Cybercrime in France: +87% attacks, a hacking industry out of control in 2026

Foto del autor

By TP

France must defend itself. The digital threat landscape in France is experiencing a notable change, revealing an organization of an industrial nature. The annual report published by COMCYBER-MI (Command of the Ministry of the Interior in Cyberspace) for the year 2026 draws a particularly demanding observation: cybercrime is no longer just a matter of isolated technical failures, but is based on a structured, international and automated market. Between 2020 and 2025, digital attacks recorded in the territory increased by 87%, reaching 453,200 incidents in 2025. The analysis of operating methods shows a rapid diversification of attack methods and a growing convergence with physical infrastructures.

The key points of this article:The cybercrime landscape in France has undergone a significant change, now relying on a structured and automated international market.
Between 2020 and 2025, digital breaches saw a shocking 87% increase, reaching 453,200 incidents in 2025, with a predominance of DDoS attacks driven by geopolitical motivations.


Cybercrime: The professionalization of attacks and sectors under pressure

According to this famous report, distributed denial of service (DDoS) attacks constitute the majority of claims, representing 89.2% of hacktivist actions in 2025. This trend is supported by geopolitical motivations linked to international conflicts, particularly in Ukraine and the Middle East. At the same time, the health, energy and transport sectors are under constant pressure. Industrial supervision systems (SCADA) and IT service providers remain preferred entry points for attackers, who seek to disrupt the continuity of essential services rather than simply defacing public interfaces. The criminal ecosystem is now organized along a value chain similar to legal business models. The rise of service offerings (Cybercrime-as-a-Service) and the use of artificial intelligence facilitate access to complex tools for low-skilled profiles. Of the automated malware and criminal AI services make it possible to design phishing campaigns and exfiltrate large volumes of data in a very short time. This parallel economy of information theft has direct consequences on the personal and banking data of French citizens.

The digital threat landscape in France is experiencing a notable change, revealing an organization of an industrial nature. The annual report published by COMCYBER-MI (Command of the Ministry of the Interior in Cyberspace) for the year 2026 draws a particularly demanding observation: cybercrime is no longer just a matter of isolated technical failures, but is based on a structured, international and automated market. Between 2020 and 2025, digital attacks recorded in the territory increased by 87%, reaching 453,200 incidents in 2025. The analysis of operating methods shows a rapid diversification of attack methods and a growing convergence with physical infrastructures.The Ministry of the Interior publishes its annual report on cybercrime (spoiler: it’s not good) – Source: Compte

The emergence of the hybrid threat and artificial intelligence

Prospective analysis identifies several major technological risks for the next few years. On the one hand, the emergence of autonomous agents capable of planning and executing intrusions without human intervention reduces the reaction time of defense teams. Detection of these asymmetric behaviors requires adaptation of monitoring tools and reassessment of security procedures. On the other hand, preparation for the “quantum day” requires critical infrastructure operators to begin a transition towards post-quantum cryptographyunder penalty of seeing their current encrypted data ultimately compromised by future powerful calculators. Finally, the porosity between digital spaces and the physical sphere constitutes another worrying dimension of the threat. The use of spyware (stalkerware) in a domestic context, as well as the targeting of professionals and content creators, illustrate this hybridization. Attacks are therefore no longer limited to computer networks, but are sometimes accompanied by extortion attempts or pressure in the real world. Public action must therefore evolve towards a more global response, combining strengthened investigative capacities and more effective international cooperation to stem illicit financial flows. But the task clearly promises to be arduous.