France Discloses Breach of National ID Document Agency

Personal data of citizens who applied for passports, driver's licenses, and national IDs was exposed through a basic API vulnerability.

Illustration: France Discloses Breach of National ID Document Agency
AI-generated illustration · Sylvaris

Government Portal Compromised

France's National Agency for Secure Documents, known as ANTS or France Titres, detected a security breach on April 15, 2026. The agency operates under the Ministry of the Interior and manages all identity documents in France—passports, national ID cards, driver's licenses, and vehicle registrations.

A threat actor using the alias 'breach3d' posted stolen data for sale on criminal forums the following day, claiming to hold between 18 and 19 million records. ANTS later confirmed on April 24 that 11.7 million accounts were impacted, with exposed data including names, email addresses, dates and places of birth, postal addresses, phone numbers, and unique account identifiers.

Elementary Vulnerability

Security researchers traced the breach to an Insecure Direct Object Reference flaw in the ANTS API. This type of vulnerability allows an attacker to access another user's data simply by changing a parameter in a request—no sophisticated tooling required.

The attacker reportedly described the security flaw as 'really stupid' and 'elementary.' Documents uploaded during administrative procedures, such as scanned identification, were not compromised, but the combination of personal identifiers creates a comprehensive profile for identity fraud and targeted phishing.

Investigation Underway

ANTS notified France's data protection authority CNIL, the Paris Public Prosecutor, and the national cybersecurity agency ANSSI. French police detained a 15-year-old suspect on April 25, who faces charges carrying up to seven years in prison and a 300,000 euro fine under French cybercrime law.

The incident adds to a surge of breaches targeting French government systems in 2026. Earlier in the year, attackers compromised France's national bank account registry, and the country experienced 58 ransomware incidents in the first four months alone—a 29 percent increase over the same period in 2025.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.