France has become one of the busiest hunting grounds on the cybercriminal underground. A new report from threat-intelligence firm CloudSEK finds that France-linked activity across dark web forums, ransomware channels, and hacktivist groups has more than quadrupled over the past two years — and it is not slowing down.
The numbers are stark. CloudSEK analyzed roughly 17,800 France-related threat intelligence items over 24 months. Monthly activity climbed from fewer than 300 items in mid-2024 to more than 1,400 at its January 2026 peak, and stayed above 1,000 per month through the spring. Across the same window, more than 145 million records tied to French residents were exposed across public services, healthcare, telecom, and retail.
Crucially, this is not one giant breach inflating the charts. The surge is broad and sustained, which the researchers read as a maturing market for French data rather than a one-off spike.
Stolen credentials are the engine
The single biggest driver is the mass harvesting of logins. CloudSEK counted 4,447 account credential exposures, 4,360 credential collections, and nearly 1,000 authentication-token leaks, most of it fueled by infostealer malware that quietly siphons passwords, cookies, and session tokens off infected machines. That stolen access is then bundled into combolists and either sold cheaply or handed out free.
The prices tell their own story. In one listing, around two million records said to belong to French women were advertised for just $399. The report also flagged fabricated databases marketed under the names of trusted institutions like ANTS, the national secure-documents agency, and CPAM, the health insurance system — fuel for phishing and impersonation even where no real breach occurred.
By sector, government took the heaviest hit with 1,652 exposure items, followed closely by financial services (1,594), technology (1,491), and telecom (1,480). Ransomware pressure, meanwhile, is landing hardest on the softer targets: municipalities and smaller organizations with thin security teams, with groups like Qilin and MedusaLocker named in claims against French local authorities.
A geopolitical edge
Layered on top is a distinctly political threat. CloudSEK logged 742 France-related hacktivism items in six months, dominated by the pro-Russian group NoName057(16), which claimed DDoS attacks against French ministries, civil aviation bodies, and drone manufacturers — several explicitly framed as retaliation for France’s support of Ukraine.
As a vendor selling predictive threat intelligence, CloudSEK has an obvious interest in a scary-looking chart, and the report leans on its own dark web tracking that is hard to independently verify. But the underlying pattern — infostealers feeding a cheap, high-volume credential economy — mirrors what other researchers have documented across Europe. With French regulator CNIL now handing down record fines for weak authentication and sloppy access controls, the cost of ignoring that pattern is climbing on both sides of the breach.
