Skip to content

Hb88vip4

News

Protect Your Data by Discovering the Cyber Huge Online Universe and Its Solutions

The CNIL recorded 6,167 notifications of personal data breaches in 2025, a level deemed exceptional. At the same time, ANSSI observes an increase of nearly 50% in incidents involving data exfiltration. These two…

Professionnelle en cybersécurité analysant des données protégées sur un double écran en open space

The CNIL recorded 6,167 notifications of personal data breaches in 2025, a level described as exceptional. At the same time, ANSSI observes an increase of nearly 50% in incidents involving data exfiltration. These two indicators outline a landscape where the threat is no longer limited to traditional ransomware: it is shifting towards the silent theft of information, without encryption of systems.

Data Breaches in France: Comparing CNIL and ANSSI Figures

The annual reports of the CNIL and ANSSI cover different scopes, but their intersection reveals complementary dynamics.

Indicator 2024 2025 Change
Notifications of breaches (CNIL) approximately 5,630 6,167 increase of about 9.5%
Incidents handled (ANSSI) 1,361 1,366 almost stable
Data exfiltrations (ANSSI) 130 196 increase of nearly 50%

The overall number of incidents handled by ANSSI remains stable. However, the proportion of exfiltrations within this total is significantly increasing. This means that attackers prefer data theft over system paralysis.

On the CNIL side, hacking accounts for about half of the notifications received. The other half includes human errors, loss of physical media, and configuration flaws. Exploring the Cyber Huge universe online helps to better understand the categories of threats facing organizations as well as individuals.

Extortion without Encryption: Why This Method Changes the Game

IT engineer in a server room holding a tablet displaying data protection solutions

Traditional ransomware locks files and demands payment to decrypt them. Extortion without encryption works differently: attackers copy the data and then threaten to publish it if the victim does not pay.

This shift has direct consequences on protection strategy.

  • Regular backups, long considered the main defense against ransomware, are no longer sufficient. Restoring systems does not prevent the disclosure of data that has already been stolen.
  • Exfiltration detection becomes a priority. Monitoring outgoing network traffic, spotting unusual transfers of large files, segmenting access to sensitive databases: these measures are gaining importance.
  • The pressure on victims is different. A company can restart its activity after encryption, but it cannot “undo” a data leak of customer information that is already circulating.

Backups no longer protect against extortion via exfiltration. This observation necessitates a rethink of security priorities, placing data flow monitoring on the same level as perimeter protection.

Service Providers and Subcontractors: The Targeted Link in Massive Breaches

The CNIL report highlights a shift towards incidents involving service providers, hosts, and subcontractors. Compromising a single technical intermediary allows access to the data of dozens, sometimes hundreds, of client organizations.

This pattern explains why so-called “massive” breaches are multiplying. The attacker no longer targets an isolated company: they aim for the central node that concentrates the information of many clients.

Consequences for Choosing a Service Provider

Entrusting data to a third party does not transfer responsibility. The GDPR requires the data controller to verify the security guarantees of their subcontractors. Three points deserve particular attention:

  • The contractual notification clause: the subcontractor must inform the data controller within a defined timeframe after any breach, and this timeframe must be compatible with the obligation to notify the CNIL within 72 hours.
  • Security audit: a provider that refuses a contractual audit right sends a negative signal. The ability to verify the technical measures in place (encryption at rest, network segmentation, access logging) remains a selection criterion.
  • The location and replication of data: knowing where the data is stored and whether it is replicated at other sites allows for assessing the actual exposure surface.

Compromising a subcontractor gives access to the data of all its clients. This concentration risk justifies increased vigilance over the chain of trust.

Data Protection Solutions: What Tools Really Detect

Two colleagues collaborating on cybersecurity solutions in a modern coworking space

Cybersecurity solutions are divided into several functional categories. The following table summarizes their capabilities against the two dominant types of threats.

Type of Solution Protection Against Encryption (Ransomware) Exfiltration Detection
Antivirus / EDR (Endpoint Detection and Response) Yes, through behavioral analysis Partial, depending on the solution
Next-Generation Firewall (NGFW) Indirect (blocking the entry vector) Yes, through inspection of outgoing traffic
DLP (Data Loss Prevention) No (not its role) Yes, monitoring file transfers
Encrypted Offline Backup Yes (post-incident restoration) No
SIEM (Security Information and Event Management) Detection through alert correlation Yes, through network log analysis

No single solution covers both scenarios. The combination of EDR, DLP, and SIEM offers the broadest coverage against current threats, but its deployment requires internal skills or a specialized provider.

Prioritizing According to Organization Size

A small business does not have the same resources as a CAC 40 group. For modest structures, a properly configured EDR combined with offline backups constitutes a minimal foundation. Adding a DLP tool becomes relevant as soon as the organization handles sensitive customer data (health, finance, identification data).

The ANSSI report mentions that 85% of ransomware in France start with an identity attack (credential theft). Strengthening multi-factor authentication on all critical access remains the measure with the best cost-effectiveness ratio, regardless of the size of the organization.

The trend towards extortion without encryption redistributes security priorities. The volume of notifications to the CNIL and the increase in exfiltrations documented by ANSSI confirm that protecting data now involves as much monitoring of outgoing flows as securing entry points. Multi-factor authentication, exfiltration detection, and subcontractor control form the triptych on which investments yield the most measurable effect.

Protect Your Data by Discovering the Cyber Huge Online Universe and Its Solutions