MIT TRACE

MIT CTL Logo
Back to Main Dashboard

DGFiP: Unauthorized access to FICOBA via stolen credentials exposed ~1.2M bank accounts

France’s Ministry of the Economy reported that from late January until 13 February 2026 an attacker using compromised credentials of an official with access to the FICOBA national bank accounts file consulted data including IBAN/RIB and account holder identity/address. Access was revoked, the CNIL notified, and a complaint filed. No operational disruption was stated.

32

Estimated severity

32 / 100

84

Source reliability

84 / 100

Approximate Date

13/02/2026

Targeted Company

DIRECTION GENERALE DES FINANCES PUBLIQUES

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

France

FRA

Other Affected Countries

No other affected countries reported

Target country

France

Affected countries

France

Impacted regions

France · France

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

No information

Affected sectors

Government & Public Administration

Affected departments

No information

Attack Profile

Attack types

Use of stolen credentialsUnauthorized accessData breach

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.