Security News

Cybersecurity news aggregator

📰
INFO News SecurityWeek

French Government Says 1.2 Million Bank Accounts Exposed in Breach

Read Full Article →

DATA BREACHES French Government Says 1.2 Million Bank Accounts Exposed in Breach The Ministry of Economy reported discovering unauthorized access to the national bank account registry FICOBA. By Eduard Kovacs | February 19, 2026 (10:02 AM ET) Flipboard Reddit Whatsapp Email France’s Ministry of Economy on Wednesday disclosed a breach that exposed information on 1.2 million bank accounts. Investigators discovered unauthorized access to the national bank account registry FICOBA. The ministry stated on its website that a threat actor stole credentials belonging to an official and used them to access the database storing information on all bank accounts opened in France. The breach occurred in late January and impacted 1.2 million accounts, including IBANs, account holder names, addresses, and in some cases tax identifiers. The attacker’s access has been terminated and impacted individuals are being notified. Officials said the attacker would not have been able to conduct banking operations or even view account balances. ADVERTISEMENT. SCROLL TO CONTINUE READING. Nevertheless, individuals have been warned of potential scams and phishing attempts. Michael Jepson, penetration testing manager at CybaVerse, commented, “If individual members of an organisation can access large volumes of sensitive data unilaterally, this creates a structural weakness where a single set of compromised credentials can lead to widespread data exposure. Any policy that allows broad access to sensitive systems via a single identity, without additional safeguards, introduces significant risk.” “Traditionally, access scope often increased with seniority, an approach that is now widely recognised as problematic in modern threat environments,” Jepson said via email. “Modern security practice recognises that access should be determined strictly by operational need rather than hierarchy. Senior figures are frequently primary targets for threat actors, which makes excessive privilege particularly dangerous,” he added. Related: Cyberattack Disrupts France’s Postal Service and Banking During Christmas Rush Related: Data Stolen in Eurofiber France Hack Related: Feds Seize Password Database Used in Massive Bank Account Takeover Scheme WRITTEN BY Eduard Kovacs Eduard Kovacs (@EduardKovacs) is the managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. More from Eduard Kovacs CISA: Hackers Exploiting Vulnerability in Product of Taiwan Security Firm TeamT5 Palo Alto Networks to Acquire Koi in Reported $400 Million Transaction Dell RecoverPoint Zero-Day Exploited by Chinese Cyberespionage Group Hackers Offer to Sell Millions of Eurail User Records Man Linked to Phobos Ransomware Arrested in Poland 3 Threat Groups Started Targeting ICS/OT in 2025: Dragos Password Managers Vulnerable to Vault Compromise Under Malicious Server Dior, Louis Vuitton, Tiffany Fined $25 Million in South Korea After Data Breaches Latest News Nearly 1 Million User Records Compromised in Figure Data Breach Venice Security Emerges From Stealth With $33M Funding for Privileged Access Management Ivanti Exploitation Surges as Zero-Day Attacks Traced Back to July 2025 OpenClaw Security Issues Continue as SecureClaw Open Source Tool Debuts German Rail Giant Deutsche Bahn Hit by Large-Scale DDoS Attack New Keenadu Android Malware Found on Thousands of Devices Cogent Security Raises $42 Million for AI-Driven Vulnerability Management Vulnerabilities in Popular PDF Platforms Allowed Account Takeover, Data Exfiltration TRENDING Password Managers Vulnerable to Vault Compromise Under Malicious Server Vulnerabilities in Popular PDF Platforms Allowed Account Takeover, Data Exfiltration Dell RecoverPoint Zero-Day Exploited by Chinese Cyberespionage Group Apple Patches iOS Zero-Day Exploited in ‘Extremely Sophisticated Attack’ New Keenadu Android Malware Found on Thousands of Devices Dior, Louis Vuitton, Tiffany Fined $25 Million in South Korea After Data Breaches Google Patches First Actively Exploited Chrome Zero-Day of 2026 CISA Navigates DHS Shutdown With Reduced Staff Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Identity Under Attack: Why Every Business Must Respond Now February 11, 2026 Attendees will walk away with guidance for how to build robust identity defenses, unify them under a consistent security model, and ensure business operations move quickly without compromise. Register Virtual Event: Ransomware Resilience & Recovery 2026 Summit February 25, 2026 SecurityWeek’s 2026 Ransomware Summit will discuss a roadmap for defending the enterprise, from mitigating root causes to mastering recovery, giving security teams the critical insights needed to navigate and neutralize today’s ransomware extortion threats. Submit PEOPLE ON THE MOVE Cyera has appointed Brandon Sweeney as President, Shira Azran as Chief Legal Officer and Joseph Iantosca as Chief Financial Officer. Robert Carvajal has been appointed as CISO of BayCare Health System. KnowBe4 announced the appointment of Kelly Morgan as Chief Customer Officer. More People On The Move EXPERT INSIGHTS How to Eliminate the Technical Debt of Insecure AI-Assisted Software Development Developers must view AI as a collaborator to be closely monitored, rather than an autonomous entity to be unleashed. Without such a mindset, crippling tech debt is inevitable. (Matias Madou) Security in the Dark: Recognizing the Signs of Hidden Information Security failures don’t always start with attackers, sometimes they start with missing truth. (Joshua Goldfarb) Living off the AI: The Next Evolution of Attacker Tradecraft Living off the AI isn’t a hypothetical but a natural continuation of the tradecraft we’ve all been defending against, now mapped onto assistants, agents, and MCP. (Etay Maor) Why We Can’t Let AI Take the Wheel of Cyber Defense The fastest way to squander the promise of AI is to mistake automation for assurance, and novelty for resilience. (Steve Durbin) The Upside Down is Real: What Stranger Things Teaches Us About Modern Cybersecurity To all those who are fighting the good fight in the world of cyber, keep collaborating to ensure our world never succumbs to the chaos of the Upside Down. (Nadir Izrael) Flipboard Reddit Whatsapp Email

Share this article