France: Prime Minister Proposes a First-Response Unit to Protect Public Agencies from Cyberattacks

August 29, 2026

Following the recent hacking of the Directorate General for Public Finances (DGFiP), the French Prime Minister Sébastien Lecornu activated an interministerial crisis cell to form a “first-response unit.” This structure will be led by the National Agency for the Security of Information Systems (ANSSI).

A team of cybersecurity experts

On August 14, 2026, the Directorate General of Public Finances (DGFiP) published its official press release regarding a massive data breach. It concerns a historic cyberattack claimed by the hacker group ZeroBytes, responsible for leaking tax data involving 678,000 individuals and businesses. The attackers stole the credentials of a DGFiP employee and an authorized third party to infiltrate the system, then bypassed security alerts by keeping the volumes of data exfiltration under the usual detection thresholds.

As explained by the news agency AEF info in an article dated August 19, the government’s response was swift. Prime Minister Sébastien Lecornu requested the creation of a “first-intervention unit” to protect administrations against cyberattacks. This task was entrusted to Nicolas Roche, Secretary General of Defence and National Security (SGDSN), while the unit itself will report to the National Agency for the Security of Information Systems (ANSSI).

Logically, the unit will be mainly composed of ANSSI agents, who are the French national authority on cybersecurity and cyberdefense. However, the group will periodically receive support from experts from the Ministry of the Armed Forces and the Ministry of the Interior, as well as reservists.

For rapid interventions before data exfiltration

According to Nicolas Roche, the unit will intervene “on-site” permanently directly within the targeted structure. In other words, the team will not operate remotely from its own premises but will physically move into the victim ministry’s offices and crisis rooms. The agents will enjoy full access to the compromised computer network, in order to connect their own analysis tools, including detection probes. Furthermore, the unit will temporarily take charge of crisis management, coordinating directly with the minister’s office, with the aim of bypassing the usual bureaucratic delays.

It should also be noted that the unit will not wait for a major outage or a ransomware demand to intervene. Indeed, the deployment will begin rapidly after the triggering of a furtive technical alert on strategic accounts. There is thus a precise trigger, namely the bypassing of a high-privilege account, such as a network administrator or a key agent, as occurred during the DGFiP breach.

In the immediate term, the mission will be to track the attacker to locate where they are hiding, but also to block their data-exfiltration channels and to freeze access before the mass theft is triggered.

A post-incident lessons-learned report for downstream work

After the intervention, the new team must draft a lessons-learned report that will not be merely a final administrative end-of-mission note. In fact, it will be a strategic report directly sent to the SGDSN and the Prime Minister. The document will consist of two distinct parts, the first detailing the technical analysis of how the attacker infiltrated, the vulnerabilities exploited, and the data involved.

The second part of the report will aim to list human or software vulnerabilities to be corrected immediately. It will serve as a basis allowing the government to impose IT compliance upgrades under penalty of budgetary (or administrative) sanctions for the failing ministry.

Sindre Halvorsen

I write about space exploration, frontier science and the technologies that are quietly shaping the future. From Norway, I follow the missions, discoveries and ideas that connect life on Earth with what lies beyond it. My goal is to make complex subjects clear, useful and worth paying attention to.