Loading market data...

Stolen government credentials gave access to IBANs and account-holder details — enough to sharpen ph

Stolen government credentials gave access to IBANs and account-holder details — enough to sharpen ph

What the register holds

FICOBA is the reference file French banks check against when accounts are opened or closed. It lists IBANs, account-holder details, and rarely a fiscal identifier. What it doesn't list is money — no balances, no transaction records.

That absence limits the direct damage. An attacker can't see how much sits in a given account, or where the money flows. What they can see is who banks where, and under what name.

How the access happened

This wasn't a direct exploit of DGFiP's public-facing systems. The breach used credentials belonging to a government official outside DGFiP. Legitimate access, in other words — the kind that doesn't trip the usual alarms until someone notices activity that doesn't fit.

That also makes it harder to close off after the fact. The official's credentials are presumably revoked, but the access window ran for weeks before it was caught.

The crypto angle

The real risk here is phishing aimed at euro on-ramps. With an IBAN, a name, and an address, a scammer can craft messages that look like they come from a real bank or exchange — the kind that asks a user to "confirm" details or "verify" a deposit.

The threat of fraudulent SEPA direct debits also goes up. The stolen fields are close to everything needed to set one up.

Exchanges should expect higher-quality scams targeting SEPA deposits. Compliance teams can already tie on-chain flows to real-world identities through KYC records and fiat-rail metadata; the breach hands attackers a head start on the same mapping.

Who gets told

Banks have been alerted, and affected individuals will be informed. The notification process is the part that matters most now — the gap between the breach being confirmed and people learning they're in it is when phishing works best.

The official whose credentials were used hasn't been named, and how the credentials were obtained remains an open question. Until the notifications land, the safest assumption for anyone who used SEPA deposits in the affected period is that their details may be out there.

Let me count words: roughly 400. I should expand a bit to hit 450-700. Let me add a bit more detail. Actually, let me re-read the rules. 450-700 words. My draft is around 400. Let me expand slightly. I can add a sentence or two about the DGFiP confirmation, or the scale. Let me add: - The scale comparison: 1.2M is under 1% of the register — that's a meaningful framing. - The fact that balances aren't included limits direct impact. Let me expand the lead and add a bit more in each section. Actually, let me rewrite with more substance: Lead: France's tax authority, DGFiP, confirmed that an attacker used stolen government credentials to reach FICOBA, the national bank-account register. Roughly 1.2 million accounts were consulted — under 1% of the register — between late January and February 13, 2026. The register holds IBANs and account-holder details, but not balances or transaction histories. Section on what's in it, section on how, section on crypto angle, section on next steps. Let me expand each slightly. I'll aim for ~500-550 words. Also, the instruction says "After the lead, write 3-5 short sections." So I have 4 sections which is fine. Let me finalize and count more carefully. Actually, let me count the paragraphs I have: Lead: 3 sentences (about 70 words) Section 1: 2 paragraphs, ~80 words Section 2: 2 paragraphs, ~70 words Section 3: 3 paragraphs, ~110 words Section 4: 2 paragraphs, ~80 words Total ~410. I need to add ~100 words. Let me expand the lead and add detail. Let me add to the lead: "The French tax authority confirmed the illegitimate access this week, and said banks have been alerted." — but wait, the facts don't say "this week" specifically. They say confirmed. I shouldn't invent timing. Let me keep it neutral. Let me expand the crypto section a bit more, and add a sentence to the lead about why it matters. Actually the instruction says lead should be 2-3 sentences. Let me keep it tight. Let me expand section 1: add a sentence about what the register is used for — banks check it when accounts open/close. That's in the facts? The facts say "the national bank-account register FICOBA" and it "contains IBANs and account-holder details". I can describe it as the national register without inventing functions. Actually I said "the reference file French banks check against" — that's an inference not directly in the facts. Let me be careful. The facts say it's the "national bank-account register". I'll just call it that. Let me rewrite carefully with only facts: Facts I can use: - DGFiP confirmed illegitimate access - ~1.2M accounts consulted, under 1% of register - Access from late January until 13 Feb 2026 - Register contains IBANs and account-holder details, not balances or transaction histories - Attack used credentials of a government official outside DGFiP, not direct exploit of public-facing systems - Risks: more convincing phishing, potential fraudulent SEPA direct debits - Banks alerted, affected individuals will be informed - Data includes IBAN/RIB, identity and postal address, rarely fiscal identifier - Could enable targeted phishing against crypto users using SEPA deposits - Compliance teams can link on-chain flows to real-world identities using KYC records and fiat-rail metadata - Absence of balances and transaction history limits direct impact - Exchanges should expect higher-quality scams targeting euro on-ramps OK. Let me write the final version. Title: "France Confirms FICOBA Breach Exposed 1.2 Million Bank Accounts" Hmm, that's a bit plain. The crypto angle: "French Bank-Register Breach Puts 1.2 Million Accounts in Phishing Crosshairs" — that's more newsy. Let me go with: "France's FICOBA Breach Hit 1.2 Million Accounts, Tax Agency Confirms" Or: "French Tax Agency Confirms FICOBA Breach Touched 1.2 Million Bank Accounts" I'll go with something like that. Let me make it specific and factual. Final title: "France's Tax Agency Confirms FICOBA Breach Hit 1.2 Million Bank Accounts" Subtitle: "Stolen government credentials exposed IBANs and account-holder details — data that could sharpen phishing aimed at crypto users who deposit via SEPA." Now the content. Let me write it fully. Word count target: ~520. Let me write:

France's tax authority, DGFiP, confirmed an illegitimate access to FICOBA, the national bank-account register. Roughly 1.2 million accounts were consulted — under 1% of the register — between late January and February 13, 2026.

The register holds IBANs and account-holder details, but no balances and no transaction histories. That limits the direct damage. What it doesn't limit is phishing.

What the data contains

FICOBA entries include an IBAN or RIB, the account holder's identity and postal address, and occasionally a fiscal identifier. No balance, no transaction list. An attacker who got in can't see how much money sits in an account, or where it moves.

What they can see is who banks where, under what name, at what address. That's a targeting list.

How the access happened

This wasn't a direct exploit of DGFiP's public-facing systems. The access used credentials belonging to a government official outside DGFiP. Legitimate access, in other words — the kind that doesn't trip alarms until someone notices activity that doesn't fit the pattern.

The window ran for weeks before it was caught. The credentials were presumably revoked after the fact, but the access had already happened.

The crypto angle

For crypto users who fund accounts via SEPA, the risk is sharper phishing. With an IBAN, a name, and an address, a scammer can build a message that looks like it came from a real bank or exchange — the kind that asks a user to confirm details or verify a deposit. The threat of fraudulent SEPA direct debits also goes up, since the stolen fields are close to everything needed to set one up.

Exchanges should expect higher-quality scams targeting euro on-ramps. Compliance teams can already link on-chain flows to real-world identities using KYC records and fiat-rail metadata; the breach hands attackers a head start on the same mapping.

Who gets told

Banks have been alerted, and affected individuals will be informed. The gap between the breach being confirmed and people learning they're caught up in it is when phishing works best.

The official whose credentials were used hasn't been named, and how those credentials were obtained remains an open question. Until the notifications land, anyone who used SEPA deposits in the affected period should assume their details may be out there.

Let me count that. Lead: ~60 words Section 1: ~80 words Section 2: ~65 words Section 3: ~110 words Section 4: ~70 words Total ~385. Still a bit short. Let me expand a bit more. I can add a sentence to the lead about why it matters. And expand the crypto section. Let me add to the lead: "The French tax authority confirmed the access this month, and said banks have been alerted." — but the facts say banks were alerted, not that DGFiP said so. Let me just say "Banks have been alerted." Actually, let me add a sentence about the scale: "The affected accounts represent under 1% of the register, but the reach of the data goes beyond the accounts themselves." Hmm, that's a bit of editorializing. Let me expand the crypto section with the point about KYC records and fiat-rail metadata more explicitly. Also add to the lead: "For crypto users who deposit via SEPA, the stolen data could enable targeted phishing — a risk the affected exchanges are now weighing." But I shouldn't invent that exchanges are weighing it. Just say what the facts say. Let me add: "The absence of balances and transaction history limits the direct impact — but the data is enough to build convincing phishing campaigns." OK let me just write it a bit longer and count properly. Here's my final draft: ---

France's tax authority, DGFiP, confirmed an illegitimate access to FICOBA, the national bank-account register. Roughly 1.2 million accounts were consulted — under 1% of the register — between late January and February 13, 2026. The register holds IBANs and account-holder details, but no balances and no transaction histories.

That absence limits the direct damage. What it doesn't limit is phishing. With an IBAN, a name, and an address, the stolen data is enough to build messages that look like they come from a real bank or exchange.

What the data contains

FICOBA entries include an IBAN or RIB, the account holder's identity and postal address, and occasionally a fiscal identifier. No balance, no transaction list. An attacker who got in can't see how much money sits in an account, or where it moves.

What they can see is who banks where, under what name, at what address. That's a targeting list, and for crypto users who fund accounts through SEPA, it's a direct concern.

How the access happened

This wasn't a direct exploit of DGFiP's public-facing systems. The access used credentials belonging to a government official outside DGFiP. Legitimate access, in other words — the kind that doesn't trip alarms until someone notices activity that doesn't fit the pattern.

The window ran for weeks before it was caught. The credentials were presumably revoked after the fact, but the access had already happened.

The crypto angle

For crypto users who deposit via SEPA, the risk is sharper phishing aimed at euro on-ramps. The threat of fraudulent SEPA direct debits also goes up, since the stolen fields are close to everything needed to set one up. Exchanges should expect higher-quality scams targeting these rails.

Compliance teams can already link on-chain flows to real-world identities using KYC records and fiat-rail metadata. The breach hands attackers a head start on the same mapping — they now hold the fiat side of the