ANSSI reported 118 compromised accounts in its innovation lab after exploitation of a vulnerability in the Metabase software, the same flaw having affected nine ministerial instances. The anti-money laundering service Tracfin also suffered a breach via a compromised subcontractor, exposing data of 136 regulated entities including crypto service providers now required to report suspicious transactions under the 2019 Pacte law. Since August 1, 99 data breaches have been reported to ANSSI, with 67 confirmed, affecting major platforms such as Zéro Logement Vacant (48 million owners), Blootel (600,000 numbers) and the GAIA file of the Education Ministry (4.35 million teachers). Investigators are still looking for potential other indirect victims of the Tracfin subcontractor as of September 30.
Source: Read the original article

