5 ms·
French government agency confirms breach as hacker offers to sell data
- ahigherugliness 6mo ago19 millions de Français! Et moi, et moi, et moi.
- hmokiguess 6mo agoC’est la vie.
- Zealotux 6mo agoGreat, now scammers can steal my identity directly from the government. I hope they release a tool to check if I'm impacted or at least email me about it.
- Oras 6mo agoare govs required to comply with GDPR and data breaches laws?
- nxm 6mo agoYes, but unelected bureaucrats only impose fines on the private sector.
- nick486 6mo agowhat would be the point of the government fining itself though? Now that I'm thinking of it, it would create the need for an extra gaggle of bureaucrats to oversee the process,so I suppose someone might see a point to it ...
- vladvasiliu 6mo agoYou may think you're funny or something, but boy do I have news for you. There absolutely are fines for French administrations. And, knowing the French tax system, they've probably found a way to levy VAT and some other taxes on top of those fines.
- whyagaindavid 6mo agoDo you mean fines for tiny companies?
- infamouscow 6mo agoThere are carve-outs to allow for governments to make exceptions, but it's besides the point. If the government were to hold themselves to account, they would fine themselves some amount N, and pay itself N using your taxes. It also wastes other finite resources for all the paperwork and legal action involved that could be used for something else. Speaking pragmatically, there's no point trying to hold the government itself to it's own laws. The only time citizens do hold the government accountable, it's always done in the form of hangings, or the guillotine in France's case.
- doublerabbit 6mo agoAlternatively, hackers can now be used as a method of age identification.
- john_strinlai 6mo ago>I hope they release a tool to check if I'm impacted or at least email me about it. "ANTS stated that it is currently in the process of notifying those identified as impacted."
- realusername 6mo agoWith the number of leaks the French administration had everywhere, you don't need a tool, you are guaranteed to be impacted.
- psychoslave 6mo ago"Our government successfully achieved wide distribution of valuable assets in the era of digital information."
- Avamander 6mo agoWhy would those pieces of data (DOB, full name, address) ever be sufficient for identity theft? If that's sufficient to achieve anything then those systems are built on top of hopes and dreams.
- rationalist 6mo agoIt's good enough for health insurance fraud. Edit: does someone not realize that many (all?) the doctors and hospitals use to verify you is your name and date of birth (in the U.S. - although I suppose that's why since this breach happened elsewhere)?
- tomjen3 6mo agoBecause the world is run by people who don't know anything, but have to pretend they know everything, so they can't ask those of us who have some idea about how IT security works.
- buttersicle 6mo ago[dead]
- loupol 6mo agoI received the email telling me I am impacted today. Ironically it changes nothing for me as that same data had already been leaked by the French government agency that handles unemployment benefits a couple years ago. Silly me had not bothered deleting that account even after it was no longer necessary due to finding a new job.
- pixel_popping 6mo agoA copy of it would be nice for record purpose (so Anthropic and OpenAI can have it in their dataset :))
- gniv 6mo agoIs it from ANTS? I haven't gotten anything yet.
- rawgabbit 6mo agoIt seems to me we must move away from worrying about ransomware, data breach, data protection as that ship has already sailed and everyone's PII has already been stolen. We should think of how to verify people's identities online (for things like government benefits etc). I have heard of the Dutch and the Japanese using national digital identity systems although I am unclear how they work. India is doing biometrics. I am curious what the US will eventually land on.
- afarah1 6mo agoBiometrics is just something else to get leaked, terrible idea because it's even more sensitive (can be used to track you through cameras for example, like used in the Iran war). This problem has long been solved with federated IdPs and MFA - something you own like OTP device/physical token besides something you know like SSN/tax id/password. Most governments prefer biometrics of course because citizen privacy is the opposite of what they want.
- anonym29 6mo agoBiometrics are the only credential you can't roll after compromise.
- artursapek 6mo agothis is exactly my problem with them
- lostlogin 6mo agoIt depends what the biometrics are. There have been successful hand transplants, so new finger prints are possible, but completely impractical. https://en.wikipedia.org/wiki/Hand_transplantation https://en.wikipedia.org/wiki/Hand_transplantation
- ntoskrnl_exe 6mo agoThinking about it, I probably wouldn't remember to change my fingerprints to the new ones with all the services I use, I'd probably have to carry my "legacy fingerprints" wherever I go for some time to avoid a lockout.
- hk__2 6mo ago> the data stolen in the breach could include full names, dates and places of birth, mailing and email addresses, and phone numbers on an undisclosed number of citizens Nothing really new here sadly, this information about me have leaked half a dozen of times in the past 2-3 years or so. These things will never change if the only penalty the company/agency gets is "send a message to your users saying you are sorry and that it won’t happen again".
- itopaloglu83 6mo ago[flagged]
- john_strinlai 6mo agodid you just want an excuse to say "microslop" or what is the relevance of your comment to either the article or the comment you are replying to?
- add-sub-mul-div 6mo agohackernews.txt
- throwup238 6mo agoWait, you don’t even get a month of free credit monitoring?
- gus_massa 6mo agoI'm not sure about France, but here in Argentina all this info is assumed to be public. If you want a credit at a bank or shop, they ask for a physical copy of the national ID [1], probably a photocopy too, an electricity or water bill and perhaps other paperwork that is hard to get (verified phone number???). [1] Do you want my number? It's inside this list: for i in range(1E9): print (i)
- deleted 6mo ago[deleted]
- _the_inflator 6mo agoI trust Google more than any government with my data. One needs security to survive the other couldn’t care less. Google selling data? So far no one came to blackmail me for certain dispositions, while the other does as they want, IRS, foreign governments, social security whatever. Google can be sued while the other gives itself a pass. Who is the baddie? In Germany the administration put massive duties on IT providers and added punitive damage as a looming consequence. Fast forward and the government with its “Ha, we are so digital!” and “Europe is better than US in CS!” suddenly has to swallow some brutal medicine I guess. I stick to my guns: Silicon Valley and especially Google is art regarding code and CS evolution. Same for FAANG etc. EU is hubris to say the least. Every time someone says “Let’s build our own Google/Cloud/…” a penguin dies. E Invoice will be a brutal boomerang, XRechnung the greatest backdoor of all times. Your data, time to shift everything into the EU.
- whyagaindavid 6mo agoI don't understand the downvotes. Literally every single German email provider took like 5 years to implement 2FA. Even now lots of security issues with many German providers that claim privacy. Even so-called DE-mail was sham. Still somehow people assume FAANG is crap in data security. (Yes, I am not demanding privacy from ANY MultiNational company)
- cynicalpeace 6mo agoA possible outcome of AI-assisted hacking is that companies, governments, and people become more resistant to using software, and software adoption actually declines.
- AlecSchueler 6mo agoI can see this happening as well. I'm extremely loathe to download or sign up or discuss anything online these days.
- ChrisArchitect 6mo agoBetter link? https://www.bleepingcomputer.com/news/security/french-govt-agency-confirms-breach-as-hacker-offers-to-sell-data/ https://www.bleepingcomputer.com/news/security/french-govt-a...
- zh_code 6mo agoUse Mythos!
- abernard1 6mo ago[dead]
- SilverElfin 6mo agoYet another example why NO ONE should trust age verification laws or companies like Anthropic forcing you to verify identity with shady companies like Persona (https://news.ycombinator.com/item?id=47872608 https://news.ycombinator.com/item?id=47872608). Whatever info you give up, it’ll be exposed one day.
- kleene_op 6mo agoI find it especially ironic that they would leak all my data, given the fact that they would ask of me to forward them every piece of id imaginable whenever I needed to forge or amend a new one (when adding a mention on my driver's license for instance). Like they didn't have access to it anyway.
- yladiz 6mo agoThey do have to prove who you are, and to do that you need to show your ID(s) and they need to check it in their system. I don't understand your comment.
- kleene_op 6mo agoI already have to log to their website with 2 factor authentification. I had to walk and physically present my id card, install the numerical identity app. That should be enough. Also, apart from reuploading IDs, they ask for information such as age, name, place of living, and a thousand more things that they already have and doesn't need to be provided to establish that you really are you.
- amelius 6mo agoIf governments are treating my personal data as if it is worth nothing, then I'm not going to treat copyrighted works as if they are worth something. If you want to build a society on information, then you cannot forget the most important group.
- AlecSchueler 6mo agoLet us know how it works out. It's great in theory to stick to your principles but taking on the government in that way is almost certainly a losing battle. There are better ways to bring about change.
- amelius 6mo agoIt all starts by noticing that there is something odd about the way governments are trying to structure things, and then raising awareness about it. There might be better ways to bring about change, but if you don't say what they are then that doesn't help much.
- AlecSchueler 6mo agoThere's a whole spectrum available from dialogue with government members to bloody revolution. But I don't see how passive aggressively breaking arbitrary civil laws that happen to be your pet peeve either raises awareness or puts any pressure on the government at all.
- gib444 6mo agoNot sure the French of all people need lectures on bringing about change and taking on the government.
- AlecSchueler 6mo agoThe person I responded to didn't seem to be French ("governments" not "or government") and I'm not sure the French have a history of opposing their governments through copyright violations.
- shevy-java 6mo agoGovernments may just be incompetent. Still, the lobbyists will never give up for mandatory age verification in the future.
- duncangh 6mo agoIt’s kind of interesting that this happens so shortly after they proudly announced how easily they would’ve able to migrate all systems from Microsoft and US firms. Maybe next year will be the year of the Linux desktop
- pembrook 6mo agoImportant to remember: this is the competency level of basically all governments who are currently proposing you be required to identify yourself using their proprietary identity systems anytime you visit a website to "save the children." There will be zero risks to you of course, because their software is magically perfect, unlike any other software created in the history of mankind.
- yubblegum 6mo agoThis shit should be stored encrypted not in plaintext.
- jonathanstrange 6mo agoThe attacker will then simply use the decryption key to decrypt it.
- yubblegum 6mo agoThen the headline would be French goverment loses encryption keys ..
- jonathanstrange 6mo agoAccess to the server gives you access to the encryption keys, unless the server is just storing end-to-end encrypted material for someone else and doesn't do anything with the data.
- yubblegum 5mo agoAt this point I must assume the expertise to troll exceeds that of secure systems' design.
- agentultra 6mo agoThere’s something to be said about old school bureaucratic institutions: it made breaches like this significantly more difficult to pull off and far less valuable as a result. It also ensured democratic participation by all of the people employed there making sure that processes are followed and making sure no one is cheating. We all knew that systems like this would get breached. It’s not a matter of, “if,” but, “when.” If we’re going to continue down this route because of convenience or surveillance and authoritarianism or whatever; people designing these systems need to thinking: When this system is breached…. And they should make sure there’s a good story for protecting people and the system from these sorts of events.
- deleted 6mo ago[deleted]
- dang 6mo agoUrl changed from https://techcrunch.com/2026/04/22/france-confirms-data-breach-at-government-agency-that-manages-citizens-ids/ https://techcrunch.com/2026/04/22/france-confirms-data-breac..., which points to this.
- mixxit 6mo agoWe are going to leak everything from our sexual health records to our HR files It's the age of the leak and the sooner we accept, no matter our efforts, we live in a security free world and design around that - the better
- misiek08 6mo ago- There was no leak - Here is sample data we stole „Small, not harmful leak of non important data, few records only”
- BrandoElFollito 6mo agoIt's nothing special. Our data goes away on a regular basis. They hack the taxes and the heath insurance system and yhay have everything about us. What a shitty world because of these idiots
- lemoncookiechip 6mo agoAnd they're still pushing through with the idea of centralized IDs for the internet creating massive honeypots for hacker groups and AI companies all over the world. Meanwhile it's a breach every other month all over.
- reorder9695 6mo agoWhat all these breaches tell me is that personal data should not be required, and especially not stored unless absolutely necessary. I cannot verify how my data is treated once it leaves my device, so how can I possibly trust it will be treated properly and not leaked? This is a major reason as to why I am so strongly against all this verification shit governments keep trying to push, the best way to keep data secure is not to have it in the first place, therefore my personal data should not leave my device except in the strictest of circumstances for things like my name/DOB/address/SSN.
- amelius 6mo agoWould it be possible to spread so much noise that data like this becomes useless? Could an LLM be used to help here?
- selfhoster1312 6mo agoAssuming this is a serious question, no. The database was compromised. Some people have the authoritative source of information. Any noise they will just ignore because they know it's not in the "real" dataset.
- sylware 6mo agoIn 2015/2016, the president (Hollande), and its prime minister (Valls) did install a document which is "law", about technical directives for the gov and its agencies/dependencies. This document was probably written by big tech themselves. No following prime minister and even the new president (macron), did fix this obvious big tech ("whatng cartel") trojan horse. They were probably screwed as f... or they had/have some interests somewhere ($$$). In the last decade, all web sites were broken to be replaced by web apps ($$$), creating a hard dependency on the massively huge and complex "whatng cartel" web engines and their related massively complex c++ compilers. It is very hard to believe to anything else than corruption, really hard. This document, which is law, which only the president and prime minister have power on, must be modified to make the difference between web sites and web apps and to mandate a web site for core and critical online services of gov and dependencies. Aka, restore noscript/basic (x)html interoperability, or "small" and technically reasonable web engines (to foster real-life alternatives from citizen, local company, etc, initiatives). All of such online services had a working web site (no app) before this document sold the gov and its dependencies to big tech (here the "whatng cartel"). No gov authorities (competition/anti-trust, justice, etc), not even the parliaments can do anything here, only the president and the prime minister. Hardly believable, and I found out only a month ago, in spite of consulting lawyers, being part of related user groups with legal experts, etc, for 10 years. I could not understand what was going on, all this money and 'loss of strategic control' channelled in those 'companies'.
- Razengan 6mo agoI wonder: Do all these government ID databases etc contain the IDs of the politicians and other people in "power" that pushed for all this shit? Or are they magically exempt?