
A new system gives the agency the power to force ministries to act quickly in the event of a cyber attack.
ANSSI receives new coercive powers from the Prime Minister via the REACTIV system to impose emergency measures on ministries in the face of repeated cyberattacks and data leaks.
AI-generated summary
ANSSI previously had an advisory role without direct power to constrain the ministries.
Who you gonna call? Since September 7, ANSSI has had an official response ready. The agency received, at the request of the Prime Minister, a power that it had never had until then. It is no longer a simple technical firefighter who is called after the fire. It is she who, from now on, can force a ministry to put out the fire within a deadline that she sets herself. The system is called REACTIV, an acronym for Interministerial RESPONSE & ACTion to Data Violations, and it formalizes what was until now only a verbal promise, that of an emergency cyber unit outlined three weeks earlier in the midst of the DGFiP crisis. This time, the promise has a name, text and legal powers.
REACTIV: when ANSSI trades advice for coercion
Until now, ANSSI advised. She could alert, recommend, sometimes get annoyed publicly, but she remained dependent on the goodwill of each ministry to act quickly.
REACTIV changes this mechanic on two specific points. First, the agency can have ministries take, within tight deadlines, the immediate measures deemed necessary to protect citizens’ data.
Then, it centralizes technical crisis communication in the event of an attack affecting the State, which prevents it from discovering an incident via a poorly calibrated ministry press release, or worse, via the press. Everything is part of the 2026-2027 roadmap for the State's digital security, which Matignon has requested to be accelerated.
On the ground, this gives a tight schedule: removal of generic accounts by June 2026, multi-factor authentication for administrators before the end of the year, then extension to all users at the start of 2027.
Added to this are advanced detection tools, the famous EDR and XDR (software that continuously monitors workstations and servers to spot an intrusion before it turns into a disaster). The most distant chapter arrives at the end of the roadmap, with encryption resistant to quantum calculation promised for 2030. Suffice to say that no one will see it happening for a while.
DGFiP, National Education, Ecological transition: a cyber back-to-school under tension
This shift does not come out of nowhere. The tax authorities paid a high price this summer, with repeated illegitimate accesses which exposed the tax and cadastral data of 678,000 taxpayers and businesses, to which are added more than two million cadastral files sucked into the same batch. At the end of July, a compromised account at the Ministry of National Education allowed the exfiltration of agent data.
And at the beginning of September, as soon as the REACTIV press release was released, the Ministry of Ecological Transition in turn confirmed an intrusion claimed by a pirate. Three ministries, three months, the same basic flaw: poorly locked access points that no one corrected in time. France Travail and the CROUS had already suffered the blow earlier in the year, with millions of files already in the wild.
The ANSSI press release does not say a word about the additional staff or budget that would go with these new powers, nor about what happens in the event of disagreement with a recalcitrant ministry. React faster to an attack, very good. But it doesn't fix the locks that let the burglars in in the first place.
Cyberattacks and crypto-kidnappings: the link that remains weak
There remains one point that ANSSI is not intended to address, and that is where the problem lies. Each tax or administrative file that leaks becomes, in the wrong hands, a directory to identify who owns what. France remains the epicenter of attacks targeting crypto holders around the world in the first half of 2026, causing more than $30 million in damage.
Investigators have been repeating it for months: a good part of these cases start with a leak of data well upstream, public or administrative, which allows robbers to target one home rather than another. Centralizing crisis communication and generalizing MFA (multi-factor authentication, which requires a second code in addition to the password) in ministries means closing a technical gap. This does not, however, close the channel which goes from the stolen Excel line to the home burglary.
AI outlook — possibilities, not facts
Removal of generic accounts in ministries by June 2026
Likely · Within months
Rolling out multi-factor authentication for administrators before the end of the year
Likely · Within months

Mistral AI has completed a record fundraising of 3 billion euros, led by Samsung Electronics, PSG Equity and Scaleup Europe, bringing its valuation to 21 billion euros to finance its computing infrastructures.

An attacker exploited a caching flaw in Liquid Network to create 4,000 ghost BTCs, returned 3,400 after implicit trading, but kept 598, or nearly $47 million, while the network remained shut down and the price of Bitcoin barely moved.

The G7 published a report on September 3, 2026 calling for immediate preparation for post-quantum cryptography, due to the “harvest now, decrypt later” threat. Bitcoin, Ethereum and Solana are directly affected, their infrastructures being in the crosshairs despite the absence of frontal targeting of cryptocurrencies. Developers are working on solutions like BIP-360 for Bitcoin, while Ethereum and Solana are testing post-quantum fixes, although the computing power required remains speculative at this time.

Vitalik Buterin considers the thesis that AI could break the security of Bitcoin unfounded. It distinguishes easily correctable software vulnerabilities from the cryptographic robustness of SHA-256, while emphasizing the difficulty of social consensus.

Jensen Huang, boss of Nvidia, proclaimed the arrival of artificial general intelligence on X following the launch of GPT-6 Astra by OpenAI, trained on more than 100,000 Nvidia GPUs.

Nearly 4,000 bitcoins (around $320 million) were removed from Liquid Network's bridge via a potential vulnerability in Elements software. The attacker presents himself as an ethical hacker, a version disputed by Ledger.