France Reports Breach of National Bank Account Registry
Breaches of national identity and financial registries expose citizens to long-term fraud risk and show the stakes of securing government-managed databases.
Compromised Credentials Grant Registry Access
France's Ministry of Economy disclosed in February 2026 that a hacker used stolen credentials to access the national bank account registry, known as FICOBA (Fichier National des Comptes Bancaires et Assimilés). The breach exposed data tied to approximately 1.2 million accounts.
The registry contains information about bank accounts held by French residents and is used by authorities for tax and legal purposes. While the exact date of the breach was not specified in public disclosures, the incident was confirmed to have occurred in late January 2026 and was disclosed the following month.
Credential-Based Attack Highlights Access Control Risk
The breach underscores the vulnerability of high-value government databases to credential theft. Unlike exploits that rely on software vulnerabilities, this attack used valid but stolen credentials to gain authorized-appearing access to the system.
Security researchers note that breaches of this type often remain undetected for extended periods because the access patterns appear legitimate. The incident reinforces the need for multi-factor authentication, privileged access monitoring, and anomaly detection in systems handling sensitive government data.
Part of February's Wave of Government Data Incidents
The FICOBA breach was one of several government and infrastructure-related security incidents disclosed in February 2026. During the same month, the European Commission and the Dutch Data Protection Authority confirmed they were compromised through critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile, with work-related data including names, email addresses, and phone numbers accessed.
Collectively, these incidents reflect a pattern of targeted attacks against government systems and critical infrastructure, with attackers using a mix of credential theft, zero-day exploits, and persistent access techniques to breach high-value targets.