France has established REACTIV, an interministerial cyber incident-response mechanism that authorizes the National Agency for the Security of Information Systems (ANSSI) to require ministries to implement urgent technical safeguards within set deadlines and to centrally manage technical crisis communications. The measure is intended to protect government services and citizens’ data during major intrusions and breaches.
The initiative follows compromises at the Directorate-General for Public Finance (DGFiP) that reportedly exposed data on between 350,000 and 678,000 taxpayers, as well as an intrusion at the National Agency for Secure Documents (ANTS). Two alleged ZeroBytes members, aged 16 and 18, were arrested in late August in connection with the DGFiP attack. France also plans mandatory multifactor authentication for government administrators, broader deployment of hardware security keys, and a €200 million government IT-security architecture overhaul; REACTIV’s own staffing and funding remain undisclosed.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
ANSSI announced REACTIV, an interministerial mechanism enabling it to require ministries to take urgent protective measures and centrally lead technical crisis communications during cyber incidents affecting state services.
French authorities arrested two individuals, aged 16 and 18, on suspicion of involvement in the DGFiP hack as members of the ZeroBytes hacking group.
The French government reportedly directed administrations to improve cyber readiness within 15 days, approved a €200 million governmental IT-architecture overhaul, and required multifactor authentication for government system administrators before year-end. It also planned to issue hardware security keys to state employees and merge DINUM with DITP.
Following the DGFiP incident, France's Prime Minister requested an extensive audit of ANSSI and the creation of a new incident-response unit.
France's National Agency for Secure Documents (ANTS) was reportedly affected by a cyber intrusion amid wider incidents targeting public administration.
France's Directorate-General for Public Finance (DGFiP) suffered reported compromises, described as three compromises by one source, exposing sensitive and personal data for an estimated 350,000 to 678,000 taxpayers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcecyber.gouv.fr
Open sourceinfosecurity-magazine.com
Open sourcezdnet.fr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.