CloudSEK: Dark Web Activity Targeting France Quadrupled In Two Years

Super Daddy
4 Min Read

A new report from CloudSEK has revealed that underground cyber activity targeting France has grown more than fourfold over the past two years, with monthly threat intelligence items climbing from fewer than 300 in mid-2024 to over 1,400 at the peak in January 2026. The research analyzed approximately 17,800 France-related items recorded across dark web forums, ransomware channels and hacktivist networks over a 24-month period.

Activity remained above 1,000 items per month through spring 2026, indicating a sustained expansion of the underground market for French data rather than a short-lived spike tied to a single breach. Worryingly, over 145 million records belonging to French residents were exposed across public services, healthcare, telecommunications and retail between 2024 and 2025.

Mass Data Exposure Behind France’s Surge, CloudSEK Says

The primary driver behind the surge in France-related underground activity is the mass harvesting and circulation of stolen credentials and infostealer logs. CloudSEK identified 4,447 account credential exposures, 4,360 credential collections, 4,011 combined datasets, 3,565 breached-record listings and 977 authentication-token exposures within the tracked period.

Infostealer malware extracts credentials, browser data, cookies and authentication tokens from infected machines. The harvested data is then packaged into “combolists” and sold or distributed freely on underground forums, enabling fraud and account takeover attacks at scale. CloudSEK noted that this low-cost, high-volume model is making stolen access easier to acquire and reuse across multiple platforms.

In one documented case, approximately two million records allegedly belonging to French women were advertised for $399. In another, nearly 489,000 French records were distributed through a forum-based access mechanism rather than a conventional sale. Fabricated databases were also advertised under the names of trusted French institutions, including ANTS (the national secure-documents agency) and CPAM (the national health insurance system), enabling phishing and impersonation even without a confirmed breach at those institutions.

Government organizations recorded the highest level of France-related exposure over the two-year period at 1,652 items, followed by financial services at 1,594, technology at 1,491, telecommunications at 1,480, email-related exposure at 1,427, retail at 1,197 and e-commerce at 1,089. The prominence of government reflects a combination of leaked credentials, ransomware pressure on municipalities and politically motivated targeting of ministries and public agencies.

CloudSEK recorded 213 France-tagged ransomware advisories over six months, with municipalities and smaller organizations appearing as recurring targets. Groups including Qilin and MedusaLocker were linked to claims involving French local authorities. Repeated listings of the same victim suggest that ransomware operators may use staged disclosures to prolong pressure during extortion negotiations.

The report also identified 742 France-related hacktivism items over six months, dominated by the pro-Russian group NoName057(16). The group claimed distributed denial-of-service (DDoS) attacks and unauthorized access involving French ministries, civil aviation bodies, drone manufacturers and private organizations, with several campaigns explicitly framed as retaliation for France’s support for Ukraine and its stance on sanctions against Russia.

On the regulatory side, France’s data protection authority CNIL has been stepping up enforcement actions, focusing on failures such as inadequate authentication, excessive access permissions and insufficient protection of personal data. These weaknesses closely mirror the patterns identified in the CloudSEK report, meaning affected organizations face consequences extending beyond operational disruption to regulatory penalties and mandatory remediation.

Pokdepinion: When 145 million records get exposed and your country’s health insurance database is being sold on a forum for less than a decent laptop, perhaps it is time to treat cybersecurity as critical infrastructure rather than an IT department problem.

Share This Article
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *