Back to blog
Threat Intelligence6 min read

Panorama de la cybermenace ANSSI 2025
What Really Changes for SMEs, Mid-Market and the Public Sector

ANSSICERT-FRExfiltration de donnéesRançongicielSecteur public

ANSSI received 2,209 reports and handled 1,366 incidents in 2025 — almost stable compared to 2024. Behind that flat number, the nature of the threat has shifted, and it directly concerns organizations with no SOC and no dedicated incident response team.

Key takeaways

  • Data exfiltration incidents jumped 51% in a year (130 → 196), while ransomware compromises fell 9% (141 → 128).
  • Attackers are shifting from encryption to pure data theft followed by extortion — harder to detect than a classic ransomware freeze.
  • Education, local authorities and healthcare alone account for nearly 70% of incidents handled by ANSSI.
  • Backup and restore plans built for ransomware do not protect against silent data exfiltration.
2 209

reports received by ANSSI in 2025

1 366

incidents handled (1,361 in 2024)

+51 %

data exfiltration incidents (130 → 196)

-9 %

ransomware compromises (141 → 128)

Data theft has overtaken encryption

The most significant statistic in this report: data exfiltration incidents jumped 51% in a year, from 130 to 196 cases handled by ANSSI. Over the same period, ransomware compromises declined slightly — 128 in 2025 versus 141 in 2024, a 9% drop.

This is not good news in disguise. The decline reflects a change in tactics rather than a decline in the threat: attackers are gradually abandoning data encryption in favor of pure theft, followed by a threat of publication or resale. Double extortion — steal, then threaten to leak — is more profitable and harder to detect than classic encryption, which is noticed immediately when systems stop working.

For an organization that built its defense around ransomware backup and restore, this shift changes the equation. An up-to-date backup does nothing against exfiltration: data is stolen before any encryption, sometimes weeks before the attack becomes visible.

Public sector and under-resourced structures on the front line

The report identifies the sectors most affected by the incidents ANSSI handled: education and research (34%), local authorities and ministries (24%), healthcare (10%), telecommunications (9%). Combined, education, local authorities and healthcare account for nearly 70% of incidents handled by the agency.

Incidents handled by sector

34 %
Education & research
24 %
Local authorities & ministries
10 %
Healthcare
9 %
Telecommunications

This is not a statistical coincidence. These are precisely the organizations that combine two characteristics: a large attack surface (many users, endpoints, partners) and dedicated security resources that are often limited, or nonexistent. A mid-sized local authority or a healthcare facility usually has no full-time CISO, let alone a detection team able to spot an ongoing exfiltration.

IBM's 2025 Cost of a Data Breach report, cited alongside the ANSSI overview, puts the global average cost of a breach at $4.44 million. That figure seems out of reach for an SME or a small local authority — but it hides a more worrying reality: the real cost is not only financial. Detection time, loss of trust from citizens or customers, and notification obligations weigh the heaviest for a structure with no dedicated legal or crisis communication team.

What it changes for priorities, concretely

For a CISO, CIO or executive carrying cybersecurity alone, this report calls for reordering priorities — without necessarily rebuilding everything:

Exfiltration detection matters as much as ransomware protection

Monitoring unusual outbound data volumes, abnormal access to sensitive databases, or connections at unusual hours doesn't require a 24/7 SOC — but it does require minimal visibility on what leaves the information system, not just what comes in.

Incident response plans must cover the "theft without encryption" scenario

Many existing plans are calibrated for a classic ransomware scenario (systems locked, restore from backup). A silent data theft follows an entirely different timeline: late discovery, notification obligations (GDPR, or NIS2 for entities in scope), and crisis communication management before technical remediation even starts.

Prioritization must account for sector, not only size

A local authority or a small healthcare facility is statistically more exposed than an industrial SME of comparable size. The level of vigilance should reflect this sector-driven reality, not just headcount or revenue.

A threat evolving faster than the resources allocated to it

This ANSSI report confirms what many CISOs at SMEs, mid-market companies and public structures live daily: the threat evolves faster than the resources granted to counter it.

Adapting vigilance to this shift doesn't necessarily require extra budget — it first requires knowing where to look. That's exactly what a cyber command tool designed for a single person, rather than a dedicated team, should deliver: a clear view of what matters, without turning every solo CISO into a full-time SOC analyst.

Frequently asked questions

What is the ANSSI Cyber Threat Overview?+
It's ANSSI's (via CERT-FR) annual report summarizing reports and incidents handled over the year. The 2025 edition lists 2,209 reports received and 1,366 incidents handled — a nearly stable volume compared to 2024, but with a clearly shifting nature of threat.
Why are data exfiltration incidents rising so much?+
Data theft incidents rose 51% in a year (130 to 196 cases), while ransomware compromises fell 9%. Attackers now favor pure theft followed by a threat of publication or resale — more profitable and harder to detect than classic encryption, which is noticed immediately.
Which sectors are most affected according to the 2025 ANSSI report?+
Education and research (34%), local authorities and ministries (24%), healthcare (10%) and telecommunications (9%) concentrate the majority of incidents handled by ANSSI. Education, local authorities and healthcare combined account for nearly 70% of incidents.
How should a solo or small-team CISO adapt their priorities?+
Three priorities: monitor outbound data volumes and abnormal access (not just what comes in), integrate the "theft without encryption" scenario into the incident response plan, and calibrate vigilance based on sector rather than organization size alone.

See where your organization stands against these threats

Eyako gives a solo or lean CISO team a clear, centralized view of what matters — from data exfiltration signals to incident response readiness — without requiring a dedicated SOC.

Request a demo
ANSSI 2025 Cyber Threat Report: What Really Changes for SMEs and the Public Sector | Eyako