
AI-generated summary
Operation REACTIV was activated by ANSSI to respond to the propagation of the Metabase flaw (CVE-2026-72898), exploited since the beginning of August 2026 via SQL injections allowing unauthorized administrator access.
But who will guard these guardians? The French cybersecurity policeman had to register on his own list of victims. ANSSI lists 118 compromised accounts in its innovation laboratory, according to the situation update of operation REACTIV published on September 30.
She is not alone in the photo. The DINUM (interministerial digital department) and the anti-money laundering service Tracfin also appear there. The observation is enough to make one cringe three weeks after activation of REACTIV.
Data leak at ANSSI, the firefighter caught in the fire
The culprit is called Metabase. This statistical dashboard software suffers from a flaw referenced CVE-2026-72898 that attackers have been exploiting en masse since the beginning of August. The mechanism is disarmingly simple: a tricked request, slipped where the software expects a trivial entry, opens the database to a stranger and offers him administrator rights. Specialists talk about SQL injection.
The fix has been in existence since August 6. However, nine ministerial authorities have fallen, according to the ANSSI situation report.
At the agency's innovation laboratory, the Metabase vulnerability delivered 118 user accounts, including around thirty belonging to external parties. Identifiers, email addresses, hashed passwords (stored in scrambled form, in principle unreadable) and usage statistics are released. ANSSI has updated its authorities and renewed all passwords. She also deactivated accounts that had been dormant for more than three months.
DINUM suffered the same fate on two instances, ProConnect and Nuage-Public. The data provided (SIREN, budgets and staff of public organizations, anonymized connection histories) were already public, according to the report.
Tracfin, data leak by the subcontractor
At Tracfin, the entry point was not Metabase. A subcontractor of the operator who manages support for the online declaration portal was compromised between the end of June and mid-July. This portal is used by “subjects”, these professionals who are required by law to report suspicious transactions: banks, notaries, real estate agents and, since the 2019 Pacte law, crypto service providers.
Results for 136 subjects whose name, position, email and telephone number were leaked, with the content of 213 requests sent to technical support. No suspicious transaction report was made. The administration cut ties with the service provider.
The report slips in one more detail. Investigators are still looking for “potential other indirect victims” of this subcontractor, which leaves the counter open.
Crypto platforms have every reason to listen. They sent 4,850 suspicious transaction reports to Tracfin in 2025, an increase of 58% over one year. A compliance manager whose name, position and direct line are in circulation becomes a perfect target for a fake support scam, especially if the scammer can cite a real ticket.
99 violations in two months, data leak as routine
Since August 1, 99 data breaches have been reported to ANSSI. The agency has confirmed 67, of which 32 are being processed by its own teams.
The volumes are dizzying. The Zero Vacant Housing platform, whose entry point would also be a Metabase instance, would concern 48 million owners. The National Education GAIA file potentially exposes 4.35 million teachers, and Bloctel was closed on August 11 after a leak which identified around 600,000 registered numbers.
The causes are repeated from one ministry to another. ANSSI first points to infostealers (spyware that sucks up passwords saved on a computer), often housed on personal computers used for work. She also cites the absence of double authentication on services exposed to the Internet. A stolen password was enough.
Do you hold crypto and appear in one of these files? Be wary of any call that cites your taxes, housing, or records, and enable two-factor authentication wherever it exists.
AI outlook — possibilities, not facts
Additional Metabase-related leaks will be reported in other jurisdictions in the coming weeks.
Likely · Within weeks
Tracfin will strengthen security controls on its subcontractors after this leak.
Very likely · Within months

MetaMask announced that it was managing a security incident affecting part of its infrastructure during the night of September 30 to October 1, 2026, without disclosing the breach or its extent. The publisher preemptively removed its validators operated within Lido, saying there is no immediate threat to users' wallets, while warning of potential scams exploiting the announcement.

The Bitget platform suffered a $387.5 million hack via a zero-day breach. SlowMist's investigation indicates an intrusion that began on August 31, leveraging third-party security products to falsify withdrawal orders without stealing private keys.

Apple has released iOS 26.7.1 update to fix zero-day CVE-2026-86950 in CoreGraphics. The company SlowMist warns of attacks targeting crypto wallets, although Apple has not formally linked the vulnerability to these thefts.

NEAR Intents claims to have blocked more than $50 million linked to the Bitget hack and froze an additional $503,000 using its SHIELD filter before solvers intervened.

China's Ministry of State Security claims that the anonymity of cryptocurrencies is an illusion, explaining that all transactions leave traceable traces via fiat-crypto exchanges and IP addresses, and cites the Bitfinex affair as proof, while banning the use of Bitcoin on its territory despite tolerance of detention.

Four days after Bitget's $387.5 million theft, on-chain investigator ZachXBT claims Chinese intermediaries are laundering funds on behalf of suspected North Korean attackers, publicly asking for help on Discord and Telegram when their XRP-bitcoin swaps on THORChain fail, captures of support tickets and transactions show.