The Briefing — Issue No. 6

Bercy counts its victims, America's water plants go manual, the Navy goes back to steam

Monday 17 August 2026 · 7-minute read · Cyber · Critical Infrastructure · Naval Power · Protective Security

← All issues

This week's essentials

— France's finance ministry confirms that taxpayer data was extracted from the DGFiP in a late-June intrusion disclosed only after the attacker boasted about it publicly; the ministry now puts the figure at 678,000 users.

— Water and wastewater utilities in at least twelve US states have reported cyberattacks on their control systems, with Iran the unofficial prime suspect and several operators forced back to manual operation.

— Donald Trump has ordered the US Navy to strip electromagnetic catapults and weapons elevators out of the Ford-class carriers from the fourth hull onwards, and return to steam and hydraulics.

— The same president, it emerged, left Air Force One in Turkey last month inside a catering truck, in a deception prompted by an Iranian assassination threat.

I.

Paris: two months between the breach and the confession

France's Ministry of the Economy and Finance has confirmed that both individual and professional taxpayer data were stolen from the Direction générale des Finances publiques, the agency behind impots.gouv.fr. The intrusion dates from late June. The public admission came on the evening of Thursday 13 August — two days after a self-described attacker claimed on a criminal forum to have got in, and roughly seven weeks after the access itself was detected and cut off during routine security checks. No announcement was made at the time. By Friday the ministry had put the number of affected users at 678,000; the monitoring platform FrenchBreaches, citing the hackers themselves, had earlier suggested a figure closer to 700,000.

The ministry says further investigation will establish precisely which categories of data were involved, and that affected users will be individually notified of what may have been consulted or extracted, together with any precautionary measures they should take. Reporting on the stolen dataset notes that it includes several hundred taxpayers declaring income above one million euros — which converts an administrative incident into something closer to a targeting list, in a country that has seen a marked rise in violent robberies against wealthy individuals.

The pattern matters more than the number. This follows an intrusion into Interior Ministry email servers in December 2025, unauthorised consultation of roughly 1.2 million bank accounts held in the FICOBA registry in February 2026 using a stolen official's credentials, and the theft of health data belonging to some fifteen million people. Each incident is separately explicable; together they describe a state that is repeatedly late to detect, and later still to disclose.

A precision worth holding onto in English. The ministry's own wording distinguishes data that was consulted from data that was extracted — in security English, unauthorised access is not the same event as exfiltration, and a breach is not automatically a leak. An attacker may hold data without publishing it; data may be published without ever having been sold. Analysts who collapse "accessed," "stolen," "leaked" and "published" into a single verb lose the entire timeline of an incident, which is usually the part that matters.

Key terms — et leur équivalent français

data breach
violation de données — le terme réglementaire au sens du RGPD
threat actor / malicious actor
acteur malveillant
unauthorised access
accès non autorisé
data exfiltration
exfiltration de données — la sortie effective des données hors du système
credential theft
vol d'identifiants
criminal forum
forum criminel — l'espace où la revendication est publiée
to claim an intrusion
revendiquer une intrusion
victim notification
information des personnes concernées
precautionary measures
mesures de précaution
data subject
personne concernée
targeting list
liste de ciblage — l'usage secondaire, et souvent le vrai risque

Source : Reuters

II.

Twelve states: when the fallback plan is a human being

Water and wastewater utilities in at least a dozen US states have reported cyber intrusions into their operational technology, according to ABC News. The FBI had confirmed seven states the previous week. Minnesota was first, with more than thirty community water systems targeted in late July. In Georgia, the Clayton County Water Authority — some 300,000 customers in the Atlanta area — saw a drop in water pressure and issued a boil water advisory, with service restored within hours. Two New Jersey municipal systems were hit, along with facilities in Michigan and South Dakota.

The technical picture is consistent: internet-exposed control systems, a vulnerability in widely used utility software, and attackers reaching pumps, valves and pressure settings. In several cases operators lost remote monitoring and control and reverted to manual operation. The FBI's advice — disconnect from the internet where possible, know how to run the plant by hand — is a reminder that in the water sector the ultimate cyber defence is still an operator with a wrench. There has been no reported impact on drinking-water safety.

Attribution is where the story becomes linguistically interesting. Multiple sources point to Iran; no federal agency has attributed the campaign publicly; and President Trump has said he does not believe there was an Iranian cyberattack at all. Nothing here is contradictory — official attribution is a deliberate political act that follows the technical assessment, sometimes by months, sometimes never.

Hence the register point. English coverage of intrusions uses a graded vocabulary that translation tends to flatten: suspected of, linked to, assessed to be, attributed to, claimed by. Only the fourth is an official position and only the fifth comes from the attacker. When a French summary renders all five as « attribué à », it manufactures a certainty the source never asserted — the single most common error in translated cyber reporting.

Key terms — et leur équivalent français

operational technology (OT)
systèmes industriels — par opposition à l'informatique de gestion (IT)
industrial control system (ICS)
système de contrôle industriel
programmable logic controller (PLC)
automate programmable industriel (API)
SCADA / human-machine interface
supervision / interface homme-machine
internet-exposed
exposé sur Internet — sans passerelle ni segmentation
to revert to manual operations
repasser en conduite manuelle
degraded operations
fonctionnement en mode dégradé
boil water advisory
avis d'ébullition de l'eau
attribution
attribution — l'acte politique, distinct de l'analyse technique
state-sponsored / state-linked
étatique / lié à un État — deux niveaux de preuve différents
shot across the bow
coup de semonce

Source : ABC News

III.

Newport News: nine years later, the steam comes back

President Trump has ordered the US Navy to remove the Electromagnetic Aircraft Launch System (EMALS) from the Ford-class carrier design and revert to steam catapults, along with a return from electromagnetic weapons elevators to hydraulic ones. The order applies from the fourth ship of the class, the future USS Doris Miller, onwards. His objection dates to 2017, when the lead ship was late, over budget and struggling with exactly these systems.

The technical ledger is not one-sided. The Pentagon's own independent testers found EMALS failing far more often than specified — on the order of once every 450 to 600 launches — and dependent on off-ship technical support, an awkward property on a long deployment. Against that, EMALS is more compact, mechanically simpler and less manpower-intensive than steam, and it can vary launch force to reduce airframe stress. The whole Ford design was drawn around a smaller crew: putting steam back means more sailors, and therefore more berthing, galleys, laundries and sewage capacity, plus interior volume for steam piping. General Atomics, halfway through building Doris Miller's EMALS equipment, warned that cancellation would send a poor signal about industrial-base stability and let adversaries close the capability gap. China's Fujian, commissioned in November 2025, is the only other carrier in service with an electromagnetic system.

For anyone writing about defence procurement in English, note how cost language works here. This is not a purchase decision but a requirement change, and requirement changes made after design freeze produce rework — physically completed modules taken apart. The reported bill is billions in capex and tens of millions in annual opex: capital expenditure is the one-off build cost, operating expenditure the recurring cost of running the ship. A decision can be defensible on one and indefensible on the other, and English keeps the two ledgers visibly separate in a way French summaries often merge into « coût ».

Key terms — et leur équivalent français

catapult / launch system
catapulte / système de lancement
weapons elevator
monte-charge à munitions
hull (fourth-in-class hull)
coque — ici au sens de « bâtiment de la série »
keel-laying
pose de la quille
rework
reprise, refonte — reprendre ce qui est déjà construit
design freeze
gel de la conception
requirement change
évolution du besoin
capex / opex
dépenses d'investissement / dépenses d'exploitation
failure rate
taux de panne
manpower-intensive
exigeant en effectifs
defence industrial base
base industrielle et technologique de défense (BITD)
capability gap
écart capacitaire

Source : The Maritime Executive

IV.

Ankara: the deception that only worked while nobody knew

Leaving the NATO summit in Ankara last month, President Trump boarded Air Force One, then left it again — through a catering truck — and flew home on a smaller military aircraft. The move was prompted by an Iranian assassination threat, made at the direction of the Secret Service, and not disclosed at the time; it surfaced only when the Washington Post reported it on 10 August. A handful of close aides went with him in the truck; no Cabinet member did. Commentators promptly asked the obvious question about the staff and journalists left aboard the aircraft everyone assumed was carrying the president. Trump's own answer was that the plane he actually took was the more exposed of the two, and that he follows what the Secret Service asks of him.

Strip away the memes and this is a textbook illustration of a protective principle: the value of a decoy movement is entirely a function of its secrecy, and it expires the moment it is reported. It also illustrates the cost side — deception that protects the principal necessarily displaces risk onto whoever remains with the visible profile, which is a decision protective details make deliberately and rarely explain in public.

One vocabulary note that rewards attention. English protective-security writing calls the person being protected the principal — never "the VIP" in professional usage — and distinguishes a threat (a stated or assessed intention) from a credible threat (one assessed as actionable) and from a threat stream (a continuing flow of related reporting). Note too that exfiltration, which appeared in our first item as the removal of data, means in this domain the removal of a person from a place of danger. Same verb, two trades: worth knowing which one your reader assumes.

Key terms — et leur équivalent français

protective detail
équipe de protection rapprochée
the principal
l'autorité protégée — jamais « the VIP » dans l'usage professionnel
decoy
leurre
deception / ruse
tromperie, manœuvre de déception
credible threat
menace crédible — évaluée comme réalisable
threat stream
flux de renseignement sur une menace
assassination threat
menace d'assassinat
exfiltration (of a principal)
extraction — ici d'une personne, non de données
low-visibility movement
déplacement discret
operational security (OPSEC)
sécurité des opérations — la protection des indices sur ses propres intentions
to displace risk
reporter le risque

Source : Military Times / Reuters

Document of the week

CISA & EPA — Internet-Exposed HMIs Pose Cybersecurity Risks to Water and Wastewater Systems

Six pages, free, and the exact vocabulary behind this week's second item: human-machine interfaces, PLCs, SCADA, bastion hosts, DMZ, and the mitigations American utilities are now being asked to apply at speed. A short, dense read for anyone who needs to talk about industrial cybersecurity in English without falling back on IT vocabulary that does not fit.

Available on cisa.gov (in English)

This vocabulary is our trade

The Briefing gives you the words; our training courses teach you to use them.

Book a free 30-minute assessment