---
title: "The State\'s Technical Debt: An Organized Bankruptcy"
subtitle: "A chronicle of a personal data haemorrhage"
date: 2026-08-18
author: JAS
theme: "Cybersecurity"
keywords: ["data breaches", "technical debt", "cybersecurity", "digital sovereignty", "State"]
image: https://ik.imagekit.io/l2lkwahet/199A/_fuites-donnees-france-dette-technique-etat_L41HvzvJj.jpg
audio: 1
slug: the-states-technical-debt-an-organized-bankruptcy
status: published
faq: [{"q":"What is the core argument of the article about the State's technical debt?","a":"The article argues that the wave of massive data breaches in France is not a string of bad luck but the mechanical result of accumulated, documented, and knowingly ignored technical debt in public information systems. It highlights repeated budgetary and political choices that sacrifice security for rapid delivery of showcase digital services, leading to vulnerabilities left unpatched for years."},{"q":"What are the key figures and dates that illustrate the scale of the data breach crisis?","a":"In 2024, the CNIL recorded 5,629 breach notifications, rising to 6,167 in 2025, with nearly 80 incidents affecting over one million citizens in the last two fiscal years. Major breaches include France Travail (36.8 million files), Viamedis/Almerys (33 million insured), Free (19-24 million subscribers), and ANTS (12 million accounts), totaling over 145 million records leaked since 2023."},{"q":"Why does the DGFiP breach represent a qualitative tipping point?","a":"The DGFiP breach touches the fiscal and cadastral core of the State, exposing tax data like reference tax income, family quotient, withholding rate, and property details for up to 433,485 individuals and 1,082 professionals. Even without compromised passwords, combining patrimonial, tax, and identification data fuels highly plausible scenarios of targeted fraud, spear phishing, and administrative impersonation."},{"q":"How does the article characterize the State's response to these breaches?","a":"The article criticizes the State for a lack of stable doctrine and continuous steering, citing seven digital portfolio holders in eight years, including a minister who lasted less than 24 hours. It argues this ministerial instability prevents long-term cybersecurity strategy, courageous budgetary arbitrations on technical debt, and a coherent digital sovereignty doctrine."},{"q":"What are the GDPR obligations for the State regarding breach notification, and what does the article say about the DGFiP case?","a":"Under GDPR Articles 33 and 34, any data controller, including the State, must notify the CNIL of breaches without undue delay (within 72 hours) and inform data subjects when risk is high. The article clarifies that in the DGFiP case, the CNIL was indeed notified and the ministry will inform individuals, so it is not accurate to claim the State evaded notification."},{"q":"How can 199A Consulting help an organization address technical debt and cybersecurity risks?","a":"199A Consulting, with over 20 years of experience, positions itself as a trusted partner for organizations facing these challenges. We provide strategic framing through audits, governance, and risk assessments, and execution through architecture, build, integration, and training, all aligned with digital sovereignty principles. Our approach ensures security by design and long-term resilience against the systemic failures described in the article. For more information, contact business@199a.agency"}]
---

A date of birth, a social security number, an IBAN, an address, a France Travail identifier. Taken in isolation, each of these fragments seems innocuous. Correlated with one another, cross-referenced across the France Travail, DGFIP, Viamedis, Free or ANTS breaches, they become the raw material of a falsification industry. A malicious actor with enough datasets can today reconstruct a complete, coherent, seemingly verifiable identity. Enough to open a line of credit, hijack an administrative account, or feed a synthetic profile tailored for a targeted social engineering operation.

The threat has become statistical, industrial, cumulative, each new leak enriching an already colossal data graph, where cross-referencing three compromised sources is enough to profile, target and manipulate millions of citizens in large-scale influence or fraud strategies. This is no longer about exposing one individual's privacy. It is the credibility of an entire national digital identification system that collapses, leak after leak, sanction after sanction, crisis statement after crisis statement.

## A chronicle that should no longer surprise anyone

It must be said with the coldness of numbers, because indignation alone is no longer enough. In 2024, the [CNIL recorded 5,629 data breach notifications](https://www.cnil.fr/fr/violations-de-donnees-personnelles-bilan-de-5-annees-de-rgpd), up 20% year on year. In 2025, the counter exploded again: 6,167 notified violations, 9.5% more, with nearly 80 incidents affecting more than one million French citizens over the last two fiscal years, a doubling in one year of the number of massive attacks. France became, in the first half of 2025, the most affected European country and the second in the world behind the United States, with 1.8 million accounts compromised between January and June.

<img src="https://ik.imagekit.io/l2lkwahet/199A/fuites-de-donnees-en-france-trajectoire-hors-de-controle_Z3LqXBZ6E.jpg" alt="fuites-de-donnees-en-france-trajectoire-hors-de-controle" class="img-fluid">

The catalogue of public disasters is truly staggering. France Travail, in March 2024, exposed up to 43 million job seekers, with the CNIL ultimately recording 36.8 million compromised files, sanctioned with a 5 million euro fine in January 2026 for a failing information system, the same operator having already been hit in 2023. Viamedis and Almerys, health third-party payment operators, leaked in January-February 2024 the data of more than 33 million insured persons: civil status, social security numbers, contract guarantees. Free and Free Mobile, in October 2024, let slip the contracts of nearly 19 to 24 million subscribers, including 5.11 million IBANs, earning the operator a record fine of 42 million euros in January 2026. The Agence nationale des titres sécurisés (ANTS), a sovereign portal if ever there was one, saw nearly 12 million accounts affected in April 2025. At the end of 2025, 16 million young people tracked by local missions and 15 million medical records via Cegedim were added to the pile. In total, more than 145 million records have leaked since 2023 in public services, healthcare, telecoms and retail alone, several violations per French resident. INSEE itself, the nation's statistical guardian, saw 12,800 employees exposed. Even the National Museum of Natural History was paralyzed by a cyberattack in 2025. According to ANSSI, ministries and local authorities alone account for 24% of security incidents handled in 2025, alongside education and health.

A necessary addition to this already damning picture: the [DGFiP acknowledged in August 2026 a new data breach](https://cnil.fr/fr/piratage-du-systeme-dinformation-des-impots-les-verifications-sont-en-cours) affecting its information system. The CNIL states that a third party was able to consult and extract information relating to individuals and professionals, including tax data such as the reference tax income, the family quotient and the withholding tax rate, as well as cadastral data such as addresses and surface areas of real estate. For companies, the SIREN number and company name are also mentioned.

The public assessment then became clearer. According to elements reported by [*Le Monde*](https://www.lemonde.fr/pixels/live/2026/08/18/en-direct-piratage-du-site-des-impots-le-gouvernement-detaille-les-trois-fuites-de-donnees-qui-concernent-aussi-les-donnees-cadastrales-et-les-successions_6749047_4408996.html), the breach would concern at most 433,485 individuals and 1,082 professionals, in a set presented by the government as three distinct violations, for a total of around 678,000 affected users.

## A technical debt knowingly ignored

There is no bad luck here. This is the mechanical result of an accumulated, documented, known and never settled technical debt. Application security vendors' reports are damning: in French public administrations, vulnerabilities identified and sometimes patched by the vendor years ago still linger on the servers of local authorities, ministries and institutions, with patching delays reaching five, seven, ten years. This is not about inevitable technological obsolescence, but about repeated budgetary and political choices consisting in sacrificing the security of information systems for the rapid production of showcase digital services.

The CNIL itself notes that 55% of violations notified in 2024 result directly from hacking, a 21% increase in one year, overwhelmingly due to infrastructure security flaws: compromised credentials, lack of segmentation, poorly audited third-party providers.

These are exactly the symptoms of untreated technical debt, of security by design never applied, of patches never budgeted, of audits never followed up.

The DGFiP case gives this idea immediate materiality. Bercy confirmed that the intrusion had been detected as early as June, but without public communication at the time, while the breach may not have been detected immediately. This sequence fuels a classic criticism of public technical debt: late detection, partial visibility over the extent of a compromise and the inability to immediately qualify the exfiltrated data.

## Ministerial negligence elevated to a system

Faced with this haemorrhage, the State should have opposed a stable doctrine, continuous steering, an identified political authority. It offered the opposite: a waltz of digital portfolio holders worthy of a second-rate ministry. Since 2017, Mounir Mahjoubi, Cédric O, Jean-Noël Barrot, Marina Ferrari, Clara Chappaz, then, in October 2025, Naïma Moutchou, whose tenure lasted less than twenty-four hours, the most ephemeral Digital Minister of the Fifth Republic, before Anne Le Hénanff took over the portfolio.

Seven holders in eight years, no doctrinal continuity, a position regularly downgraded from a full ministry to a mere state secretariat drowned in a large Economy ministry, despite a tribune signed by eighty digital personalities demanding a real ministry with resources and a voice in the Council of Ministers. How can one demand a long-term cybersecurity strategy, courageous budgetary arbitrations on technical debt remediation, a coherent digital sovereignty doctrine, when the top of the state apparatus changes face every twelve to eighteen months, sometimes within hours?

## From isolated leaks to the collapse of trust

The real tipping point is qualitative. When the CNIL observes that the number of violations affecting more than one million people doubled in one year, from around twenty to around forty, this is a change in the scale of the threat. A synthetic identity built from authentic fragments, real civil status, real social security number, real administrative history, is infinitely harder to detect than crude fraud. It enables methodical impersonation, the targeting of vulnerable profiles, the manufacture of credible influence campaigns built on verifiable public data. Each additional leak does not only add victims. It enriches a cumulative, permanent attack repository, exploitable by any actor, state or criminal.

And the DGFiP affair further darkens this picture, because it touches the fiscal and cadastral core of the State. Even in the absence, at this stage, of compromised identifiers and passwords according to the CNIL, the combination of patrimonial data, tax data and identification information fuels highly plausible scenarios of targeted fraud, spear phishing and administrative impersonation.

## Notification to the CNIL: the State is not above the law

The obligation to notify personal data breaches does not stop at the administration's doors. The [CNIL recalls that Article 33 of the GDPR](https://www.cnil.fr/fr/services-en-ligne/notifier-une-violation-de-donnees-personnelles) requires any data controller to notify a breach presenting a risk to the rights and freedoms of individuals, without undue delay and, where feasible, within 72 hours. Where the risk is high, Article 34 additionally requires the data subjects to be informed.

This rule also applies to the State and to public bodies that process personal data. The French Data Protection Act explicitly echoes this requirement to notify the CNIL and to communicate with the data subjects pursuant to Articles 33 and 34 of the GDPR.

On the DGFiP case, however, verified sources require a rigorous wording. It is not accurate to claim, as things stand, that the French State evaded notification to the CNIL in this specific affair, since the [CNIL states in writing that it was notified of the violations](https://cnil.fr/fr/piratage-du-systeme-dinformation-des-impots-les-verifications-sont-en-cours) affecting the DGFiP's information system, and specifies that the ministry will inform the data subjects individually.