Europe
French bank account registry (FICOBA)
The French Ministry of Finance disclosed a data breach affecting information tied to more than 1.2 million accounts in the national bank account registry, known as FICOBA.
In late January, a threat actor used credentials stolen from a civil servant with access to an interministerial information-sharing platform. This access allowed the attacker to access part of a database containing records for all bank accounts opened at French banking institutions. The compromised data includes bank identity details (RIBs), international bank account numbers (IBANs), account holder identities, physical addresses, and, in some cases, taxpayer identification numbers.
The ministry said it acted immediately to restrict the threat actor's access after detecting the incident. However, it was unable to prevent the exposure of data linked to approximately 1.2 million accounts, which may have been exfiltrated.
How it could affect your business
Email threats, such as business email compromise (BEC) and account takeovers (ATO), are becoming harder to detect as attackers use AI to craft highly convincing messages that trick users into revealing sensitive information, including login credentials. Organizations must strengthen user awareness while also deploying advanced technologies, including Gen AI-driven detection, to identify such attempts and prevent credential abuse before it escalates.
