Cyber & AI intelligence
Wasteland.
Briefs indexed2884
Issues29
Published Mondays07:30 CT
▣ Breach FRENCH-BANKING-REG 2026-09-26

FICOBA French Bank Account Registry: Credential Abuse Exposes Account Holder Data

"A report published today describes a breach of a French banking registry that exposed the personal and financial data of about 12 million customers. The same page also carries a February 20, 2026 date, and the sources…"

A report published today describes a breach of a French banking registry that exposed the personal and financial data of about 12 million customers. The same page also carries a February 20, 2026 date, and the sources don't support treating this as a new incident. It looks like a republished account of the February 2026 breach of FICOBA, France's national register of bank accounts. The 12 million figure also has weak support. It comes from a single OTHER-tier outlet (ctrlaltnod). Independent analysis by Christophe Mazzola puts the February FICOBA theft at 1.2 million records, which is a tenth of that. None of the sources supplied here is a primary statement from the French Finance Ministry (Bercy) or the DGFiP, the public finance directorate that runs FICOBA. Until an official figure is available, defenders should treat the scale as between 1.2M and 12M and unconfirmed. The FICOBA breach is also part of a larger set of intrusions at the French finance administration during 2026. Several of them used the same method: logging in with a legitimate official's stolen credentials.

What Happened

Timeline check. The ctrlaltnod article (S1) carries a September 26, 2026 byline and also a February 20, 2026 date tag. Mazzola (S7) places the FICOBA theft in February and says it used one officer's credentials. GFdaily (S4), published August 15, describes a FICOBA breach through credentials belonging to a government official outside DGFiP, with access lasting "weeks" before anyone noticed. No source describes a second FICOBA compromise in September. The most likely reading is that S1 is recycling the February incident.

The wider pattern. The FICOBA breach sits alongside a run of incidents across the French state in 2026:

What Was Taken

FICOBA. According to GFdaily, the register holds IBANs, account-holder identity details and addresses, and occasionally a tax identifier. It holds no balances and no transaction history. S1 claims names, addresses, phone numbers and banking details were exposed. Record counts range from 1.2M (Mazzola) to 12M (ctrlaltnod). Neither figure has official confirmation in these sources.

DGFiP tax data (June/July). Figures vary by source: - Total: the ministry's statement quoted by BleepingComputer gives 678,000 individuals and businesses. Mazzola gives 678,438 rows. - Individuals only: Mazzola says just under 393,000. Les Echos, quoting Bercy, says "just over 350,000". - Fields: name, birth name, date and place of birth, tax and postal address, household composition, spouse identity, family quotient, reference tax income and withholding rate. For businesses, company name and SIREN number (the French company registration number). - Messages: Bercy told Les Echos that in fewer than 250 cases the attacker could see messages between taxpayers and the tax administration. - Not affected: the ministry says online accounts, user IDs and passwords were not compromised.

Land registry (SPDC, DGFiP's professional portal for cadastral property data). DGFiP puts it at 200,000 accounts (France 24). ZeroBytes claims 252,149 records covering more than 2 million property owners (BleepingComputer). ZeroBytes told AFP the data had already been sold to "two people" for "thousands of euros". That claim comes from the attacker and has not been verified.

Why It Matters

The Attack Technique

The sources agree that no novel exploit was involved:

France 24 reports that ZeroBytes claimed VPN access used by tax officials. Access was cut on the day it was detected during a routine check. Mazzola credits that quick cut-off with keeping the haul to about 678K rows. - Attribution. ZeroBytes calls itself a French hacking duo and says its motive is "money, I imagine". Nothing in these sources links ZeroBytes to the February FICOBA breach.

What Organizations Should Do

  1. Require phishing-resistant MFA on every route into sensitive registries, including VPN, internal query tools, and access granted to officials from other agencies. Revoke shared or inherited access that has no current business owner.
  2. Monitor query behaviour, not just logins. Alert on bulk lookups, unusual volumes, off-hours sessions and lookups outside a user's normal caseload. In both the FICOBA and DGFiP cases, legitimate tools were used legitimately, just at the wrong scale.
  3. Limit what each query can return. Apply per-user rate limits, return only the fields a role needs, and require a stated justification for high-sensitivity searches such as FICOBA and income data.
  4. Banks and exchanges: prepare for sharper fraud. Tighten checks on new SEPA direct-debit mandates, flag first-time creditors taking debits from exposed accounts, and warn customers that attackers may quote their real IBAN or income details.
  5. Close the gap between detection and notification. Pre-approve notification templates and CNIL (French data protection authority) filing workflows so that affected people are warned during the window when phishing works best, not weeks later.
  6. Check incident reports before acting on them. Cross-check dates and record counts against official statements before escalating a "new" breach. The 12M FICOBA figure in circulation now is uncorroborated and probably refers to February.

Sources: French Banking Registry Breach: 12M Records Compromised | French tax authority data breach affects 678,000 individuals | French taxpayers' data stolen in cyber attack, ... | Stolen government credentials gave access to IBANs and account-hold... | New data leak to the State: the IBANs of 143,000 French people comp... | Tax hack: What we know about the cyberattacks on French ... | DGFiP breach: seven weeks of silence, the same vector | « Consulter régulièrement les mouvements sur votre compte bancaire...