France Recorded Over 145 Million Data Exposures in Two Years as Dark Web Activity Targeting the Country Quadrupled

France-linked underground cyber activity has increased more than fourfold over the past two years, with stolen credentials, personal data, ransomware advisories and hacktivist claims rising sharply across dark web forums and cybercriminal channels.

Monthly activity climbed from fewer than 300 items in mid-2024 to more than 1,400 at its peak in January 2026. It remained above 1,000 items per month through spring 2026, pointing to a sustained expansion of the underground market for French data rather than a short-lived spike caused by a single breach.

These findings are part of a new CloudSEK report, France Cyber Threat Outlook: Dark Web, Ransomware, and Hacktivism Trends,” which analysed approximately 17,800 France-related threat intelligence items recorded over 24 months.

The report shows that stolen credentials and infostealer logs account for a significant share of the increase, while government organisations, financial services, technology companies and telecom providers remain among the most exposed sectors.

It also highlights a parallel rise in ransomware activity targeting smaller organisations and municipalities, alongside sustained pro-Russian hacktivist campaigns against French ministries, aviation entities, drone manufacturers and other policy-linked organisations.

Stolen credentials are driving the underground market

The increase is being fuelled primarily by the mass harvesting and circulation of passwords, authentication data and personal information, rather than only by large corporate breaches.

The research identified:

  • 4,447 account credential exposures
  • 4,360 credential collections
  • 4,011 combined datasets
  • 3,565 breached-record listings
  • 977 authentication-token exposures

This pattern reflects the growing use of infostealer malware, which extracts credentials, browser data, cookies and authentication tokens from infected systems. The stolen information is then packaged into combolists, sold on underground forums or distributed freely to support fraud and account takeover. 

CloudSEK researchers found that this low-cost, high-volume model is making stolen access easier to acquire and reuse across multiple platforms.

French personal data is being traded at low cost

In one case, approximately two million records allegedly belonging to French women were advertised for $399. In another, nearly 489,000 French records were distributed through a forum-based access mechanism rather than offered through a conventional sale.

The research also identified fabricated databases advertised in the names of trusted French institutions, including ANTS, the national secure-documents agency, and CPAM, the national health insurance system.

Such activity can enable phishing, impersonation and fraud even when the institution named in the listing has not suffered a confirmed breach.

Government organisations face the highest exposure

CloudSEK research shows that government recorded the highest level of France-related exposure over the two years, with 1,652 items.

It was followed by:

  • Financial services: 1,594
  • Technology: 1,491
  • Telecommunications: 1,480
  • Email-related exposure: 1,427
  • Retail: 1,197
  • E-commerce: 1,089

The prominence of government reflects a combination of leaked credentials, ransomware pressure on municipalities and politically motivated targeting of ministries and public agencies. 

Ransomware pressure is concentrated on smaller organisations

The research recorded 213 France-tagged ransomware advisories over the past six months. Some victims were posted more than once, meaning the total should not be interpreted as the number of unique organisations attacked.

Even after accounting for repeated listings, the data shows that municipalities and smaller organisations remain recurring targets, particularly where security teams and incident-response capabilities are limited.

Groups including Qilin and MedusaLocker were linked to claims involving French local authorities. Repeated listings of the same victim suggest that ransomware operators may use staged disclosures to prolong pressure during extortion attempts.

Pro-Russian hacktivism adds a geopolitical threat

The report identified 742 France-related hacktivism items over six months, with the activity dominated by the pro-Russian group NoName057(16). 

The group claimed distributed denial-of-service attacks and unauthorized access involving French ministries, civil aviation bodies, drone manufacturers and private organisations.

Several of these campaigns were explicitly framed as retaliation for France’s support for Ukraine and its position on sanctions against Russia.

CloudSEK assesses that this activity represents a continuing operational risk for organisations associated with government, defence, aerospace and public policy, rather than an isolated wave of disruption.

Regulatory consequences are becoming more serious

The rise in underground cyber activity is taking place alongside stricter enforcement of data-protection and security obligations in France. Recent CNIL actions have focused on failures such as inadequate authentication, excessive access permissions and insufficient protection of personal data.

These weaknesses closely mirror the patterns identified in the report, particularly credential exposure, weak access controls and third-party risk.

For affected organisations, the impact of a breach can therefore extend beyond operational disruption to include regulatory penalties, mandatory remediation and reputational damage.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading