusion via ÉduConnect, the login portal for pupils and parents, affecting millions of minors. In August, France VAE (the public portal for recognition of prior learning), then an HR contractor working for France Travail (Wikipedia, 2026 list, dpo-partage.fr, Shattered).
This isn't a bad run; it's the permanent state of affairs. CNIL received 6,167 breach notifications in 2025, a record, up nearly 50% in two years; around forty of them involved more than a million people each (Cyberini). Between 2024 and 2025, more than 145 million records about French residents were exposed, public services included (Corbado).
Is France alone in this?
No — and that makes it worse, not better. The phenomenon is global: 425.7 million accounts compromised worldwide in 2025, and 210 million in the first quarter of 2026 alone, the worst quarter ever recorded (Surfshark, quarterly tracker). But France stands apart: the highest breach density in the world in 2025, twelve times the global average per head of population; and in the first half of 2026, 43.4 million French accounts compromised — 58% of all compromised accounts in Europe, second in the world behind the United States (Surfshark, via AzerNews). Those figures count accounts in databases doing the rounds, not incidents; they still put France, on its own, at the top of an entire continent.
Its neighbours aren't spared either, and every country has its own "France Travail".
Spain. In May 2024, a database of 34.5 million rows attributed to the Dirección General de Tráfico (DGT, the national driving-licence and vehicle-registration agency) — names, addresses, number plates and vehicles for almost every driver in the country — went up for sale on a forum, hot on the heels of the Santander, Iberdrola and Telefónica leaks (Unitel, Yahoo Noticias). In January 2025, data from the Guardia Civil and the armed forces (PSN Sercon). Between November 2025 and February 2026, the prime minister's office itself — the Moncloa — went around a hundred days without protection against advanced attacks; data on the prime minister, ministers and the chief of the defence staff leaked, along with the credentials of hundreds of police officers and civil guards; the European Commission opened proceedings against Spain for failing to transpose NIS2 (Digital Perito). In August 2026, a hacker put up for sale what he claimed was the data of every Spanish social security (INSS) pensioner — DNI numbers (the Spanish ID card), addresses, bank details — a claim the INSS hasn't confirmed, but one the researchers who examined it found plausible (Cybernews).
Italy. The heaviest blow didn't land on a government department but on its contractor: in May 2026, Sistemi Informativi, the IBM subsidiary that has run the infrastructure of ministries, the INPS (the pensions and social security institute) and INAIL (the workplace-accident insurer) for decades, was compromised by the Chinese group Salt Typhoon, which stayed inside the systems for weeks; the scale of the exfiltration hasn't been quantified (Il Giornale, Tom's Hardware). Before that, the Lazio Region — the region around Rome, which runs the health system for six million residents — was paralysed in 2021 by ransomware that got in through an employee's laptop, blocking bookings, payments and vaccinations for millions of patients (Garante privacy), and the ASL of L'Aquila (the local health authority) in 2023, whose medical records were published. Attacks on Italian public health more than doubled between 2023 and 2024 — one every three days is expected in 2026 (Il Sole 24 Ore) — and according to the Clusit report (the Italian IT security association, the sector's annual benchmark), Italian public bodies suffered 10% of the serious incidents recorded worldwide in 2025 (TechPost).
Portugal. In October 2024, ransomware hit the AMA, the administrative modernisation agency that runs gov.pt (the online public-services portal) and the Chave Móvel Digital (the national digital identity, Portugal's equivalent of FranceConnect) — and took online services down for days; the government says no data leaked (Sábado). The country logged a record 2,758 incidents in 2024, and cyberattacks there have risen by more than 700% since 2019 according to the CNCS, Portugal's national cybersecurity centre; hospitals, media outlets and municipalities have already been hit (CNCS via Ajuda à Informática).
Three countries, one pattern: highly centralised national registers where a single breach hits tens of millions of people; shared contractors whose compromise becomes the whole state's; and paperwork going digital faster than the means to protect it. You won't change any of the three. But in every one of these countries the same rule holds: what you never handed over can't leak.
What this changes for you
You don't get to choose how secure France Travail or the ANTS are. You can't refuse to give them your social security number. But you decide everything else: what you attach on top, in what form, through which channel, and how many third parties touch the document before it arrives.
And these breaches make one thing concrete: what leaks is almost never a password, it's a profile — name, address, social security number, IBAN, employer, circumstances. That profile then feeds targeted scams (the fake bank adviser who knows your bank and your address) and identity theft, which hits several hundred thousand people a year (beta.gouv.fr). Every extra document you supplied "just in case" — a full ID card where a certificate would have done — fills in that profile.
Six reflexes, from the simplest to the most structural.
1. Send only what's required
It's the most effective reflex and the least practised. A document that was never sent can't leak.
- Read the exact list of documents requested, and don't supply any others. For a rental application, a 2015 decree limits what a landlord can demand; for an ANTS procedure, the list is on the procedure's page.
- One document per file, never "the whole application" in a single PDF: you don't know which department, contractor or officer will see each file.
- Keep only the pages that matter. The fifteen-page employment contract when only the first page is wanted; the bank statement where a single line counts; the tax notice where all they want is your reference income. Delete pages before sending.
- Redact properly whatever isn't asked for: an IBAN on a statement, a social security number on a payslip when only the salary is required. Not with a black rectangle — with a method that holds, and Redact PDF does it locally.
- Prefer single-use proofs where they exist: France Identité, the state's digital identity app, generates a proof of identity valid once, for one named recipient, from the new-format ID card (francenum.gouv.fr). A proof that leaks is no use to anyone.
2. Watermark every copy
A copy of an ID card marked "For the ANTS only — passport application — 12/09/2026" can't open an account or take out a loan. If it turns up in a breach, it says where it came from. The state itself recommends this and launched FiligraneFacile for the purpose (France Travail).
What to write (purpose, recipient, date) and how to apply it in your browser without sending the document anywhere — not even to FiligraneFacile's server — is covered in Why you should watermark your ID card. Tool: Watermark PDF.
The same goes for payslips, tax notices, bank details, the family record book: anything that, combined, makes up an identity-theft kit.
3. One e-mail address per service: the "+" that traces leaks
With most providers (Gmail, Outlook, iCloud, Proton, Fastmail), anything after a + in the local part of the address is ignored on delivery: marie.durand+ants@gmail.com lands in the inbox of marie.durand@gmail.com. Use one variant per service — +francetravail, +urssaf, +impots, +landlord2026.
Three effects:
- You'll know where the leak came from. The day a phishing e-mail lands on
+urssaf, the question "who let my address slip?" has its answer. - You can filter. An e-mail claiming to come from France Travail but addressed to
+impotsis a fake, without reading a single line. - You can cut it off. A mailbox rule sends
+landlord2026to the bin once the lease is signed.
Limits worth knowing: some forms reject the + (over-strict address validation), and a savvy fraudster can strip it out. For those cases, aliases are sturdier: Firefox Relay, SimpleLogin, Apple's "Hide My Email", or the built-in aliases in Proton and Fastmail generate a separate address per service, forwarded to yours, and switched off in one click.
Same logic for your phone: a secondary number (second SIM, virtual number) for official business, and a personal number that sits in no database.
4. One password per service, and two-factor authentication everywhere
What leaks gets used to break in elsewhere. A unique password per service, in a password manager (the browser's will do to start with), and two-factor authentication wherever it's offered — FranceConnect offers it, as do most public portals since CNIL started requiring MFA on any database of more than a million people (Fiduciaire Yadan).
And one simple rule: you never give a code received by text to someone who calls you, whatever name shows on the screen. No adviser, no government department asks for it.
5. Don't add a third party to the chain
This is the point this article adds to the usual advice. Every time you prepare a document for a procedure — compressing it to get under the ANTS's 1 MB limit, converting it to PDF, merging it — you choose whether or not to add one more server between you and the administration.
The "free" online converter you compress your ID card on keeps the file for an hour or two on an unnamed cloud, under a jurisdiction you don't know (we read their pages). You've just doubled the number of organisations that could leak your ID, to save thirty seconds.
Every preparation step — compress, convert a photo, delete pages, rotate, watermark, redact — runs on PDFKami in your browser, with nothing uploaded; you can do it in flight mode. The only server that will receive the document is the administration's, because there's no way round that one.
6. Find out whether you're affected, and what to do next
- Check your addresses on haveibeenpwned.com, which catalogues public breaches. With
+serviceaddresses, you'll also know which one leaked. - Read the notifications: organisations are required to inform you when a breach poses a high risk. The e-mail from France Travail or Urssaf isn't spam — but check it contains no link to click; the genuine ones point you to the official site, for you to type in yourself.
- After a breach that affects you: change the password for that service and for any service where you reused it; keep an eye on your bank accounts and your inbox; be wary, for months, of calls and e-mails that "know" your details — that's precisely what leaked.
- If your identity is stolen: file a police report, report it on cybermalveillance.gouv.fr, contact CNIL. At that point, a watermark on your copies is the proof of where the copy being used came from.
What these breaches shouldn't push you into
Giving up on online procedures is neither possible nor desirable; paper post isn't safer, and it's slower. The right reflex isn't distrust, it's parsimony: give what's asked for, in a form that serves only what's asked for, through a channel that doesn't multiply the middlemen. You won't fix France Travail's IT systems. You can make sure what they hold on you is the bare minimum.
Notes — the bodies mentioned
For readers who don't know them, and for the translated versions of this article.
France
- CNIL: Commission nationale de l'informatique et des libertés, the data protection authority; it receives breach notifications and issues fines.
- France Travail: the national employment agency, formerly Pôle emploi, which registers jobseekers and pays unemployment benefit.
- Urssaf: the body that collects social security contributions from businesses and the self-employed; it holds data on every employee and employer.
- DGFiP and FICOBA: the Direction générale des finances publiques is the tax authority; FICOBA is the national register of every bank account opened in France and its holders.
- ANTS: Agence nationale des titres sécurisés, which issues ID cards, passports, driving licences and vehicle registration certificates.
- ÉduConnect: the single login portal for pupils and parents to Ministry of Education services.
- HubEE / DINUM: HubEE is a platform for exchanging procedures between administrations, run by the Direction interministérielle du numérique, the state's IT department.
- France VAE: the public portal for recognition of prior learning (validation des acquis de l'expérience).
- FranceConnect: the single sign-on system for online public services.
Spain
- DGT: Dirección General de Tráfico, the national driving-licence and vehicle-registration agency.
- Moncloa: the palace and offices of the Spanish prime minister.
- INSS: Instituto Nacional de la Seguridad Social, the pensions and social security institute.
- DNI: Documento Nacional de Identidad, the Spanish ID card, whose number serves as an identifier in most official procedures.
- NIS2: the EU directive on cybersecurity for essential entities, which each member state must transpose into national law.
Italy
- INPS: Istituto Nazionale della Previdenza Sociale, the pensions and social security institute.
- INAIL: Istituto Nazionale Assicurazione Infortuni sul Lavoro, the workplace-accident insurer.
- Regione Lazio: the region around Rome, responsible for the regional health system.
- ASL: Azienda Sanitaria Locale, the local health authority that runs care in a given area.
- Clusit: Associazione Italiana per la Sicurezza Informatica, whose annual report is the sector's reference.
- Salt Typhoon: a hacking group linked to Chinese intelligence, already behind intrusions at US telecoms operators.
Portugal
- AMA: Agência para a Modernização Administrativa, which runs the state's digital services.
- gov.pt and Chave Móvel Digital: the online public-services portal and the national digital identity.
- CNCS: Centro Nacional de Cibersegurança, the national cybersecurity centre.