This shit should be stored encrypted not in plaintext.

The attacker will then simply use the decryption key to decrypt it.

Then the headline would be French goverment loses encryption keys ..

Access to the server gives you access to the encryption keys, unless the server is just storing end-to-end encrypted material for someone else and doesn't do anything with the data.