A report published today describes a breach of a French banking registry that exposed the personal and financial data of about 12 million customers. The same page also carries a February 20, 2026 date, and the sources don't support treating this as a new incident. It looks like a republished account of the February 2026 breach of FICOBA, France's national register of bank accounts. The 12 million figure also has weak support. It comes from a single OTHER-tier outlet (ctrlaltnod). Independent analysis by Christophe Mazzola puts the February FICOBA theft at 1.2 million records, which is a tenth of that. None of the sources supplied here is a primary statement from the French Finance Ministry (Bercy) or the DGFiP, the public finance directorate that runs FICOBA. Until an official figure is available, defenders should treat the scale as between 1.2M and 12M and unconfirmed. The FICOBA breach is also part of a larger set of intrusions at the French finance administration during 2026. Several of them used the same method: logging in with a legitimate official's stolen credentials.
What Happened
Timeline check. The ctrlaltnod article (S1) carries a September 26, 2026 byline and also a February 20, 2026 date tag. Mazzola (S7) places the FICOBA theft in February and says it used one officer's credentials. GFdaily (S4), published August 15, describes a FICOBA breach through credentials belonging to a government official outside DGFiP, with access lasting "weeks" before anyone noticed. No source describes a second FICOBA compromise in September. The most likely reading is that S1 is recycling the February incident.
The wider pattern. The FICOBA breach sits alongside a run of incidents across the French state in 2026:
- February: FICOBA. Mazzola reports 1.2M records stolen. S1's claim of 12M is unverified.
- Before April 30: According to Mazzola, ANTS, the agency that issues secure identity documents, lost 11.7 million accounts. On April 30 the Prime Minister announced €200M for state cybersecurity. The 11.7M figure is close to S1's "12 million", so the two incidents may have been conflated. This can't be confirmed from these sources.
- Late June and late July: Two intrusions at DGFiP. The French Finance Ministry confirmed them on August 13–14 (reported by Reuters and BleepingComputer) after a group calling itself "ZeroBytes" listed the data for sale on PwnForums on August 12.
- Around August 18: France 24 reports that DGFiP head Amélie Verdier disclosed a further breach, detected on a Monday and still being assessed at the time.
- September 25: A 01net headline, seen here only through a comment-thread aggregator (S5), reports a new leak of IBANs (international bank account numbers) belonging to 143,000 French people. The page gives no detail and the report has not been corroborated.
What Was Taken
FICOBA. According to GFdaily, the register holds IBANs, account-holder identity details and addresses, and occasionally a tax identifier. It holds no balances and no transaction history. S1 claims names, addresses, phone numbers and banking details were exposed. Record counts range from 1.2M (Mazzola) to 12M (ctrlaltnod). Neither figure has official confirmation in these sources.
DGFiP tax data (June/July). Figures vary by source: - Total: the ministry's statement quoted by BleepingComputer gives 678,000 individuals and businesses. Mazzola gives 678,438 rows. - Individuals only: Mazzola says just under 393,000. Les Echos, quoting Bercy, says "just over 350,000". - Fields: name, birth name, date and place of birth, tax and postal address, household composition, spouse identity, family quotient, reference tax income and withholding rate. For businesses, company name and SIREN number (the French company registration number). - Messages: Bercy told Les Echos that in fewer than 250 cases the attacker could see messages between taxpayers and the tax administration. - Not affected: the ministry says online accounts, user IDs and passwords were not compromised.
Land registry (SPDC, DGFiP's professional portal for cadastral property data). DGFiP puts it at 200,000 accounts (France 24). ZeroBytes claims 252,149 records covering more than 2 million property owners (BleepingComputer). ZeroBytes told AFP the data had already been sold to "two people" for "thousands of euros". That claim comes from the attacker and has not been verified.
Why It Matters
- Targeting data, not credentials. The stolen fields are mostly things people can't change. You can't easily get a new IBAN, and household income doesn't change on request. Mazzola's point is that a list sorted by declared income tells criminals whom to target, which makes the tax files more useful to them than an ordinary contact list.
- Fraud risk. GFdaily notes that a name, IBAN and address together are close to everything needed to set up fraudulent SEPA direct debits (the euro-area bank payment scheme). They also make convincing bank-impersonation phishing much easier, including against fiat on-ramps to crypto exchanges.
- The same weakness keeps being used. Credential abuse against DGFiP repeated over several months, and Mazzola also documents a seven-week gap between detection in June and public disclosure in August. Together these suggest a systemic identity-governance problem, not a one-off failure.
- The reporting itself is a risk. Stale incidents republished with inflated or misread figures make both triage and public warnings less reliable. Verify the date and record count before escalating.
The Attack Technique
The sources agree that no novel exploit was involved:
- FICOBA. GFdaily reports the attacker used valid credentials belonging to an official outside DGFiP, so the activity looked like legitimate use. How those credentials were obtained is unknown, and the official has not been named.
- DGFiP, June. Mazzola describes the sequence as:
- obtaining an authorised officer's credentials;
- compromising internal servers and the VPN;
- using an internal lookup tool, working as intended, to pull taxpayer records in bulk.
France 24 reports that ZeroBytes claimed VPN access used by tax officials. Access was cut on the day it was detected during a routine check. Mazzola credits that quick cut-off with keeping the haul to about 678K rows. - Attribution. ZeroBytes calls itself a French hacking duo and says its motive is "money, I imagine". Nothing in these sources links ZeroBytes to the February FICOBA breach.
What Organizations Should Do
- Require phishing-resistant MFA on every route into sensitive registries, including VPN, internal query tools, and access granted to officials from other agencies. Revoke shared or inherited access that has no current business owner.
- Monitor query behaviour, not just logins. Alert on bulk lookups, unusual volumes, off-hours sessions and lookups outside a user's normal caseload. In both the FICOBA and DGFiP cases, legitimate tools were used legitimately, just at the wrong scale.
- Limit what each query can return. Apply per-user rate limits, return only the fields a role needs, and require a stated justification for high-sensitivity searches such as FICOBA and income data.
- Banks and exchanges: prepare for sharper fraud. Tighten checks on new SEPA direct-debit mandates, flag first-time creditors taking debits from exposed accounts, and warn customers that attackers may quote their real IBAN or income details.
- Close the gap between detection and notification. Pre-approve notification templates and CNIL (French data protection authority) filing workflows so that affected people are warned during the window when phishing works best, not weeks later.
- Check incident reports before acting on them. Cross-check dates and record counts against official statements before escalating a "new" breach. The 12M FICOBA figure in circulation now is uncorroborated and probably refers to February.
Sources: French Banking Registry Breach: 12M Records Compromised | French tax authority data breach affects 678,000 individuals | French taxpayers' data stolen in cyber attack, ... | Stolen government credentials gave access to IBANs and account-hold... | New data leak to the State: the IBANs of 143,000 French people comp... | Tax hack: What we know about the cyberattacks on French ... | DGFiP breach: seven weeks of silence, the same vector | « Consulter régulièrement les mouvements sur votre compte bancaire...