France Reports Breach of National Bank Account Registry

Breaches of national identity and financial registries expose citizens to long-term fraud risk and show the stakes of securing government-managed databases.

Illustration: France Reports Breach of National Bank Account Registry
AI-generated illustration · Sylvaris

Compromised Credentials Grant Registry Access

France's Ministry of Economy disclosed in February 2026 that a hacker used stolen credentials to access the national bank account registry, known as FICOBA (Fichier National des Comptes Bancaires et Assimilés). The breach exposed data tied to approximately 1.2 million accounts.

The registry contains information about bank accounts held by French residents and is used by authorities for tax and legal purposes. While the exact date of the breach was not specified in public disclosures, the incident was confirmed to have occurred in late January 2026 and was disclosed the following month.

Credential-Based Attack Highlights Access Control Risk

The breach underscores the vulnerability of high-value government databases to credential theft. Unlike exploits that rely on software vulnerabilities, this attack used valid but stolen credentials to gain authorized-appearing access to the system.

Security researchers note that breaches of this type often remain undetected for extended periods because the access patterns appear legitimate. The incident reinforces the need for multi-factor authentication, privileged access monitoring, and anomaly detection in systems handling sensitive government data.

Part of February's Wave of Government Data Incidents

The FICOBA breach was one of several government and infrastructure-related security incidents disclosed in February 2026. During the same month, the European Commission and the Dutch Data Protection Authority confirmed they were compromised through critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile, with work-related data including names, email addresses, and phone numbers accessed.

Collectively, these incidents reflect a pattern of targeted attacks against government systems and critical infrastructure, with attackers using a mix of credential theft, zero-day exploits, and persistent access techniques to breach high-value targets.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.