France's Ministry of Ecological Transition confirms a 'sophisticated' attack on mail systems; a criminal separately claims 22,000+ records via an IDOR flaw in its inspection-oversight tool
ANSSI investigates suspected account compromise at the ministry, while an unconfirmed criminal claim names the specific application flaw
Analysis
France's Ministère de la Transition écologique confirmed to AFP on 2026-09-02/03 that its ministerial IT hub suffered a sophisticated cyberattack targeting mail systems, filed a report with the public prosecutor, and took several public-facing sites (the environmental public-consultation platform and multiple regional-administration sites) into maintenance mode (ICI / Radio France, 2026-09-03). ANSSI, France's national cyber-defense authority, separately confirmed it is intervening at ministry administrations "following suspicions of compromise of certain user accounts" as part of its own investigation, a fact-level statement from the authority itself, distinct from the criminal's unconfirmed claim below (ICI / Radio France, 2026-09-03).
On 2026-09-02, a criminal using the pseudonym "mondial" posted on a cybercriminal forum, tracked and reported by the specialist outlet French Breaches, claiming exfiltration of two files from systems tied to developpement-durable.gouv.fr (French Breaches, 2026-09-02): a 14,656-record file on approved inspection controllers (names, birthdates, approval numbers, phone numbers, some tied to inspection bodies such as APAVE Exploitation France) and an 8,166-record internal-directory file (unique emails, landline and mobile numbers, professional IDs, unit/directorate affiliations spanning 942 administrative units) (Le Monde Informatique, 2026-09-07). The attacker claims initial access via a misconfigured authentication service, followed by exploitation of an IDOR flaw in OISO (Outil Informatique de Surveillance des Organismes), the ministry's internal tool for monitoring accredited inspection bodies, to enumerate and pull records outside the authenticated session's intended scope (Le Monde Informatique, 2026-09-07). Neither the record counts, the precise nature of the misconfiguration, nor the scope of compromised systems has been independently confirmed as of the article date; this is the criminal's claim, not an established fact, though the underlying intrusion and ANSSI's investigation into it are victim- and authority-confirmed (Le Monde Informatique, 2026-09-07).
This follows a summer of repeated French public-administration intrusions (the Ministry of National Education in July and the tax authority DGFiP in August among them) that, per separate Le Monde Informatique reporting, led Prime Minister Sébastien Lecornu to impose a deadline at a 31 August government seminar for every minister to accelerate implementation of a EUR 200 million state-cybersecurity plan first announced in April; the same report cites ANSSI's own 2025 statistics of 3,586 security events and 1,366 qualified incidents, with ministries and local authorities accounting for 24% of incidents, second only to education and research at 34% (Le Monde Informatique, 2026-09-04). No source ties this intrusion's actor or mechanism to the credential-theft cluster already tracked in the DGFiP entry; the poster here uses a different handle with no stated affiliation.
Triage: sequential or rapidly-incrementing identifier values in an internal application's access logs against a single authenticated session, or access spanning far more organizational units than that account's normal scope, is the vendor-neutral discriminator for this technique class; legitimate bulk reporting by an authorized administrator can produce similar volume, so the sequence and the scope mismatch together are the signal, not either alone.
Cited evidence
The ministerial hub was the target of a sophisticated cyberattack last week, targeting messaging tools. (translated from French)
A report was filed with the public prosecutor. (translated from French)
ANSSI, the authority responsible for protecting the country against cybersecurity and cyberdefense threats, stated it is intervening "on behalf of administrations of the Ministry of Ecological Transition, following suspicions of compromise of certain user accounts and as part of investigations". (translated from French)
In a post published on 2 September 2026 on a cybercriminal forum, a user under the pseudonym "mondial" claims to have extracted two databases from systems associated with developpement-durable.gouv.fr. (translated from French)
He then claims the exploitation of an IDOR (Insecure Direct Object Reference) vulnerability. (translated from French)
The authenticity and completeness of the data presented have not been independently confirmed. (translated from French)
Sources4
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.