Skip to content
cyber security
reflection

2026 data breaches in France: Is Belgium really any safer?

Between the apocalyptic wildfires in France, in Spain and our own scorched Fagnes this summer, everyone got a taste of the heat. If some of us are living through the direct consequences of climate change, for 678,000 French individuals and businesses, it was hackers turning up the temperature instead.

Nobody could have missed the headlines explaining that the French tax authority (DGFiP) had been hacked, with the tax, land registry and inheritance records of nearly 700,000 French citizens left out in the wild. The same story repeated itself a few days later with another attack, this time targeting the French Ministry of Education.

Is France the champion of data breaches?

Not quite, but almost, unfortunately. According to Surfshark, France remains, over the whole first half of 2026 (January to June), the most affected country in Europe and the second most affected worldwide, with 43.4 million compromised accounts, just behind the United States (90.8 million). In the second quarter alone, around 19.6 million accounts were exposed. The “4th place worldwide” figure you sometimes see refers to something else entirely: the cumulative ranking since 2004, counting the total number of compromised French accounts across every year (740.9 million), which places France 4th over the long run, behind the United States, Russia and China. On recent activity, though, the trend leaves no room for doubt: France is indeed 2nd worldwide, and 1st in Europe, having even overtaken North America in volume during this second quarter alone.

Between government agencies, insurers, retailers and booking platforms, it is hard to find a French resident who hasn’t received at least one of these notifications in 2026. This isn’t just a feeling. It’s a measurable, documented phenomenon, and one that raises a question bigger than cybersecurity itself: can we still trust anyone, the state included, to actually keep our data safe?

Is Belgium spared?

From Belgium, it’s tempting to look at these French numbers and wonder whether we’re doing any better. Let’s be honest: nothing in the figures suggests Belgium is getting off lightly. The Centre for Cybersecurity Belgium handled 635 incident notifications in 2025, a rise of nearly 70 percent in a single year, according to this article comparing both countries directly. And Belgium’s Data Protection Authority (APD) received, that same year, 1,216 breach notifications and 1,394 complaints (a 67 percent increase compared to 2024), according to its 2025 annual report.

And there is no shortage of concrete incidents at home either. In April 2025, the Walloon public service (SPW) had to shut down all of its digital platforms after a large scale cyberattack, with suspicions of a data leak involving sensitive information on arms exports. Between May 2025 and spring 2026, the State Security Service (VSSE, our civil intelligence agency) had the names, phone numbers and email addresses of its staff stolen, through a known vulnerability in a third party vendor’s software, as reported by Trends-Tendances. The Belgian tax authority (SPF Finances), for its part, flagged a phishing campaign impersonating it in April 2026, a sign that Belgium’s tax administration remains a prime target, even without a confirmed intrusion so far.

That said, there’s also a more structural topic in the Belgian tech landscape that rarely gets discussed: itsme, the digital identity app used by millions of Belgians to log into their bank, their health insurer and public services, built by a consortium of the four major banks (Belfius, BNP Paribas Fortis, ING, KBC) and the three telecom operators (Orange, Proximus, Telenet). Nothing suggests itsme has ever been breached, since the app is regularly audited and certified under the ISO 27001 standard, as Test-Achats points out. But the very principle of a single access point to so many sensitive services raises a fair question: the more an app centralises connections to different institutions, the more it becomes a target whose compromise, even a hypothetical one, would carry outsized consequences. This isn’t an accusation, it’s a concentration risk worth keeping in mind.

Why France concentrates the biggest incidents

While the volume of incidents is comparable between the two countries once adjusted for population, the scale of certain French breaches remains out of the ordinary. Two examples are enough to understand why, and how these hacks happen in the first place.

1. ANTS (France Titres), the agency in charge of national ID documents, saw 11.7 million accounts exposed according to the Ministry of the Interior, because of an IDOR flaw. The principle, explained simply: an application exposes an internal identifier (a case number, a user ID) without ever checking whether the person requesting it actually has the right to access it. In practice, all it takes is changing a number in a web address to pull up someone else’s file, then the next person’s, and so on, with no control ever stepping in to block the process.

This flaw, IDOR (Insecure Direct Object Reference), is among the most common vulnerabilities listed by OWASP, the global reference for application security. It requires no sophisticated tooling and no malware, just a plain browser and a bit of patience, which makes it the classic Achilles’ heel of public administrations that digitised their services without ever thoroughly auditing access control on their APIs (as detailed by tech-insider.org). The alleged author of the intrusion was a bold 15 year old teenager.

2. Cegedim Santé, the publisher of software used by around 3,800 doctors, exposed the data of roughly 15 million patients in February 2026, according to this sourced overview. The company had already been fined by the CNIL in 2024 for a similar incident involving one of its other pieces of software. The repeat offence points to technical debt that was clearly never paid down.

What these two cases have in common isn’t bad luck, it’s a well identified combination: legacy applications that were never properly audited, third party vendors that weren’t sufficiently controlled, patches arriving after the breach instead of before it, and a heavily centralised digitisation of public services, which turns every national database into a highly valuable target for attackers. A more fragmented system, the kind you often find in Belgium, mechanically limits the scale of each individual incident, without reducing how often they happen, as we just saw.

The bad habits of 2026

Faced with all this, some people tend to downplay the impact of a breach as long as it “doesn’t contain any password or bank details.” In a previous post about a data breach in a hotel booking, I was given that exact same line, almost routine, meant to be reassuring.

Of course, passwords and bank details floating around are explosive, but that reasoning is too short and misses the point. A name, a first name, a date of birth and an email address are just as enough to craft a phishing campaign that is credible, targeted and hard to distinguish from a genuine official message. And above all, the real danger isn’t a single breach, it’s the accumulation. Adding up “basic” data, cross referenced with tax and medical records, is no longer a simple leak, it’s identity theft that can turn your life into a genuine nightmare.

The uncomfortable question: can we trust those who collect data without knowing how to protect it?

In Belgium, citizens are increasingly asked to centralise their digital identity for taxes, healthcare and purchases, at the exact moment when the institutions collecting it keep demonstrating, incident after incident, how hard they find it to secure. This isn’t an indictment aimed specifically at public administrations: the private sector doesn’t do any better, and healthcare, one of the most sensitive sectors of all, accounts for some of the heaviest incidents. The problem isn’t institutional in a political sense, it’s systemic: nobody, public or private, in France or in Belgium, has yet figured out how to secure databases at this scale and this pace.

One thing is clear though: we need to stop treating every breach as an isolated accident, and start treating it for what it is, a structural failure that calls for structural responses, such as mandatory regular audits, personal accountability for executives in cases of proven negligence, and above all a reduction in the volume of data collected “just in case.”

Why keep giving your real identity, even knowing all this?

There’s a paradox that keeps nagging at me: most of us know, in 2026, that the odds of our data ending up in a breach sooner or later approach certainty. And yet we keep filling in our real name and real email address on pretty much every form we come across.

This reflex isn’t irrational at all. Lying about your identity takes active effort (remembering a pseudonym, managing a separate email address), while telling the truth costs nothing cognitively. Identity verification is also becoming increasingly systematic, across deliveries, payments and customer support, which makes partial anonymity more of a hassle than a protection. On top of that, there’s a deeply rooted social norm at play: lying on a form is still seen, wrongly, as a transgression, while passively letting a piece of data you never chose to make public leak out is almost never framed as the real fault, which actually lies with the system that failed to protect it.

The problem is that “total anonymisation,” the thing we might aspire to, is largely an illusion in 2026 anyway: between mandatory banking KYC (Know Your Customer) checks and increasingly systematic identity verification, nobody really becomes invisible. The real question, then, isn’t “how do I disappear completely,” but “how do I reduce my exposure and compartmentalise how I use different services,” so that a breach at an online shop doesn’t allow anyone to trace a path all the way to your tax file.

What comes next in Europe?

The subject of data breaches goes beyond France and Belgium taken on their own, and that’s probably where the real structural answers lie. The European Digital Identity Wallet (eIDAS 2) is meant to eventually allow sharing with a service only the exact piece of data strictly needed for a check (proving you’re over 18 without revealing your full date of birth, for instance), rather than handing over an entire identity file at every sign up. The NIS2 directive already imposes stronger security obligations on a wider range of companies deemed critical, in Belgium as much as in France.

These efforts are moving slowly, far too slowly given the pace of breaches seen this summer and the speed at which technology keeps evolving. But they point in a clear direction: an architecture where the data collected is, by default, kept to the strict minimum, rather than one that collects broadly “just in case,” and where, leak after leak, we keep discovering what should never have been kept in the first place. The only real loser being the person who believed that what they were officially asked to hand over would actually be protected.


Cover credit: Photo by GuerrillaBuzz on Unsplash

Let's talk