# ANSSI launches REACTIV to counter state data breaches

Published: 2026-09-30 · Severity: routine · Sectors: government-national
Canonical: https://vorant.io/reports/654aba3b-f69d-57e6-ae77-d3277dc4a8a4/anssi-launches-reactiv-to-counter-state-data-breaches

> France's ANSSI stood up a rapid-response operation (REACTIV) to counter a wave of account-compromise and data-exfiltration attacks against government services.

CERT-FR published a situation report on 'REACTIV' (REponse & ACTion Interministérielle face aux Violations de données), an ANSSI-led operational capability created at the request of the French Prime Minister on 1 September 2026. The initiative responds to an intensification of cybercriminal activity involving account compromises and data breaches affecting French state administrations. Under REACTIV, ANSSI gains enhanced authority to compel ministries to take urgent protective measures within constrained timeframes and to centralise technical crisis communications for any state-related incidents tied to this threat.

The document is explicitly a point-in-time situation report reflecting ongoing investigations; no specific indicators, malware, threat actor attribution, or exploited vulnerabilities are disclosed. It complements France's 2026-2027 state cybersecurity roadmap, whose implementation the Prime Minister has ordered accelerated to durably raise the security posture of ministerial networks. For defenders in government and public administration, the key takeaway is that account takeover and data exfiltration against state services are an active, escalating concern warranting heightened monitoring of user account activity and data access patterns, alongside expectation of centralised guidance from ANSSI as incidents are further characterised.

## Mentioned in this report

- Campaigns: REACTIV

## Detection guidance (public sample)

### Suspicious Data Exfiltration via Web Service

ATT&CK: T1567

Detects processes writing large volumes of data to web service destinations or uploading files to cloud/web storage services, indicative of state data breach activity. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Suspicious Data Exfiltration via Web Service
description: Detects processes establishing connections to web services and transferring
  potentially sensitive data, typical of account-compromised exfiltration attacks
  against government networks. Matches on network destination patterns (HTTPS/HTTP
  to public cloud/web domains) combined with file write or process I/O indicators.
tags:
- attack.exfiltration
- attack.t1567
logsource:
  category: network_connection
  product: windows
detection:
  selection_https_exfil:
    DestinationPort: 443
    DestinationHostname|contains:
    - .s3.amazonaws.com
    - .blob.core.windows.net
    - .dropboxapi.com
    - .onedrive.com
    - drive.google.com
    - .box.com
    - .sharefile.com
  selection_http_exfil:
    DestinationPort: 80
    DestinationHostname|contains:
    - .s3.amazonaws.com
    - .blob.core.windows.net
    - .dropboxapi.com
    - .onedrive.com
    - drive.google.com
    - .box.com
    - .sharefile.com
  filter_admin_tools:
    Image|endswith:
    - \OneDrive.exe
    - \OneDriveStandaloneUpdater.exe
  condition: (selection_https_exfil or selection_http_exfil) and not filter_admin_tools
falsepositives:
- Legitimate employee use of approved cloud storage and sync tools
- Administrative backup services configured to upload to cloud repositories
level: medium
id: 7099069b-1389-5a8a-a9fd-b3a881273641
status: experimental
author: Vorant
references:
- https://www.cert.ssi.gouv.fr/cti/CERTFR-2026-CTI-006
```

### Unusual User Elevation and Privilege Escalation Activity

ATT&CK: T1078

Detects privilege elevation and lateral movement using valid compromised accounts—escalation pattern seen in data breach campaigns. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Unusual User Elevation and Privilege Escalation Activity
description: "Detects use of valid user credentials to perform administrative operations\
  \ or lateral movement via PsExec, WMI, or runas commands\u2014indicators of account\
  \ compromise being leveraged for lateral movement and privilege escalation within\
  \ ministries."
tags:
- attack.lateral-movement
- attack.t1078
logsource:
  category: process_creation
  product: windows
detection:
  selection_psexec:
    CommandLine|contains:
    - psexec
    - psexec.exe
    - paexec
    Image|endswith:
    - \cmd.exe
    - \powershell.exe
  selection_runas:
    CommandLine|contains: runas
    Image|endswith:
    - \cmd.exe
    - \powershell.exe
  selection_wmi:
    CommandLine|contains:
    - wmic
    - Get-WmiObject
    Image|endswith:
    - \cmd.exe
    - \powershell.exe
  condition: selection_psexec or selection_runas or selection_wmi
falsepositives:
- Systems administrators performing routine lateral administration via approved tools
- Automated administrative scripts deployed by IT operations
level: medium
id: 9508657f-17a4-53e7-b0fb-2b2f7752b0ac
status: experimental
author: Vorant
references:
- https://www.cert.ssi.gouv.fr/cti/CERTFR-2026-CTI-006
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.cert.ssi.gouv.fr/cti/CERTFR-2026-CTI-006

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/654aba3b-f69d-57e6-ae77-d3277dc4a8a4/anssi-launches-reactiv-to-counter-state-data-breaches.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
