Cyberattacks: ANSSI Can Now Impose Measures on Ministries with REACTIV
Who you gonna call? Since September 7, ANSSI has an official response ready. At the request of the Prime Minister, the agency has received powers it never had before. It is no longer just a technical firefighter called after the fire. Now, it can force a ministry to extinguish the fire within a timeframe it sets itself. The system is called REACTIV, which stands for Interministerial Response & Action to Data Breaches, and it formalizes what until now was merely a verbal promise, that of an emergency cyber unit outlined three weeks earlier during the DGFiP crisis. This time, the promise has a name, a text, and legal powers. Key points of this article: * ANSSI has gained unprecedented power with the REACTIV system, allowing it to impose data protection measures on ministries within constrained timelines. * Recently, several ministries have suffered cyberattacks, revealing concerning security flaws and highlighting a persistent vulnerability despite new measures. Until now, ANSSI advised. It could alert, recommend, and sometimes publicly express frustration, but it remained dependent on each ministry's goodwill to act quickly. REACTIV changes this mechanism in two specific ways. First, the agency can require ministries, within constrained timelines, to take immediate measures deemed necessary to protect citizens' data. Second, it centralizes technical crisis communication in the event of an attack affecting the state, preventing it from discovering an incident through a poorly calibrated ministry statement or, worse, through the press. All of this is part of the 2026-2027 roadmap for the state's digital security, which Matignon has requested to accelerate. On the ground, this results in a tight schedule: elimination of generic accounts by June 2026, multi-factor authentication for administrators by the end of the year, and then extension to all users in early 2027. Additionally, there are advanced detection tools, the famous EDR and XDR (software that continuously monitors workstations and servers to detect intrusions before they turn disastrous). The most distant chapter comes at the end of the roadmap, with quantum-resistant encryption promised for 2030. Suffice it to say that no one will see it coming for a while. This shift does not come out of nowhere. The tax authorities paid a heavy price this summer, with repeated illegitimate accesses exposing the tax and cadastral data of 678,000 taxpayers and businesses, along with more than two million cadastral records siphoned in the same batch. At the end of July, a compromised account at the Ministry of National Education allowed the exfiltration of agent data. And at the beginning of September, barely after the REACTIV announcement, the Ministry of Ecological Transition confirmed an intrusion claimed by a hacker. Three ministries, three months, the same underlying flaw: poorly secured accesses that no one corrected in time. France Travail and CROUS had already taken a hit earlier in the year, with millions of files already out in the wild. The ANSSI statement does not mention a word about the additional staff or budget that would accompany these new powers, nor what happens in case of disagreement with a reluctant ministry. Reacting faster to an attack is great. But it does not fix the locks that allowed the burglars in the first place. There remains one point that ANSSI is not meant to address, and that is where the problem lies. Each tax or administrative file that leaks becomes, in the wrong hands, a directory to identify who owns what. France remains the epicenter of attacks targeting crypto holders worldwide in the first half of 2026, with over $30 million in damages. Investigators have been repeating for months: a good portion of these cases starts with a data leak well upstream, public or administrative, allowing robbers to target one home rather than another. Centralizing crisis communication and generalizing MFA (multi-factor authentication, which requires a second code in addition to the password) in ministries is plugging a technical gap. However, it does not close the channel that goes from the stolen Excel line to home burglary. Strengthening ANSSI on paper is one thing. Preventing a file of 678,000 lines from ending up for sale on a dark web forum is another, and French crypto holders have learned this the hard way since the beginning of the year. There is also a project that REACTIV does not cover: the European NIS2 directive, intended to tighten cybersecurity obligations for sensitive operators, is still awaiting transposition into French law. Another text in the pipeline, while data continues to leak.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

The Zondacrypto Scandal Expands: This Time Involving Notable MPs

Crypto: The Fake Coinbase Advisor Sentenced After a $16 Million Theft

DeltaForesight Announces Completion of 324 Million Yen Financing to Develop Over-Collateralized Yen Stablecoin JPYdf

EBA Recommends Including Crypto Lending and DeFi Access Services in MiCA Regulation

New US Crypto Tax Regulations: Exchanges Required to Report Transaction Amounts, Investors to Calculate Gains and Losses Themselves

SlowMist: Unconfirmed iPhone Safari Attack Leads to Theft of Crypto Assets

CoinMarketCap Acquires Crypto Derivatives Platform Coinglass

INDODAX Highlights Strengthening of National Crypto Ecosystem at FEKDI x IFSE 2026 - Fintech World

CFTC Allows Derivatives Firms to Use Customer Funds for Investing in Tokenized Assets

Tether says EQIBank exposure below 0.034% after U.S. seizure

Robinhood: Tenev Sees Crypto Outpacing Sports

Robinhood Chain Achieves $1.5 Billion in DEX Trading Volume and $114 Million in Fees in August

Block Adds Bitcoin Lightning to AI Agents' Payments

US Considers Global Expansion and Adoption of Dollar-Denominated Stablecoins to Stimulate Treasury Demand

Compute Finance: The Financial Layer Being Built by the AI Economy, 0G is Constructing a New Paradigm for Computing Assets
![[Column] The On-Chain Transformation of Financial Markets Accelerated by the U.S.](/public-static/030_efb4e908c1.png?format=avif)
[Column] The On-Chain Transformation of Financial Markets Accelerated by the U.S.

Brazil Requires Declaration for Transfers Over $10,000 from Self-Custody Wallets, Bans Unauthorized Crypto Service Providers

Fed proposes GENIUS Act rules for stablecoin reserves and bank issuers

xStocks adds Ledger hardware wallet support for tokenized shares

The EU will strengthen its oversight of AI and tokenization starting in 2027

NYSE is assembling the pipes for a $5.5 trillion tokenized asset market

Crypto in France: Binance, taxes, digital euro, what changes by 2027

Sequans Sells 314 Bitcoins, Eliminates Cryptocurrency Exposure

Paxos Labs launches PAXGy token backed by PAX Gold

New York Files Lawsuit Against Polymarket for Illegal Gambling

Today in the Crypto Market: Wall Street is Turning to Tokenization, US Aims to Globalize Stablecoins

Multicoin: RWA on Chain Will Open the Era of DeFi 2.0

Ministry of Justice launches free course on bitcoin and crypto asset tracking open to all Brazilians

Perpetuals on Gold, Oil, and Stocks: $117 Billion Traded in One Month





