Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
third-party-vendor-breachmass-credential-exposurebreach-disclosure-notificationidentity-impersonation-fraud

Data exposures tied to third-party access and credential misuse in Ukraine and France

Updated 3mo agoFirst seen Feb 20, 20264 sources

Ukraine’s National Bank (NBU) took its collectible coin/numismatic online store offline after a cyberattack against a supporting contractor potentially exposed customer registration data (names, phone numbers, emails, and delivery addresses). The NBU said core banking systems were not affected and no payment card or banking data was compromised, but warned the exposed PII could be leveraged for phishing and other follow-on fraud; the incident was described as consistent with a supply-chain intrusion path.

In France, authorities disclosed illegal access to a portion of the National Bank Accounts File (FICOBA)—a government database used for tax, customs, and law-enforcement purposes—after an attacker impersonated a civil servant and used valid credentials to query data. Officials said up to 1.2 million accounts may have been impacted, with exposed fields potentially including account numbers, names, addresses, and in some cases tax identifiers; DGFiP, supported by ANSSI, is investigating and notifying affected individuals while banks were alerted to heighten fraud/phishing monitoring. Separately, Safran Group denied being cyberattacked, stating that a leaked dataset containing “non-strategic” order/customer details was inadvertently exposed via a third-party provider, with external analysis suggesting the compromise occurred elsewhere in the supply chain rather than within Safran’s own systems.

Share:
Data exposures tied to third-party access and credential misuse in Ukraine and France
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Feb 20, 20264mo ago

NBU says contractor breach did not affect core banking systems or card data

On February 20, 2026, the NBU stated that the incident was limited to the contractor environment, with network isolation preventing impact to core systems, and said payment card data and other banking information were not compromised.

Ukraine's central bank takes collectible coin store offline after contractor breach

The National Bank of Ukraine took its online store for collectible coins and numismatic products offline after a cyberattack on a supporting contractor potentially exposed customer names, phone numbers, email addresses, and delivery addresses.

Feb 19, 20264mo ago

France notifies CNIL, alerts banks, and prepares to contact affected individuals

Following disclosure of the FICOBA incident, authorities notified the CNIL, warned banks about possible fraud and phishing risks, and said affected individuals would be informed while ANSSI and finance ministry teams supported the investigation.

France discloses FICOBA breach affecting up to 1.2 million accounts

On or before February 19, 2026, the French government disclosed that unauthorized access to FICOBA may have exposed data linked to up to 1.2 million bank accounts, including names, addresses, account numbers, IBANs, and in some cases tax identification numbers.

French authorities detect FICOBA breach and restrict access

After detecting the malicious activity internally, French authorities took measures to limit the attacker's access and began restoration and security-hardening work on affected FICOBA systems.

Jan 28, 20265mo ago

Attackers begin unauthorized access to France's FICOBA database

In late January 2026, a threat actor used credentials stolen from a civil servant to impersonate an authorized user and query part of France's national bank account database, FICOBA, via an interministerial information exchange.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

3 LINKEDOpen in app
Organizations
3 linked
National Bank of UkraineNational Bank of Ukraine online store contractorRecorded Future
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.