Tech News

REACTIV: ANSSI Gains Power to Enforce Emergency Measures on Ministries After Data Leaks

Summer 2026 was tough on the State’s information systems, with several major data leaks. Following these incidents, the Prime Minister asked ANSSI to respond. The answer now has a name: the REACTIV framework.

August 2026 was marked by a series of incidents, including the full breakdown I published in this article on the data leaks at the DGFiP, the land registry, and the French Ministry of Education. In almost every case, the scenario is the same: an employee or authorized third-party account is compromised, the attacker uses it to query a business database, and then exfiltrates personal data on a large scale.

In response, the executive branch announced its intention to strengthen the State’s cyberdefense capabilities. ANSSI was called upon, rightly so. In fact, it was through a press release published on September 7, 2026 that ANSSI announced the deployment of a "reinforced capacity for response, intervention, and assistance to State services", at the Prime Minister’s request.

REACTIV: a shift of ANSSI resources toward the ministries

Behind the REACTIV acronym lies the title "REsponse & ACtion Interministerielle face aux Violations de données". This is not a new organization, but rather new operational capabilities for ANSSI within cyberdefense operations. The press release refers to "an immediate shift of ANSSI’s operational efforts" to support ministries on two specific fronts:

  • Handling compromised user accounts. In other words, the entry vector used at the DGFiP and at the Ministry of Education.
  • Analyzing data breaches. The stated goal is to better contain attacks and fight "more reactively against data exfiltration".

That is no small matter, because in the DGFiP leak case, the Ministry of Finance acknowledged that access had been cut off as soon as the intrusion was detected, but the checks carried out at that point did not make it clear that data had been stolen. The case only became public after the hacker claimed responsibility, several weeks later.

ANSSI’s authority strengthened on two fronts

Until now, ANSSI supported the ministries. With REACTIV, it can now set the pace, and that matters. Two new concrete levers are mentioned:

  • Immediate measures, within tight deadlines. The agency gains "the ability to require ministries, within constrained timeframes, to take the immediate measures necessary to protect citizens’ data entrusted to the administration". Cutting off access, revoking accounts, isolating a server: ANSSI will be able to require these actions without waiting for internal ministry arbitration.
  • Centralized technical crisis communications. In the event of an attack of this kind affecting State services, ANSSI will handle the technical communications. We will have to wait and see whether future announcements become more detailed, especially regarding numbers and the number of victims (unless incidents like these stop happening altogether, which would be ideal).

This power of injunction reminds me of CISA’s authority in the United States. The U.S. agency can impose mandatory measures on federal agencies, with a compliance deadline, as soon as a serious threat is identified. This is often the case when vulnerabilities are being exploited: CISA sets the pace with very short deadlines so patches are applied as quickly as possible. The comparison has its limits, however: CISA directives are public, measured in hours or days, and backed by specific legislation. REACTIV, for now, remains a cyberdefense operation whose legal basis is not mentioned in the press release.

Finally, on the occasion of this announcement, ANSSI also highlighted the State digital security roadmap for 2026-2027, which the Prime Minister has asked to accelerate. As I wrote in April 2026 about this ANSSI roadmap, it notably requires MFA on all administrator accounts by December 31, 2026, as well as the deployment of an EDR or XDR across all workstations and servers by the same deadline. MFA, yeah, that’s the bare minimum.

One reality remains: this reinforcement comes in response to a series of leaks that affected millions of French citizens. If you are among those concerned, the checks to perform to detect identity theft after the State data leaks are still relevant, REACTIV or not.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.