In just three days, a hacker has just hit three giants of French tourism: Pierre & Vacances, Belambra and Gîtes de France. A few weeks before the summer holidays, it is the Michelin guide of homes to burglarize which is now circulating on the dark web.
In the space of three days, between May 15 and 17, 2026, a single hacker brought down Pierre & Vacances, Belambra and Gîtes de France. More than five million French people are affected. Names, postal addresses, telephone numbers, and above all, the precise details of their summer reservations: where they will be, when they will be there, and therefore when they will not be at home. A few weeks before the summer holidays, it is the Michelin guide of homes to burglarize which is now circulating on the dark web.
The motive claimed by the hacker, contacted by the French Breaches site, has the merit of frankness: “to demonstrate that France is a sieve when it comes to cybersecurity”. The demonstration is successful even if it is part of a long line of data leaks that the Merovingians would not deny: ANTS, France Travail, Ministry of the Interior, FICOBA files, FREE, SFR… At this rate, it will be easier in 2027 to list the entities which have not suffered data leaks.
But the most worrying thing is not this umpteenth leak, but rather the convergence of attacks on people and property with what is happening in cyberspace. We have already moved from a “virtual” world, with online scams, to a world where organized crime relies on our data to reach us in “real” life.
The affair of the French Shooting Federation is an illustration of this. In October 2025, the data of a million current and former licensees was exfiltrated and put up for sale on the darknet for 10,000 euros. Last April, Interior Minister Laurent Nuñez acknowledged that between 20 and 30 targeted burglaries were a direct result of this. In Nice, five heavy weapons were stolen by a fake agent. In the Lyon region, nine weapons and 1,300 ammunition were stolen during a violent robbery. A simple database has transformed into a supply chain for arms trafficking.
And then there is cryptocurrency, where violence takes a further step. France has become, astonishingly, the world leader in physical attacks against holders of cryptoassets. More than 135 kidnappings have been recorded since 2023, including 41 in the first three months of 2026 alone. In January 2025, David Balland, co-founder of Ledger, was kidnapped with his partner. His finger was cut off to speed up payment of the ransom. In May 2025, it was the daughter of Pierre Noizat, founder of Paymium, who was tried to kidnap in the middle of the street in Paris with her infant son.
Where does the data that feeds these networks come from? From everywhere. From a tax agent from Bobigny who consulted the Mira tax software without legitimate reason to resell addresses and assets of taxpayers declaring crypto gains. From the FICOBA leak, in February 2026, which exposed 1.2 million bank accounts. From the Waltio platform, whose breach has been linked to at least three kidnappings totaling $17 million in ransom.
The time is therefore no longer for observing the phenomenon but for our leaders to take responsibility. Cybersecurity can no longer be relegated to a folkloric subset of digital issues. It must be considered a central pillar of citizen security and the resilience of the Nation. No serious programmatic proposal can do without in-depth reflection on the cyber issue, which is trans-partisan in nature.
Because the objective of awareness must be followed by an objective of understanding and audit. Indeed, how can a country like France, whose expertise in cybersecurity is so recognized, be number one for data leaks in Europe? The reality is that everyone has an opinion on the matter, but no one really knows. Is it a matter of not being taken seriously, of a lack of resources, of a lack of responsibility on the part of economic and political leaders, of the laxity of the CNIL? Or is it due to the presence of old and obsolete digital infrastructures that are difficult to secure? All hypotheses are on the table, but only an urgent and independent audit of what is happening in our cyberspace will allow us to act accordingly.