Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsChecklistsAI RankingsNewsletterStatusTagsAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Checklists
AI Rankings
Newsletter
Status
Tags
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

429+ Articles
114+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Hacker Accesses 1.2 Million French Bank Accounts via
Hacker Accesses 1.2 Million French Bank Accounts via
NEWS

Hacker Accesses 1.2 Million French Bank Accounts via

The French Economy Ministry confirmed that a hacker stole credentials from a government official and accessed France's FICOBA centralized bank account...

Dylan H.

News Desk

February 19, 2026
3 min read

France's National Bank Registry Breached

The French Economy Ministry has confirmed that a hacker compromised credentials belonging to a single government official and used them to access FICOBA — France's centralized database of all bank accounts — consulting information on 1.2 million accounts since the end of January 2026.

FICOBA (Fichier des Comptes Bancaires et Assimilés) is maintained by French tax authorities and contains records for every bank account opened in France.


What Was Exposed

Data TypeRisk Level
Account details (RIB/IBAN)Critical
Account holder identityCritical
Home addressesHigh
Dates of birthHigh
Place of birthHigh
Tax identification numbersCritical

What Was NOT Accessed

  • Account balances
  • Transaction histories
  • The ability to conduct transactions

How It Happened

The attack vector was credential theft — likely a social engineering or phishing attack targeting a single government official with FICOBA access privileges.

1. Attacker compromises government official's credentials
2. Authenticates to FICOBA using stolen credentials
3. Queries 1.2 million bank account records over ~3 weeks
4. Exfiltrates account holder identity, IBAN, and tax data
5. Ministry detects unauthorized access pattern
6. Access terminated and investigation launched

The fact that a single set of credentials provided access to 1.2 million records raises serious questions about:

  • Access controls — Why could one account query this volume of data?
  • Rate limiting — Why weren't mass queries flagged?
  • Multi-factor authentication — Was MFA enforced for FICOBA access?

Scale and Impact

With 1.2 million accounts exposed, the breach affects roughly 1 in 55 French residents. The combination of IBANs, full identities, and tax IDs creates a potent toolkit for:

  • SEPA direct debit fraud — IBANs can be used for unauthorized direct debits across the EU
  • Identity theft — Full identity details enable opening accounts in victims' names
  • Targeted phishing — Attackers can craft highly convincing bank impersonation emails
  • Tax fraud — Tax identification numbers enable filing fraudulent tax returns

Government Response

French authorities are calling for calm while warning that stolen data could be weaponized:

  • All 1.2 million affected account holders will be notified in the coming days
  • The French Economy Ministry has launched a formal investigation
  • Security review of FICOBA access controls is underway
  • Affected individuals are being advised to monitor bank accounts closely

Recommendations for Affected Individuals

  1. Monitor bank accounts — Watch for unauthorized direct debits referencing your IBAN
  2. Contact your bank — Request enhanced fraud monitoring
  3. Be vigilant against phishing — Expect scam emails impersonating your bank or tax authority
  4. File a complaint — Report to CNIL (France's data protection authority) if you receive a notification
  5. Monitor tax filings — Watch for unauthorized tax return filings using your tax ID

A single compromised credential providing access to a national banking registry underscores why privileged access management and monitoring are non-negotiable for government databases.

Sources

  • Cybernews — France Bank Accounts Breach via FICOBA
  • SecurityWeek — French Government Says 1.2 Million Bank Accounts Exposed
  • Security Affairs — French Ministry Confirms Data Access to 1.2M Bank Accounts

Related Reading

  • Fintech Giant Figure Technology Confirms Breach: Nearly 1
  • LexisNexis Confirms Cloud Breach Exposing 400K User
  • Conduent Breach Balloons to Tens of Millions of Americans
#Data Breach#France#Banking#FICOBA#Government#Social Engineering

Related Articles

Cegedim Santé Breach Exposes 15.8 Million French Healthcare Records Including HIV Status

A cyberattack on French healthcare software vendor Cegedim Santé exposed 15.8 million patient records from 3,800 doctors, with leaked data including...

4 min read

LexisNexis Confirms Cloud Breach Exposing 400K User

LexisNexis Legal & Professional confirms a data breach after threat actor FulcrumSec exploited an unpatched React2Shell vulnerability to exfiltrate 2.04...

4 min read

Fintech Giant Figure Technology Confirms Breach: Nearly 1

Blockchain-based lending platform Figure Technology Solutions confirms a data breach affecting nearly 1 million customers after ShinyHunters exploited an...

5 min read
Back to all News