Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
mass-credential-exposurebreach-disclosure-notificationgovernment-diplomatic-threatcredential-access-method

Unauthorized Access to France’s FICOBA Bank Account Registry Exposes 1.2 Million Accounts

Updated 3mo agoFirst seen Feb 19, 20264 sources

France’s Ministry of the Economy and Finance confirmed that an attacker accessed and consulted data tied to ~1.2 million French bank accounts by using stolen login credentials belonging to an authorized government user of the national bank account registry (FICOBA). The intrusion began in late January 2026 and exposed account-linked personal data including IBANs, account holder names, addresses, and in some cases tax identification numbers (DGFiP-issued). Authorities stated the access did not enable viewing balances or initiating transactions.

After detection, the ministry reported it blocked the attacker, notified France’s data protection authority (CNIL), and filed a criminal complaint; impacted individuals are expected to be contacted directly, and banks were alerted to advise customers to remain vigilant. Reporting noted the incident follows other recent cyber disruptions affecting French public services (including attacks impacting La Poste/La Banque Postale and the Interior Ministry), though no motive or attribution for the FICOBA access has been publicly confirmed.

Share:
Unauthorized Access to France’s FICOBA Bank Account Registry Exposes 1.2 Million Accounts
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Apr 7, 20263mo ago

Threat actor advertises alleged FICOBA dataset for sale

On 2026-04-07, a threat actor using the name "bestdata" was reported to be offering for sale a dataset allegedly containing 1.2 million French FICOBA-related records. The listing claimed data from more than 15 financial institutions and included sensitive identity and banking fields such as IBANs, tax identifiers, and other personal details.

Threat Actor Selling 1.2 Million French FICOBA Banking Leads With IBANs, SSNs, and Tax IDs From 15+ Banks
Feb 18, 20264mo ago

CNIL notified and criminal complaint filed over registry breach

Following the discovery and disclosure of the incident, French authorities notified the CNIL data protection authority and filed a criminal complaint. Banks and affected individuals were also being alerted about the exposure and related fraud risks.

French Ministry discloses FICOBA breach affecting 1.2 million accounts

On 2026-02-18, the French Ministry of the Economy publicly confirmed the breach of the national bank account database. It said exposed data included IBANs or account numbers, names, addresses, and in some cases tax identification numbers.

Feb 15, 20264mo ago

French authorities detect and contain the FICOBA intrusion

By mid-February 2026, the French Economy Ministry and DGFiP detected the unauthorized access, blocked the attacker, revoked the compromised credentials, and took steps to prevent data removal. Authorities said the accessed system did not allow viewing balances or conducting transactions.

Jan 31, 20265mo ago

Intruder accesses FICOBA using stolen civil servant credentials

In late January 2026, an attacker used compromised credentials belonging to an authorized government official to access France’s FICOBA national bank account registry. The unauthorized access exposed records tied to about 1.2 million bank accounts.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

25 LINKEDOpen in app
Threat actors
1 linked
Organizations
24 linked
BNP ParibasHSBCSociété GénéraleCredit AgricoleRevolutBforBankCaisse d'EpargneCredit MutuelMonabanqCarrefour BanqueCredit LyonnaisBanque PopulaireAllianz BanqueBoursoramaCrédit Industriel et CommercialAXA BanqueFrance TravailTV5MondeRescanaLa PosteLa Banque PostaleSecurity AffairsLe MondeAnadolu Agency
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Unauthorized Access to France’s FICOBA Bank Account Registry Exposes 1.2 Million Accounts | Mallory