PDF Kami EU-Hosted

Blog

When public services get hacked, what happens to your documents?

France Travail, Urssaf, ANTS, the FICOBA bank-account register: French state data breaches keep piling up. You don't control their security; you control what you hand over. Six concrete reflexes.

On 22 January 2026, CNIL, the French data protection authority, fined France Travail, the national employment agency (formerly Pôle emploi), €5 million. The reason: the March 2024 attack exposed the data of 36.8 million people — names, social security numbers, login IDs, addresses, phone numbers — and the agency had identified the necessary measures in its own risk assessments without ever deploying them (Usine Digitale).

The same month, Urssaf, the body that collects social security contributions from every business, announced a breach affecting 12 million people. In February, the DGFiP, the French tax authority, admitted that 1.2 million records from FICOBA, the national register of every bank account opened in France, had been exposed: account holders' identity, address and bank details. In April, the ANTS, the agency that issues ID cards, passports, driving licences and vehicle registration documents, confirmed a cyberattack on 11.7 million accounts, and the Ministry of Education an intrusion via ÉduConnect, the login portal for pupils and parents, affecting millions of minors. In August, France VAE (the public portal for recognition of prior learning), then an HR contractor working for France Travail (Wikipedia, 2026 list, dpo-partage.fr, Shattered).

This isn't a bad run; it's the permanent state of affairs. CNIL received 6,167 breach notifications in 2025, a record, up nearly 50% in two years; around forty of them involved more than a million people each (Cyberini). Between 2024 and 2025, more than 145 million records about French residents were exposed, public services included (Corbado).

Timeline of the main data breaches at French public services from 2024 to 2026: France Travail 36.8 million, Urssaf 12 million, ANTS 11.7 million accounts, FICOBA 1.2 million bank accounts, ÉduConnect several million pupils, HubEE 160,000 documents

Is France alone in this?

No — and that makes it worse, not better. The phenomenon is global: 425.7 million accounts compromised worldwide in 2025, and 210 million in the first quarter of 2026 alone, the worst quarter ever recorded (Surfshark, quarterly tracker). But France stands apart: the highest breach density in the world in 2025, twelve times the global average per head of population; and in the first half of 2026, 43.4 million French accounts compromised — 58% of all compromised accounts in Europe, second in the world behind the United States (Surfshark, via AzerNews). Those figures count accounts in databases doing the rounds, not incidents; they still put France, on its own, at the top of an entire continent.

Its neighbours aren't spared either, and every country has its own "France Travail".

Spain. In May 2024, a database of 34.5 million rows attributed to the Dirección General de Tráfico (DGT, the national driving-licence and vehicle-registration agency) — names, addresses, number plates and vehicles for almost every driver in the country — went up for sale on a forum, hot on the heels of the Santander, Iberdrola and Telefónica leaks (Unitel, Yahoo Noticias). In January 2025, data from the Guardia Civil and the armed forces (PSN Sercon). Between November 2025 and February 2026, the prime minister's office itself — the Moncloa — went around a hundred days without protection against advanced attacks; data on the prime minister, ministers and the chief of the defence staff leaked, along with the credentials of hundreds of police officers and civil guards; the European Commission opened proceedings against Spain for failing to transpose NIS2 (Digital Perito). In August 2026, a hacker put up for sale what he claimed was the data of every Spanish social security (INSS) pensioner — DNI numbers (the Spanish ID card), addresses, bank details — a claim the INSS hasn't confirmed, but one the researchers who examined it found plausible (Cybernews).

Italy. The heaviest blow didn't land on a government department but on its contractor: in May 2026, Sistemi Informativi, the IBM subsidiary that has run the infrastructure of ministries, the INPS (the pensions and social security institute) and INAIL (the workplace-accident insurer) for decades, was compromised by the Chinese group Salt Typhoon, which stayed inside the systems for weeks; the scale of the exfiltration hasn't been quantified (Il Giornale, Tom's Hardware). Before that, the Lazio Region — the region around Rome, which runs the health system for six million residents — was paralysed in 2021 by ransomware that got in through an employee's laptop, blocking bookings, payments and vaccinations for millions of patients (Garante privacy), and the ASL of L'Aquila (the local health authority) in 2023, whose medical records were published. Attacks on Italian public health more than doubled between 2023 and 2024 — one every three days is expected in 2026 (Il Sole 24 Ore) — and according to the Clusit report (the Italian IT security association, the sector's annual benchmark), Italian public bodies suffered 10% of the serious incidents recorded worldwide in 2025 (TechPost).

Portugal. In October 2024, ransomware hit the AMA, the administrative modernisation agency that runs gov.pt (the online public-services portal) and the Chave Móvel Digital (the national digital identity, Portugal's equivalent of FranceConnect) — and took online services down for days; the government says no data leaked (Sábado). The country logged a record 2,758 incidents in 2024, and cyberattacks there have risen by more than 700% since 2019 according to the CNCS, Portugal's national cybersecurity centre; hospitals, media outlets and municipalities have already been hit (CNCS via Ajuda à Informática).

Three countries, one pattern: highly centralised national registers where a single breach hits tens of millions of people; shared contractors whose compromise becomes the whole state's; and paperwork going digital faster than the means to protect it. You won't change any of the three. But in every one of these countries the same rule holds: what you never handed over can't leak.

What this changes for you

You don't get to choose how secure France Travail or the ANTS are. You can't refuse to give them your social security number. But you decide everything else: what you attach on top, in what form, through which channel, and how many third parties touch the document before it arrives.

And these breaches make one thing concrete: what leaks is almost never a password, it's a profile — name, address, social security number, IBAN, employer, circumstances. That profile then feeds targeted scams (the fake bank adviser who knows your bank and your address) and identity theft, which hits several hundred thousand people a year (beta.gouv.fr). Every extra document you supplied "just in case" — a full ID card where a certificate would have done — fills in that profile.

Six reflexes, from the simplest to the most structural.

1. Send only what's required

It's the most effective reflex and the least practised. A document that was never sent can't leak.

2. Watermark every copy

A copy of an ID card marked "For the ANTS only — passport application — 12/09/2026" can't open an account or take out a loan. If it turns up in a breach, it says where it came from. The state itself recommends this and launched FiligraneFacile for the purpose (France Travail).

What to write (purpose, recipient, date) and how to apply it in your browser without sending the document anywhere — not even to FiligraneFacile's server — is covered in Why you should watermark your ID card. Tool: Watermark PDF.

The same goes for payslips, tax notices, bank details, the family record book: anything that, combined, makes up an identity-theft kit.

3. One e-mail address per service: the "+" that traces leaks

With most providers (Gmail, Outlook, iCloud, Proton, Fastmail), anything after a + in the local part of the address is ignored on delivery: marie.durand+ants@gmail.com lands in the inbox of marie.durand@gmail.com. Use one variant per service — +francetravail, +urssaf, +impots, +landlord2026.

Three effects:

Limits worth knowing: some forms reject the + (over-strict address validation), and a savvy fraudster can strip it out. For those cases, aliases are sturdier: Firefox Relay, SimpleLogin, Apple's "Hide My Email", or the built-in aliases in Proton and Fastmail generate a separate address per service, forwarded to yours, and switched off in one click.

Same logic for your phone: a secondary number (second SIM, virtual number) for official business, and a personal number that sits in no database.

4. One password per service, and two-factor authentication everywhere

What leaks gets used to break in elsewhere. A unique password per service, in a password manager (the browser's will do to start with), and two-factor authentication wherever it's offered — FranceConnect offers it, as do most public portals since CNIL started requiring MFA on any database of more than a million people (Fiduciaire Yadan).

And one simple rule: you never give a code received by text to someone who calls you, whatever name shows on the screen. No adviser, no government department asks for it.

5. Don't add a third party to the chain

This is the point this article adds to the usual advice. Every time you prepare a document for a procedure — compressing it to get under the ANTS's 1 MB limit, converting it to PDF, merging it — you choose whether or not to add one more server between you and the administration.

The "free" online converter you compress your ID card on keeps the file for an hour or two on an unnamed cloud, under a jurisdiction you don't know (we read their pages). You've just doubled the number of organisations that could leak your ID, to save thirty seconds.

Every preparation step — compress, convert a photo, delete pages, rotate, watermark, redact — runs on PDFKami in your browser, with nothing uploaded; you can do it in flight mode. The only server that will receive the document is the administration's, because there's no way round that one.

6. Find out whether you're affected, and what to do next

What these breaches shouldn't push you into

Giving up on online procedures is neither possible nor desirable; paper post isn't safer, and it's slower. The right reflex isn't distrust, it's parsimony: give what's asked for, in a form that serves only what's asked for, through a channel that doesn't multiply the middlemen. You won't fix France Travail's IT systems. You can make sure what they hold on you is the bare minimum.

Notes — the bodies mentioned

For readers who don't know them, and for the translated versions of this article.

France

Spain

Italy

Portugal

FAQ

Is France the only country affected?

No. The phenomenon is global, but France had the highest breach density in the world in 2025 and accounts for 58% of compromised accounts in Europe in the first half of 2026. Spain (DGT, Moncloa), Italy (the INPS and INAIL contractor, Lazio Region) and Portugal (AMA, gov.pt) have had major attacks of their own.

Which French public bodies have been hacked recently?

France Travail (March 2024, 36.8 million people, €5 million CNIL fine in January 2026), Urssaf (January 2026, 12 million), the DGFiP via the FICOBA register (February 2026, 1.2 million bank accounts), the ANTS (April 2026, 11.7 million accounts), the Ministry of Education via ÉduConnect (April 2026), DINUM's HubEE platform (January 2026) and France VAE (August 2026), among others.

How do I know whether my data has leaked?

Organisations must notify you when there's a high risk. You can also check your addresses on haveibeenpwned.com. Separate addresses per service let you pinpoint the source.

What's the point of an e-mail address with a "+"?

name+service@ lands in your usual inbox but identifies the service you gave it to: you know where a leak or a phishing attempt came from, and you can filter. Aliases (Firefox Relay, SimpleLogin, Apple) do the same thing more robustly.

Should I watermark documents I send to public bodies?

Yes, as with any recipient: a copy marked with the purpose, recipient and date is useless elsewhere and traceable if it leaks. The state recommends it.

Can I refuse to give my social security number?

Not when the procedure legally requires it. You can, however, refuse to supply documents that weren't requested, attach only the relevant pages, and redact whatever the procedure doesn't need.

Is compressing my ID card online risky?

You're adding a third-party server — often under foreign jurisdiction — to the list of those holding your ID. The same operations run in the browser, with nothing uploaded, on PDFKami.

Read next

← All articles