CTIPilot

Ministère de la Transition écologique data-exposure claim (France, 2026-09)

incident · incident:france-transition-ecologique-breach-2026-09

France's Ministry of Ecological Transition confirmed a sophisticated attack on ministerial mail systems in late August/early September 2026 and referred the matter to prosecutors; ANSSI is investigating suspected user-account compromise. A criminal separately claims (unconfirmed as of 2026-09-07) exfiltration of 22,000+ records (inspection-controller and internal-directory data) via a misconfigured authentication service and an IDOR flaw in the OISO internal monitoring tool (Le Monde Informatique / AFP, 2026-09-03/07).

Coverage timeline
1
first 2026-09-08 → last 2026-09-08
Peak priority
notable
1 notable
Sources cited
4
3 hosts
Sections touched
1
active-threats
Co-occurring entities
2
see Co-occurring entities below
ATT&CK techniques
2
pinned v19.2 · see below

ATT&CK techniques

2 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-08/france-transition-ecologique-breach-idor-oiso · ATT&CK page ↗

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-09-08/france-transition-ecologique-breach-idor-oiso · ATT&CK page ↗

Story timeline

  1. 2026-09-08France's Ministry of Ecological Transition confirms a 'sophisticated' attack on mail systems; a criminal separately claims 22,000+ records via an IDOR flaw in its inspection-oversight tool
    active-threatsANSSI investigates suspected account compromise at the ministry, while an unconfirmed criminal claim names the specific application flaw

Where this entity is cited

  • active-threats1

Source distribution

  • lemondeinformatique.fr2 (50%)
  • frenchbreaches.com1 (25%)
  • ici.fr1 (25%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Ministère de la Transition écologique data-exposure claim (France, 2026-09) (1)

2026-09-08 · view entry permalink →

NOTABLENATOB3

France's Ministry of Ecological Transition confirms a 'sophisticated' attack on mail systems; a criminal separately claims 22,000+ records via an IDOR flaw in its inspection-oversight tool

France's Ministère de la Transition écologique confirmed to AFP on 2026-09-02/03 that its ministerial IT hub suffered a sophisticated cyberattack targeting mail systems, filed a report with the public prosecutor, and took several public-facing sites (the environmental public-consultation platform and multiple regional-administration sites) into maintenance mode (ICI / Radio France, 2026-09-03). ANSSI, France's national cyber-defense authority, separately confirmed it is intervening at ministry administrations "following suspicions of compromise of certain user accounts" as part of its own investigation, a fact-level statement from the authority itself, distinct from the criminal's unconfirmed claim below (ICI / Radio France, 2026-09-03).

On 2026-09-02, a criminal using the pseudonym "mondial" posted on a cybercriminal forum, tracked and reported by the specialist outlet French Breaches, claiming exfiltration of two files from systems tied to developpement-durable.gouv.fr (French Breaches, 2026-09-02): a 14,656-record file on approved inspection controllers (names, birthdates, approval numbers, phone numbers, some tied to inspection bodies such as APAVE Exploitation France) and an 8,166-record internal-directory file (unique emails, landline and mobile numbers, professional IDs, unit/directorate affiliations spanning 942 administrative units) (Le Monde Informatique, 2026-09-07). The attacker claims initial access via a misconfigured authentication service, followed by exploitation of an IDOR flaw in OISO (Outil Informatique de Surveillance des Organismes), the ministry's internal tool for monitoring accredited inspection bodies, to enumerate and pull records outside the authenticated session's intended scope (Le Monde Informatique, 2026-09-07). Neither the record counts, the precise nature of the misconfiguration, nor the scope of compromised systems has been independently confirmed as of the article date; this is the criminal's claim, not an established fact, though the underlying intrusion and ANSSI's investigation into it are victim- and authority-confirmed (Le Monde Informatique, 2026-09-07).

This follows a summer of repeated French public-administration intrusions (the Ministry of National Education in July and the tax authority DGFiP in August among them) that, per separate Le Monde Informatique reporting, led Prime Minister Sébastien Lecornu to impose a deadline at a 31 August government seminar for every minister to accelerate implementation of a EUR 200 million state-cybersecurity plan first announced in April; the same report cites ANSSI's own 2025 statistics of 3,586 security events and 1,366 qualified incidents, with ministries and local authorities accounting for 24% of incidents, second only to education and research at 34% (Le Monde Informatique, 2026-09-04). No source ties this intrusion's actor or mechanism to the credential-theft cluster already tracked in the DGFiP entry; the poster here uses a different handle with no stated affiliation.

Triage: sequential or rapidly-incrementing identifier values in an internal application's access logs against a single authenticated session, or access spanning far more organizational units than that account's normal scope, is the vendor-neutral discriminator for this technique class; legitimate bulk reporting by an authorized administrator can produce similar volume, so the sequence and the scope mismatch together are the signal, not either alone.

The ministerial hub was the target of a sophisticated cyberattack last week, targeting messaging tools. (translated from French)

A report was filed with the public prosecutor. (translated from French)

ANSSI, the authority responsible for protecting the country against cybersecurity and cyberdefense threats, stated it is intervening "on behalf of administrations of the Ministry of Ecological Transition, following suspicions of compromise of certain user accounts and as part of investigations". (translated from French)

ICI / Radio France (AFP wire) 2026-09-03

In a post published on 2 September 2026 on a cybercriminal forum, a user under the pseudonym "mondial" claims to have extracted two databases from systems associated with developpement-durable.gouv.fr. (translated from French)

French Breaches 2026-09-02

He then claims the exploitation of an IDOR (Insecure Direct Object Reference) vulnerability. (translated from French)

The authenticity and completeness of the data presented have not been independently confirmed. (translated from French)

Le Monde Informatique 2026-09-07
incident08 Sep 04:43Zmulti-sourceOpen finding ↗