ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Hackers access French National Bank account registry, expose data linked to 1.2 million accounts

The French Ministry of Finance has disclosed a cybersecurity incident that exposed data associated with approximately 1.2 million user accounts after a threat actor accessed the country’s national bank account registry.


An internal investigation determined that in late January a hacker used credentials stolen from a civil servant who had access to an interministerial information sharing platform. The compromised credentials enabled access to part of the FICOBA database, which records all bank accounts opened at French financial institutions.


FICOBA, a centralized registry operated by the Direction générale des Finances publiques, maintains records of the existence and identifiers of bank accounts. French banking institutions are required by law to provide this data for tax enforcement purposes.


The database accessed during the incident contained sensitive personal and financial information, including bank account details such as RIBs and IBANs, account holder identities, physical addresses and, in some cases, taxpayer identification numbers.


The Ministry stated that immediate action was taken to restrict the threat actor’s access once the intrusion was detected. Despite the swift response, officials believe data linked to about 1.2 million accounts had already been exposed and may have been exfiltrated.


The cyberattack has disrupted FICOBA’s operations. Work is underway to restore the system with enhanced security measures, but no timeline has been provided for when the registry will return to full service.


Affected individuals will be notified directly in the coming days. Banking institutions across France have been informed and are expected to advise customers to exercise heightened vigilance.


Authorities reported a surge in scam attempts circulating via email and SMS messages that seek to obtain personal information or money from recipients. The Ministry emphasized that the tax administration does not request login credentials or bank card numbers through electronic messages.


The French data protection authority, Commission nationale de l’informatique et des libertés, has been notified of the breach.


Information technology teams at the tax authority are working alongside the Ministry and the Agence nationale de la sécurité des systèmes d’information to strengthen system defenses and restore full operational capacity.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543