France-linked underground cyber-activity has increased more than fourfold over the past two years, reports CloudSEK.
The company explains that stolen credentials, personal data, ransomware advisories and hacktivist claims have risen sharply across dark web forums and cyber-criminal channels.
Monthly activity climbed from fewer than 300 items in mid-2024 to more than 1,400 at its peak in January 2026.
It remained above 1,000 items per month through spring 2026, pointing to a sustained expansion of the underground market for French data rather than a short-lived spike caused by a single breach.
These findings are part of a new CloudSEK report titled: “France Cyber Threat Outlook: Dark Web, Ransomware, and Hacktivism Trends.”
The company says that the report analysed approximately 17,800 France-related threat intelligence items recorded over 24 months.
The report highlights that stolen credentials and infostealer logs account for a significant share of the increase, while government organisations, financial services, technology companies and telecom providers remain among the most exposed sectors.
It also shows the parallel rise in ransomware activity targeting smaller organisations and municipalities, alongside sustained pro-Russian hacktivist campaigns against French ministries, aviation entities, drone manufacturers and other policy-linked organisations.
The impact of stolen credentials
The company says that the increase is being fuelled primarily by the mass harvesting and circulation of passwords, authentication data and personal information, rather than only by large corporate breaches.
The research identified:
- 4,447 account credential exposures
- 4,360 credential collections
- 4,011 combined datasets
- 3,565 breached-record listings
- 977 authentication-token exposures
This pattern reflects the growing use of infostealer malware, which extracts credentials, browser data, cookies and authentication tokens from infected systems.
The stolen information is then packaged into combo lists, sold on underground forums or distributed freely to support fraud and account takeover.
CloudSEK researchers found that this low-cost, high-volume model is making stolen access easier to acquire and reuse across multiple platforms.
The cost of trading personal data
In one case, approximately two million records allegedly belonging to French women were advertised for $399. In another, nearly 489,000 French records were distributed through a forum-based access mechanism rather than offered through a conventional sale.
The research also identified fabricated databases advertised in the names of trusted French institutions, including ANTS, the national secure-documents agency, and CPAM, the national health insurance system.
Such activity can enable phishing, impersonation and fraud even when the institution named in the listing has not suffered a confirmed breach.
The highest exposure
CloudSEK research shows that government recorded the highest level of France-related exposure over the two years, with 1,652 items.
It was followed by:
- Financial services: 1,594
- Technology: 1,491
- Telecommunications: 1,480
- Email-related exposure: 1,427
- Retail: 1,197
- E-commerce: 1,089
The prominence of government reflects a combination of leaked credentials, ransomware pressure on municipalities and politically motivated targeting of ministries and public agencies.
Ransomware pressure
The research recorded 213 France-tagged ransomware advisories over the past six months.
Some victims were posted more than once, meaning the total should not be interpreted as the number of unique organisations attacked.
Even after accounting for repeated listings, the data shows that municipalities and smaller organisations remain recurring targets, particularly where security teams and incident-response capabilities are limited.
Groups including Qilin and MedusaLocker were linked to claims involving French local authorities.
Repeated listings of the same victim suggest that ransomware operators may use staged disclosures to prolong pressure during extortion attempts.
Regulatory consequences
The rise in underground cyber activity is taking place alongside stricter enforcement of data-protection and security obligations in France.
Recent CNIL actions have focused on failures such as inadequate authentication, excessive access permissions and insufficient protection of personal data.
These weaknesses closely mirror the patterns identified in the report, particularly credential exposure, weak access controls and third-party risk.
For affected organisations, the impact of a breach can therefore extend beyond operational disruption to include regulatory penalties, mandatory remediation and reputational damage.

