The French banking regulator has confirmed a major data breach affecting 1.2 million bank accounts. The attacker stole credentials belonging to a government official and used them to gain access to the country's bank account records.

The Directorate General of Public Finances detected the intrusion at the end of January 2026 and restricted access to prevent the extraction of data from FICOBA, the comprehensive database that records every bank account opened in French banking institutions.
The attacker compromised the credentials of an officialwho had access to FICOBA through inter-ministerial information exchange channels. This legitimate access route allowed the threat actor to view the database without immediately triggering alarms, demonstrating how credential theft allows attackers to masquerade as trusted internal users and bypass perimeter security checks.
See also: Cyberattack at University of Mississippi Medical Center leads to clinic closures
French National Bank Authority: What data was leaked?
FICOBA contains sensitive personal data, including bank account details such as RIB and IBAN numbers, account holder IDs, addresses and in some cases tax identification numbers. The database acts as France’s central registry for tracking financial accounts, making it a high-value target for criminals looking for identity theft, financial fraud opportunities or information on French taxpayers.

The Directorate General of Public Finances did not disclose how long the intrusion had been going on before it was detected, the specific method the attackers used to steal official credentials, or whether the compromised accounts were protected by multi-factor authentication. The ministry said it implemented immediate access restrictions to stop the attack and prevent further unauthorized access.
Work is continuing to restore the service with enhanced security measures, although the ministry did not provide a timeline for full restoration. Affected users will receive individual notifications in the coming days, informing them of the incident. The breach notification follows the requirements of the European Union's General Data Protection Regulation.
See also: Operation Red Card 2.0: 651 arrests for online fraud in Africa
The ministry has contacted French banking institutions to coordinate customer awareness campaigns, highlighting the need for increased vigilance against financial fraud and identity theft. Compromised bank account details allow for various attack methods, including targeted phishing campaigns, account takeover attempts and the initiation of fraudulent transactions.

The ministry reported the incident to the National Commission for Information Technology and Civil Liberties, France's data protection authority, equivalent to other supervisory authorities in the European Union. The CNIL will investigate whether the Directorate General of Public Finances implemented adequate security measures to protect FICOBA's data and can impose sanctions if violations of data protection law are found.
See also: Tenga: Sex toy manufacturer victim of data breach
Authorities have also filed a formal criminal complaint, launching an investigation into the breach. French prosecutors will try to identify the threat actor, determine whether the breach is linked to organized cybercrime groups or state-owned enterprises, and pursue criminal charges if suspects are identified. Citizens whose accounts appear on FICOBA should monitor their bank statements for unauthorized transactions, be alert to suspicious communications claiming to come from financial institutions or government agencies, and report any attempted fraud to the authorities.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
