Lecornu speaks of “heist of the century” on ANTS. It’s a student TP heist. A flaw from 2007. With 200 million euros of announcement effect on top.
You may have received this email on April 15. The subject is neutral, the tone reassuring. He explains to you that unauthorized access has affected your data on the France Titles portal, formerly ANTS. It lists what was leaked, your name, address, date of birth, phone number. It concludes with this sentence, “You therefore have no action to take.” You read it twice. You looked for what was wrong with the formula. That’s what was wrong. The phrase is technically accurate and symbolically grotesque. She tells you that there is nothing to do, because indeed, there is nothing to do. This is precisely the problem.
The hacker, a 15-year-old minor arrested at the end of April, exploited a vulnerability whose technical name you do not need to remember. It’s called IDOR, for Insecure Direct Object Reference. It has been in the OWASP top 10 since 2007. It is the canonical example taught in the first week of any cybersecurity course. Concretely, it was enough to modify a number in an address to retrieve the file of another citizen. No zero days. No state operation. No criminal genius. The hacker himself called the flaw “really stupid.” She is. It has existed for nineteen years in manuals, in repositories, in ANSSI guides, in OWASP checklists. It remained open on a sovereign portal which manages the identity documents of tens of millions of French people.
I am the CISO of a company that develops applications. If one of our developers delivered an API into production exposed to an IDOR vulnerability on personal data, he would lose his job within a day, and me almost within the same week. Not by severity. Because it is unacceptable. Not a question of opinion, a question of profession. We run automatic static analysis tools which cost a few thousand euros per year and which detect this type of vulnerability before going into production. We mandate intrusion tests several times a year, on rotating perimeters, to validate what the tools have not seen. We are not a multinational, we are an organization of reasonable size with constrained budgets. In 2026, ANTS will have its own budget of more than 315 million euros. The State spends between 700 million and one billion euros per year on cybersecurity. The tools exist. The methods exist. Budgets exist. What is missing is execution discipline, and no one buys execution discipline with a check for 200 million announced in the middle of a crisis.
I already wrote it. On this blog, by analyzing the State’s cybersecurity roadmap published on April 9, 2026, six days before the ANTS hack, I explained that this document said everything without meaning to. He listed with almost clinical lucidity the structural failures of the French system. Multi-factor authentication to be generalized on high-stakes systems by February 2027. Removal of generic accounts by June 2026. Systematic annual testing of recovery plans. This was all in the text. All this existed on paper. And on April 15, 2026, six days after publication, a sovereign portal came across a 2007 flaw. I also spoke on CNews about the gap between French regulation and operational execution. This is not a posture of circumstance. This is a consistent reading, for months, of a system which produces international quality standards and which proves incapable of applying its own requirements on its own portals.
On April 30, Prime Minister Sébastien Lecornu went to France Titles with four ministers to announce a series of measures. An envelope of 200 million euros released at the beginning of May, as part of the France 2030 program launched in 2021. A state digital authority to be created. A merger of the DITP and DINUM interministerial directorates. CNIL fines redirected towards a modernization fund. Digital blackout scenarios to be designed, with the explicit hypothesis of an American administration which would deprive France of tools. Vulnerability tests to be carried out at the ministry level. On paper, this is a complete answer. In fact, it is budgetary communication. Because the overall envelope is not the problem. Because the merger of organizational charts does not create injunctive power if the legislator does not include it in the law. Because vulnerability tests should have been running continuously on sovereign portals for years, and to this day they are still not running in a mandatory and verified manner.
The right word to describe what is happening is ulterior motive. In the management of the French digital state, cybersecurity is an afterthought. We treat it as a defensive cost which is added at the end of the chain, after the design of the service, after the development, after the launch of production. We invoke it in speeches, we cite it in roadmaps, we devote summits and plans to it. But we don’t plan it upstream, in the specifications, in the code review, in the pre-production tests. However, cybersecurity cannot be decided after the incident. It is built when we draw the architecture, when we choose the format of the user identifier, where we write the first line of code, where we define the rights matrix. The ANTS IDOR flaw did not arise by accident in April 2026. It was coded at a specific time, by someone, without cross-checking, without automated testing, without subsequent independent auditing. And it remained open because no one in the chain had the authority or the mission to detect it.
There is one detail that must be taken seriously. In September 2025, data allegedly from ANTS had already circulated on the dark web, revealing 12 million accounts. ANSSI then concluded that previous leaks had been recycled and ruled out the hypothesis of an intrusion. Seven months later, the same volume appears, this time confirmed. Either the IDOR fault was already active in fall 2025 and the alert was treated as a false positive. Or two successive intrusions exploited the same vulnerability, without any correction occurring between the two. In both cases, we are exactly on what I call the decision-making gap. This moment when an organization has useful information, has the means to act, and does not do so. Not out of malice. By cognitive bias. Social validation within the hierarchical chain normalizes the false positive. Business continuity pressure defers in-depth audit. The perceived cost of the investigation appears greater than the perceived risk of the incident. All the ingredients are there so that the organization that knows does not act. Organizational psychology is more decisive here than technology.
ANTS is not an isolated case. Since the start of 2024, France has known Free, France Travail, Cegedim Santé, entire sports federations, the UNSS, three ARS, the TAJ and FPR files. The CNIL recorded 8,163 notifications of data breaches between September 2024 and September 2025, an increase of 45% year-on-year. In 2025, France became the second country in the world for stolen accounts reported to the population. No announcement treats this pattern as a pattern. Each incident is commented on as an isolated event, dealt with by an extra budget, and forgotten as the next one arrives. This is precisely what I meant by talking about ulterior motives. As long as cybersecurity remains a reaction to the incident rather than an upstream discipline, we will sign all the 200 million checks in the world without correcting the discrepancy.
You reread the email of April 15. You found it strange. You were right. What he was telling you was that you didn’t have to do anything. What he did not say was that there would be no action taken beyond the announcements on the State side either. The ANTS flaw dates back to 2007. We have been waiting for the execution discipline that should have corrected it for just as long.