French FICOBA Bank Account Registry Accessed Using Stolen Government Credentials
French authorities confirmed unauthorized access to FICOBA, the national registry of bank accounts, after an attacker used stolen credentials belonging to a government official to view records tied to roughly 1.2 million accounts. Exposed data reportedly included account numbers and account-holder identity details (names, addresses, and in some cases tax identification numbers), while balances and transaction histories were not accessed; officials said the access was detected and blocked quickly and that affected individuals would be notified. A criminal complaint was filed and the incident was reported to CNIL (France’s data protection authority).
Reporting also indicated the government described the incident as involving data “stolen” from the repository, though other accounts emphasized that access was interrupted before exfiltration could occur, leaving the precise extent of data removal unclear. The incident highlights the risk of credential compromise for privileged government access to sensitive financial registries and the downstream exposure of identity-linked banking metadata that can enable targeted fraud and social engineering even without transaction data.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
4 events from the most recent confirmed update back to the earliest known activity.
Authorities file complaint, notify CNIL, and prepare victim notifications
Following the disclosure, French authorities said they had filed a criminal complaint and informed CNIL, France’s data protection authority. The government also said affected account holders would be notified about the breach.
French government discloses FICOBA breach affecting 1.2 million accounts
On or before February 19, 2026, the French government publicly reported that an unauthorized third party had accessed FICOBA and stolen data associated with roughly 1.2 million bank accounts. The compromised information included account numbers, names, addresses, and in some cases tax identification numbers.
French authorities block access after detecting the intrusion
After the unauthorized access was discovered, French authorities immediately revoked the attacker’s access to the system. Officials said account balances and transaction data were not accessed, and stated that further exfiltration was prevented once the breach was detected.
Attacker uses stolen credentials to access FICOBA in January
In January 2026, an unknown attacker used stolen credentials belonging to a French government official to access FICOBA, France’s national registry of bank accounts. The intrusion exposed personal and banking-related data tied to about 1.2 million accounts.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
3 references tracked. Mallory keeps watching after this page renders.
Attacker gets into France's DB listing all bank accounts • The Register
go.theregister.com
Open sourceHacker accesses data from 1.2 million French bank accounts using stolen credentials | SC Media
scworld.com
Open sourceteiss - News - Hacker stole data on 1.2m bank accounts from French government accounts repository
teiss.co.uk
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


