-
France’s cyber agency says hackers hit 118 accounts in its lab through a flaw in Metabase.
-
The same flaw hit two Metabase systems at France’s digital agency, DINUM.
-
Paris prosecutors have opened a case over access to and theft of data from a state system.

France’s top cyber agency, ANSSI, has suffered a data breach after hackers used a flaw in Metabase, a data tool.
The breach hit 118 user accounts in ANSSI’s lab. About 30 of those accounts belonged to users from outside the agency, ANSSI said in a report on September 30. The data at risk included use stats, login names, email addresses and hashed passwords.
The case stands out because ANSSI helps guard France’s state networks from cyberattacks. Still, the breach does not mean hackers broke into all of ANSSI. The facts point to one Metabase setup used by its lab. ANSSI has not said that its main systems faced a wider breach.
The case also hit the Direction interministérielle du numérique, or DINUM. Hackers also hit two Metabase systems tied to ProConnect and Nuage-Public. The stolen data included admin data on public bodies, project data and logs of past logins. The logs had no names. ANSSI said the data was already public.
A Metabase Flaw Gave Attackers a Path
The attacks used CVE-2026-72898, a key SQL flaw in Metabase. Metabase said on August 6 that it had found the flaw after seeing real attacks. The attack began at its password reset page. It used a chain of flaws in four parts of the code.
An attacker did not need an account to use the flaw. A successful attack could give the attacker admin rights in Metabase. The attacker could then reach data tied to the data sets linked to the tool and take it out.
Metabase said the flaw hit versions 0.58 and later. It fixed the flaw on August 6. The firm said less than 3% of its cloud users had faced a breach before the fix. Some self-hosted sites also faced risk.
France’s CERT-FR warned in September that hackers had hit many Metabase sites. Its September 10 alert called the flaw critical and told users to check their systems. The alert also urged organizations to review logs, admin accounts, API keys and database access.
ANSSI’s review found that attackers hit nine Metabase systems in state bodies. One was France VAE. Hackers got a high-level account on August 8 and took user data. Another was Qualicharge. Hackers took 102,000 charge sessions and data tied to about 100 tech accounts.
Paris Prosecutors Open a Cybercrime Case
The ANSSI case has now moved into a legal probe. The Paris prosecutor’s office opened a case after the ANSSI breach came to light. The case went to the cybercrime unit. French authorities have also taken action in a separate international cybercrime investigation, including the Thai Police arresting three Swedes in a global darknet drug trafficking probe. It covers illegal access, staying in a state data system, and taking data from it.
Prosecutors want to learn how the hackers got in, what data they saw and where the data went. The probe will also examine logs and other traces left by the attack. Those clues may help show which servers the hackers used. They may also show if the same group hit other French state bodies. French officials have not named a hacker or group behind the attack.
REACTIV Finds a Wider State Security Problem
The ANSSI breach came to light during a wider state security review. Prime Minister Sébastien Lecornu asked ANSSI on September 1 to start REACTIV. The name means “Interministerial Response and Action against Data Breaches.”
The task began after a rise in data theft from French state bodies. It gives ANSSI more power to press ministries to take fast steps when a breach hits.
ANSSI’s first REACTIV report said 99 data breach cases had reached the agency from August 1 to September 30. The agency had confirmed 67 of them. The other 32 were still under ANSSI’s handling.
The report says its figures remain provisional and may change as investigations continue now. Metabase was one of several weak points found in the review. Other cases involved stolen passwords, weak or missing multi-factor login, poor access rules, and risks from outside firms. The pattern shows that France’s state data risk goes beyond one software flaw.
ANSSI and DINUM Lock Down Affected Systems
Both agencies took steps after the breaches. ANSSI updated the Metabase systems and reset all account passwords. It also shut down accounts that no one had used for more than three months.
DINUM fixed its two systems, reset its access keys, and removed accounts that the hackers had made. Metabase also told users to update their software and check logs for signs of a breach. It shared an attack pattern that teams can use to spot the flaw in past logs.
The Paris case will now seek to explain what happened at France’s cyber agency and who was behind it. The breach also sends a wider warning. Even a cyber agency can face risk when a weak outside tool connects to state data.