Stolen official login used to access French bank account database

Stolen official login used to access French bank account database

The details of up to 1.2 million French bank accounts were accessed illicitly in a recent compromise involving credentials stolen from a government official. 

Attackers were able to access the FICOBA database, a national file of all bank accounts opened in France, and leveraged the stolen credentials to view personal information about account holders, basic account information like IBANs, and, in some cases, tax-identification numbers.

The database was initially accessed at the end of January 2026, and this access was maintained over several days.

The French Government said that it would be notifying those affected by the breach in the coming days.

Michael Jepson, Penetration Testing Manager at CybaVerse, said: “If individual members of an organisation can access large volumes of sensitive data unilaterally, this creates a structural weakness where a single set of compromised credentials can lead to widespread data exposure. Any policy that allows broad access to sensitive systems via a single identity, without additional safeguards, introduces significant risk.

“Traditionally, access scope often increased with seniority, an approach that is now widely recognised as problematic in modern threat environments. Modern security practice recognises that access should be determined strictly by operational need rather than hierarchy. Senior figures are frequently primary targets for threat actors, which makes excessive privilege particularly dangerous.

“Organisations in both the public and private sectors should adopt zero trust principles, ensuring that access requests are not trusted solely on the basis of valid credentials. Individuals should only have access to the data necessary for their specific role and daily operations.

“Automated monitoring should be implemented, particularly in more mature security environments, to detect anomalous behaviour, even from legitimate users, with appropriate human oversight to investigate and validate alerts. Unusual patterns such as repeated bulk access, manipulation, or excessive data export should be flagged for review.

“The compromised data could be used to conduct phishing campaigns, submit fraudulent credit applications, or facilitate financial fraud. Individuals affected should remain vigilant, exercise caution online, and monitor financial accounts and credit records for suspicious activity.”

George Foley, Security Spokesperson for ESET Ireland, said: “Most people hear ‘bank data breach’ and picture a technical break-in. In reality, a lot of these incidents are closer to someone getting hold of the right keys. If an attacker gets a legitimate login, they often don’t need to ‘hack’ anything. They just log in.”

ESET Ireland said data like names, addresses and account identifiers can be enough to power follow-on fraud, particularly scams that pretend to be from banks, revenue-type bodies, or official support teams.

Foley added:“Even where money can’t be moved directly, the details are still valuable. They help criminals sound convincing. That’s when you get the ‘we need to verify you’ calls, the fake security emails, and the pressure to act fast.”

ESET Ireland said organisations should treat account security as a frontline control, including strong authentication, tighter access rules, and proper monitoring for unusual account activity, especially in systems used by large numbers of staff.

James Neilson, SVP of Global at OPSWAT, said: “The exposure of 1.2 million bank accounts is significant, and the main concern now will be stolen data being used to conduct identity fraud and phishing attacks. For example, tax identifiers could be used to mimic official tax agencies or to file fraudulent tax returns.

“Both the financial sectors and the government’s reputations depend on their ability to protect people’s sensitive information. The theft of information can result not only in financial damage but also in jeopardising the government’s values and reputation.

“Organisations must be equipped to detect and neutralise hidden threats by managing data flows and inspecting files in transit across systems, users, and the broader digital supply chain.

“Securing access credentials, implementing malware detection, and enforcing data sanitisation can reduce the risk of attackers establishing a foothold before data is stolen. Once an attack begins, swift detection, response and recovery are essential.”

Browse our latest issue

Intelligent CISO

View Magazine Archive