Attackers Access France’s National Bank Account Database
French authorities have confirmed that a threat actor illegally accessed part of the country’s National Bank Accounts File (FICOBA) — a centralized system that records bank accounts across France.
According to France’s data protection authority (CNIL), the database contains information on more than 80 million individuals. Government officials stated that approximately 1.2 million accounts may have been impacted.
How the Breach Happened
The FICOBA system is operated by the Directorate General of Public Finances (DGFiP).
Authorities report that the attacker:
- Impersonated a civil servant
- Used legitimate credentials
- Queried part of the database through interministerial access channels
This was not a system “hack” in the traditional sense, but rather a case of credential misuse and unauthorized access.
What Data Is Stored in FICOBA?
FICOBA serves as a registry of all bank accounts opened at French financial institutions.
The database includes:
- Account numbers
- Names
- Addresses
- In some cases, tax identification numbers
However, officials clarified that the system does not provide access to:
- Account balances
- Transaction histories
- The ability to move funds
It is primarily used by tax authorities, customs officials, and law enforcement agencies for fraud detection and judicial investigations.
Timeline & Response
- Malicious activity reportedly began in late January
- The intrusion was detected internally
- Containment measures were implemented to limit exposure
Authorities have confirmed:
- Affected individuals will be notified directly
- Banks have been alerted to monitor for follow-on fraud
- Customers should be cautious of phishing attempts
Cybersecurity teams from the Ministry of Finance and France’s national cybersecurity agency (ANSSI) are assisting with the investigation and strengthening defenses.
Why This Matters
This incident underscores the growing risk surrounding large, centralized government databases.
Across Europe, administrative systems have become attractive targets for:
- Financially motivated cybercriminals
- State-linked espionage actors
- Identity-focused threat groups
In a recent report, the EU’s cybersecurity agency (ENISA) warned that public administration entities represent high-value targets due to the strategic importance of the data they collect.
At this time, no threat actor has been officially attributed.



