When the Threat Speaks French: What the Paris Cybercrime Prosecutors Told Us
Tabla de contenido
CybelAngel recently welcomed two members of the cybercrime division of the Paris Public Prosecutor’s Office. Their view of the threat closely matches what our own data has been telling us all year.
On September 23, 2026, our teams spent two hours with members of the cybercrime section of the Paris Public Prosecutor’s Office, which handles many of France’s most serious cyber cases. The session had a clear purpose. Every day, CybelAngel analysts detect threats aimed at our clients, but once an incident moves from the technical world into the judicial one, it usually leaves our field of view. We wanted to see that other end of the chain.
The conversation covered three broad topics: the current state of cyber threats in France, how a cyber investigation unfolds behind the scenes, and the legal framework that governs this work.
Here are the trends that stood out.
1. French breach data is rising, and increasingly homegrown
Data breaches keep increasing in France, whether they come from ransomware operations or from attackers who steal and publish data outright. The attackers are changing too. Previously, data suggested that threats came mainly from abroad. Today, more and more actors are French-speaking individuals targeting French organizations.
Our own data tells the same story. Between January and September 2026, our threat intelligence sources recorded nearly three times as many claimed data breaches against French organizations as over the same period in 2025. Worldwide, the increase was about 55%. France’s share of global breach claims has almost doubled, and claimed ransomware attacks against French victims have doubled as well.
We are also seeing a growing number of threat actors whose activity is concentrated almost entirely on France. These are not opportunists who occasionally hit a French target. France is their main hunting ground.
2. Stolen data never stays still
The second trend is what happens after a breach. Organized crime has understood the value of personal data. A breached database is no longer simply resold; it becomes a starting point. Attackers pivot on it to identify new targets and launch the next attack, from convincing phishing campaigns to crimes that reach into the physical world.
For our analysts, this confirms something we tell our clients every day. A data breach is rarely the end of an incident. More often, it is the first link in a chain. The earlier the exposure is detected, the shorter that chain can be.
3. Crypto: two threats, one target
Cryptocurrency holders face two distinct threat phenomena, one purely digital and one physical.
Crypto drainers: The first threat comes from malicious tools, often hidden behind fake wallet apps or convincing lures, designed to empty digital wallets in seconds. Crypto transactions are irreversible, so a single click can mean a total and permanent loss. CybelAngel published a full report on crypto fraud in France last month.
Crypto kidnappings (crypto-rapts): The second threat is far more alarming. In these attacks, criminals bypass technology entirely and use physical violence to force victims to transfer their assets. France has become the epicenter of this phenomenon. According to blockchain security firm CertiK, France led the world in verified attacks of this kind in 2025, with more than double the number recorded in the United States. The trend has only accelerated since. On June 30, 2026, France’s Minister of the Interior reported 77 kidnappings and extortion cases linked to crypto assets since the start of the year, compared with 45 in all of 2025. These crimes are often organized like an “uberized” criminal service, with tasks outsourced to recruits. They frequently rely on personal data exposed online to choose their targets.
Together, these two threats show how far the consequences of data exposure can reach, from an emptied wallet to a threat to someone’s physical safety.
Why this conversation mattered to us
France is home to a large share of CybelAngel’s clients, and our data shows that the country is becoming a primary target rather than a collateral one. Hearing directly from the specialists who work on these cases every day gave our teams a judicial perspective on the threats they track. It also confirmed that what we see in our data reflects what is happening in the field.
The session also reinforced why speed matters so much. Detecting exposure early limits the damage for our clients. It also preserves the traces that investigators may need later, at a time when attacker infrastructure can disappear within days.
Finally, a clear understanding of the legal framework helps us keep our threat intelligence work both effective and responsible.
The takeaway
The session confirmed something our analysts already suspected in that France is no longer a secondary target in the global threat landscape. It is a primary one, with a growing population of French-speaking actors who treat French organizations as their main hunting ground. The judicial perspective also underscored a practical point. The window between a breach and the first downstream attack is shrinking, and the organizations that detect exposure earliest are the ones that keep that chain shortest.