ANTS leak: the State must protect us and not expose us

ANTS leak: the State must protect us and not expose us

The data leak at the National Agency for Secure Titles (ANTS) reveals a contradiction: the State is centralizing data that it does not know how to protect, while preparing to want more.

Up to 19 million French people are affected by the hacking of the National Agency for Secure Securities (ANTS). Well beyond the disaster, this affair reveals a profound contradiction: the State centralizes data that it is structurally incapable of protecting and yet prepares a law which will require millions more.

Promises and leaks

This latest hack compromises data covering marital status, site identifiers, email addresses, postal addresses and telephone numbers. Everything is now circulating on the dark web, put up for sale by a pirate hiding behind the photo of Pablo Escobar. The litany of data breaches generally invites a form of public apathy. Commentators, including myself, insist on the necessary resilience of French society and on the good practices to adopt to defend themselves against the tsunami of online scams that is brewing.

But this umpteenth news raises a deeper question about the sovereign role of the State in cyberspace. Because if it is impossible to rule out all cyber risks 100%, is it necessary to increase the opportunities for hackers to capture a large volume of data by centralizing it in the same places?

The ANTS site is not a creation of cybercriminals, any more than that of France Travail or the FICOBA files. The leak that affected France Travail concerned the data of 43 million people, or almost the entire working population in March 2024. We were assured that FICOBA was an impregnable fortress, before a malicious actor extracted 1.2 million IBANs by usurping the identifiers of a simple civil servant. Data security in France is therefore talk while leaks are facts.

Age verification as a jackpot for pirates

It is in this context that the legislator chose to build one of the most intrusive devices ever imagined: generalized age verification for access to social networks. Adopted at first reading by the National Assembly on January 26, 2026, the bill plans to prohibit access to social networks for those under 15 from September. The intention is laudable because who could decently oppose the protection of children? The mechanism, however, is a disaster waiting to happen.

Because what are we actually asking of the French? To scan their identity document and send it to a “trusted third party”, a private service provider responsible for verifying their age before transmitting an anonymized certificate to the social network concerned. We call this “double anonymity”, a reassuring term which masks a much more trivial reality: the concentration, among a few private actors, of millions of digitized identity documents. In other words, we are creating a treasure island from scratch for pirates around the world.

The State cannot do everything and centralize everything

Cyber ​​resilience, long theorized by experts, is not just about surviving after a cyberattack. It consists of adopting anti-fragile systems, which hold and minimize the impacts in the event of intrusion by segmenting a network, dividing databases or reducing access rights to the strict minimum. Faced with the cyber threat, society as a whole must be considered as a resilient system. However, the State seems to be taking the opposite path.

By what right can the State force its citizens to massively and centrally disclose biometric data that it is, in essence, incapable of protecting? It cannot both protect us and expose us in the same almost schizophrenic movement. This risk is not virtual. When cryptocurrency holders’ data leaks, and they leak, it’s not abstractions that find themselves exposed: it’s lives and families targeted by burglars or kidnappers. So the real question is not whether the age verification system will be hacked. The real question is: when?

Leave a Reply

Your email address will not be published. Required fields are marked *