Latest / Tech Talks With Kinsoft / France's FICOBA Registry Breach – 1.2M Bank Accounts
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. Imagine holding
- 0:03the routing instructions for like 1 .2 million
- 0:07bank accounts. Yeah, that is a staggering amount
- 0:10of financial data. Right. And you can't see the
- 0:12balances and you can't just click a button to
- 0:15transfer the money out yourself. But you know
- 0:17exactly who owns every single account. You know
- 0:19where they live, their names, everything. Exactly.
- 0:21And even their government issued tax ID. In January
- 0:252026, someone spent 16 completely uninterrupted
- 0:29days inside France's National Bank Account Registry
- 0:32gathering exactly that information. Which is
- 0:35just wild to think about. It really is. So our
- 0:38mission here on the show is to take a stack of
- 0:40complex. collect sources, you know, security
- 0:42bulletins, official ministry reports, news articles,
- 0:44and just extract the most important nuggets of
- 0:47knowledge for you. Yeah, we give you a shortcut
- 0:48to being well -informed without the information
- 0:51overload. Getting straight to the context of
- 0:53why these events actually impact you. And today
- 0:55we are analyzing a massive exposure involving
- 0:58a system called FICOBA. Right, FICOBA. And to
- 1:01understand the gravity of this event, we really
- 1:04have to establish what FICOBA actually represents.
- 1:07Because it's not just a small regional database,
- 1:09right? Oh, not at all. This is not a localized
- 1:11database for a single bank. FICOBA is the centralized
- 1:15national registry in France. It tracks nearly
- 1:17300 million bank accounts. Wow. 300 million.
- 1:22Yeah. For around 80 million people. It is essentially
- 1:25the master index of financial existence within
- 1:28the country. If you have an account operating
- 1:30in France, your information is sitting in this
- 1:32registry. Which makes it a staggering target
- 1:34for anyone looking for data. So our goal today
- 1:37is to examine how the data of 1 .2 million of
- 1:40those bank accounts was walked out the door in
- 1:42late January 2026. Right. We're looking at why
- 1:45this wasn't. you know, a traditional breach and
- 1:47crucially, what an attacker can actually do with
- 1:50this very specific combination of stolen data.
- 1:52Okay, let's unpack this. Let's do it. So the
- 1:55initial entry. According to reporting from TV5
- 1:57Mond and disclosures from the French Ministry
- 2:00of the Economy and Finance, the attackers didn't
- 2:03break down any firewalls. Right. There's no sophisticated
- 2:06hacking involved. No, they didn't write some
- 2:08brilliant piece of malicious code to force their
- 2:10way into a mainframe. They just obtained the
- 2:13legitimate login credentials of a fully authorized
- 2:16civil servant. What's fascinating here is they
- 2:19walked right through the front gate wearing the
- 2:21uniform, basically. Yeah. By using a legitimate.
- 2:25Authorized credential the attackers were able
- 2:27to quietly access and query the registry for
- 2:31about 16 days 16 days over two weeks of uninterrupted
- 2:35access to a national database. Yeah before anyone
- 2:38realized hostile actor was pulling records I
- 2:41have to push back on how we frame these incidents
- 2:43though I mean we're calling this a massive cybersecurity
- 2:45vulnerability but isn't this fundamentally just
- 2:48human error have you mean well if a government
- 2:51employee gets tricked by a phishing email or
- 2:54hands over their password or I don't know writes
- 2:56it on a sticky note no IT system in the world
- 2:59can patch human gullibility that is a fair point
- 3:01yeah So why are we treating this like a sophisticated
- 3:04technical failure instead of just a basic human
- 3:07resources and training issue? This isn't an Ocean's
- 3:11Eleven vault heist with lasers and explosives.
- 3:14Right. This is someone swiping the night manager's
- 3:17key card and wandering the file room for over
- 3:19two weeks. It's a great analogy, but that assumes
- 3:22the only layer of defense a system should have
- 3:25is the initial password. Okay, go on. A modern,
- 3:28centralized infrastructure holding the sensitive
- 3:31financial data of 80 million people cannot rely
- 3:35solely on a single point of human failure. When
- 3:38the perimeter is secured by a login, the behavior
- 3:41of that identity becomes the new security perimeter.
- 3:43I see what you're saying. Right. So if an authorized
- 3:46civil servant suddenly starts downloading or
- 3:48querying 1 .2 million individual records, which...
- 3:51is almost certainly far beyond any normal daily
- 3:54administrative workflow. The system should trigger
- 3:56an immediate anomaly alert. So the failure isn't
- 3:59just that the password was stolen. The failure
- 4:01is the lack of internal alarms. The system saw
- 4:04that night watchman suddenly loading two tons
- 4:07of filing cabinets into a moving truck and just
- 4:10assumed it was part of his normal shift. That
- 4:13is the core issue with legacy identity and access
- 4:15management. Intrusion detection systems are traditionally
- 4:19built to keep unauthorized people out. Like a
- 4:22wall. Right, like a wall. But when the system
- 4:24looks at the login and verifies it as an authorized
- 4:27user from a recognized portal, it often just
- 4:30waves them right through and stops monitoring
- 4:32their behavior. The system has no way of knowing
- 4:35the human behind the keyboard has malicious intent
- 4:38unless it is actively monitoring for bizarre
- 4:41data access patterns. Yeah, and if I have 16
- 4:43days inside that system without setting off any
- 4:45alarms, I am trying to grab every piece of valuable
- 4:48data I can find. Oh, absolutely. The Ministry
- 4:51of the Economy made a point to highlight what
- 4:54was not taken. The attackers could not see the
- 4:57actual account balances. Right. That's an important
- 4:59distinction. And they could not initiate direct
- 5:01transfers or card payments from inside the system.
- 5:04Because FICOVA is an index, right? Yeah. It's
- 5:06not the bank vault itself. It knows where the
- 5:08accounts are, but it doesn't hold the funds.
- 5:10Okay. The French Banking Federation confirmed
- 5:13that the information stolen is simply not sufficient
- 5:16to allow fraudsters to log into a victim's bank
- 5:19portal and wire money. money away. So what exactly
- 5:23did they get? The specific data points accessed
- 5:25across those 1 .2 million accounts included the
- 5:29international bank account numbers, so the IBANs.
- 5:32Okay, the routing info. Right. Plus the account
- 5:34holders' first and last names, their physical
- 5:36addresses, and in some cases, their tax identification
- 5:39numbers issued by the Directorate General for
- 5:41Public Finance, or DGFIC. So what does this all
- 5:45mean? If I'm a victim and hearing that they can't
- 5:47see my balance or wire my money to an offshore
- 5:49account, I mean, that feels like a massive relief.
- 5:53It does sound like a silver lining. Yeah, it
- 5:55sounds like they broke into the registry but
- 5:56didn't actually get the prize. Why should you
- 5:58or I be worried about them just knowing my routing
- 6:00number and address? Well, the danger lies in
- 6:03how the broader financial ecosystem uses that
- 6:06specific combination of data to establish trust.
- 6:09Think of it this way. While the locked front
- 6:12door meaning your account balance and direct
- 6:14transfers, is secure, the attacker just grabbed
- 6:18the architectural blueprints to the house. Okay,
- 6:21that's not good. No, it's not. The attackers
- 6:24don't need to log into your bank account if they
- 6:26can trick the rest of the financial system into
- 6:28pulling the money out for them. Both the French
- 6:30Banking Federation and the tax authorities have
- 6:32issued stark warnings about how this data is
- 6:35weaponized. And how is it weaponized? Primarily
- 6:38through direct debit forgery. Wait, a direct
- 6:40debit is just what I use to pay my water bill
- 6:42or my gym membership. It's essentially auto pay.
- 6:45How do you forge that if you aren't the utility
- 6:47company? Right. So in the European banking system
- 6:50and many others globally, direct debits are built
- 6:52on a foundation of systemic trust. A legitimate
- 6:55creditor sets up a mandate to pull money from
- 6:58your account. Fraudsters exploit this by setting
- 7:01up a front company and registering with a payment
- 7:03service provider as an authorized debit issuer.
- 7:06Armed with your exact IBAN, your full name, and
- 7:10your physical address, they literally forge a
- 7:12debit mandate. Oh, wow. Yeah. They present this
- 7:16mandate to the banking network, which looks at
- 7:18the perfectly matching personal data and just
- 7:21assumes you have authorized this new company
- 7:23to withdraw funds for a service. Here is where
- 7:26it gets really interesting. They are weaponizing
- 7:28the convenience of auto pay. It's like giving
- 7:31a criminal a stack of your blank checks. That's
- 7:33exactly what it is. They might not know how much
- 7:35is in the account and they can't log in to check,
- 7:37but they can keep writing them to pay for their
- 7:40own Netflix or electricity until the bank finally.
- 7:43notices the signature is faked. Yes. And subscription
- 7:46fraud is another major vector here. Fraudsters
- 7:49use the stolen I -bands and matching identities
- 7:52to sign up for various high -end subscriptions,
- 7:55software licenses, or cloud hosting services.
- 7:58Stuff they can resell or use themselves. Yeah,
- 8:00right. They receive the real usable services.
- 8:04And the billing is silently routed to the victim's
- 8:06account through those forged mandates. It relies
- 8:09entirely on the victim not noticing small recurring
- 8:12leaks in their monthly statements. Until the
- 8:15victim catches a weird $50 charge from a company
- 8:18they've never heard of. But there is a second
- 8:21layer to this threat, isn't there? Because the
- 8:23physical addresses and the tax identification
- 8:25numbers aren't strictly necessary to forge a
- 8:28digital subscription. No, they aren't. So what
- 8:30is the attacker doing with that specific, highly
- 8:34sensitive information? They use it for social
- 8:36engineering. Honestly, the psychological threat
- 8:38here is arguably more dangerous than the automated
- 8:41fraud. Oh, so? Armed with your exact address,
- 8:44your name, your tax ID, and your IBAN, an attacker
- 8:48can execute a highly targeted phone scam. They
- 8:51call you. spoofing the caller ID to make it look
- 8:53like your specific bank. I can see exactly how
- 8:56this plays out. They start the call by verifying
- 8:57my home address and referencing my tax ID. Instantly,
- 9:00my defenses are gone because who else would know
- 9:03my internal government tax identifier and my
- 9:06banking route except the bank's fraud department.
- 9:09They build immense credibility in the first 10
- 9:12seconds of the call using the stolen registry
- 9:14data. Then they pivot to creating a sense of
- 9:18panic. They tell you that your account is currently
- 9:20under attack, ironically, and that to secure
- 9:23your funds, they need you to read back a security
- 9:25code they just texted to your phone. But the
- 9:28text isn't a cancellation code. No. The attacker
- 9:31is sitting at their computer trying to log into
- 9:33my actual bank account using my email, and they
- 9:36just triggered a two -factor authentication code.
- 9:38They are using the panic and the trust they built
- 9:41with the FICO beta to make me hand over the final
- 9:44key. You are handing them the keys to the vault
- 9:46while believing you are locking the door. Yeah.
- 9:48It is incredibly manipulative. So how do you
- 9:51even defend against that? Well, the French Banking
- 9:53Federation has laid out very specific, actionable
- 9:55advice for listeners caught up in this exposure.
- 9:59First, you have to check your accounts and monitor
- 10:01listed transactions weekly. Yet do not wait for
- 10:04the monthly statement to arrive in the mail.
- 10:07you need to watch direct debit transactions closely
- 10:09because European banking rules give you an eight
- 10:12-week window to dispute a fraudulent direct debit
- 10:15and have the funds reversed without question.
- 10:18Eight weeks is a generous window, but if you
- 10:20have auto pay set up for a dozen different services
- 10:23and you aren't checking line by line, two months
- 10:26can fly by. Absolutely. And if you miss that
- 10:28window, that money is just gone and you might
- 10:30be funding someone's server farm indefinitely.
- 10:33Right. And the second critical piece of advice
- 10:35is hypervigilance against inbound communication.
- 10:38Banks generally do not call you and ask for your
- 10:41passwords, your usernames, or your two -factor
- 10:44safety codes. Yeah, they just don't do that.
- 10:46If someone calls claiming to be your bank, no
- 10:49matter how much accurate personal information
- 10:51they recite to you, hang up the phone. Look up
- 10:53the official number on the back of your bank
- 10:55card and call the institution back yourself.
- 10:57That is a sobering reminder of how vulnerable
- 11:00individuals become when seemingly harmless data
- 11:03points like a routing number and an address are
- 11:05combined and weaponized. But I want to zoom out
- 11:09for a second. OK. Because this level of data
- 11:11exposure makes individuals highly vulnerable.
- 11:14But zooming out, this breach is actually part
- 11:17of a much larger, more troubling trend for the
- 11:20French government. It really is. If we connect
- 11:23this to the bigger picture, the pattern is hard
- 11:25to ignore. We are seeing a rapid fire string
- 11:28of cyber incidents hitting French institutions.
- 11:30Let's go through the timeline. Just two months
- 11:33prior to the FITCOBA exposure, a massive distributed
- 11:36denial of service, or DDoS attack, disrupted
- 11:39the websites and mobile apps of the French postal
- 11:42service, La Poste, and its banking subsidiary,
- 11:45La Banque Postale. Okay, so that was just two
- 11:47months prior. Right. And around that same time,
- 11:49there was a cyber attack that compromised the
- 11:51email servers at the French Ministry of the Interior.
- 11:54And if we look back to March 2024, there was
- 11:56an enormous breach involving France Travail,
- 11:58the National Unemployment Agency and CAP employees.
- 12:01Yes, exposing 20 years worth of job seeker data.
- 12:04We are talking about decades of citizen data,
- 12:07email servers at the Ministry of the Interior,
- 12:10the Postal Service and now the National Bank
- 12:12Account Registry. Are we seeing a coordinated
- 12:16siege on French infrastructure or is this just
- 12:19the new normal for any government that centralizes
- 12:21decades of citizen data? While taking an impartial
- 12:24look at this trend, it is vital to see how centralized
- 12:27databases like The COBA, which tracks 300 million
- 12:30accounts, act as massive honeypots. Honeypots,
- 12:34meaning they attract every threat actor out there.
- 12:36Exactly. When governments consolidate data to
- 12:38make civil services efficient, you know, to make
- 12:41tax collections seamless or to streamline welfare
- 12:43distribution, they inadvertently create highly
- 12:46lucrative targets. So it's not necessarily a
- 12:48coordinated political siege, but just criminals
- 12:50going where the money is. Right. Decentralized
- 12:53data is a nightmare for a civil servant to manage.
- 12:56But a breach only affects a small, localized
- 12:58segment. Centralized data is wonderfully efficient.
- 13:01But a single compromised employee password exposes
- 13:04millions of identities across the entire nation
- 13:07in a matter of days. It is the ultimate double
- 13:10-edged sword. You centralize the architecture
- 13:12to make the machinery of government work smoothly
- 13:15for the citizen. But in doing so, you put all
- 13:18the eggs in one incredibly fragile basket. And
- 13:21threat actors don't need to coordinate a grand
- 13:23siege. They are simply drawn to the largest repositories
- 13:26of data on the board. Right now, centralized
- 13:28civil service registries are the biggest prize.
- 13:31And the FICOBI incident perfectly illustrates
- 13:34that the data itself is the weapon. You don't
- 13:37need to crack the encryption on a bank's vault
- 13:39to steal money if you have enough administrative
- 13:41data to trick the broader system into handing
- 13:44the funds to you. So to briefly recap our journey
- 13:46today, a civil servant's compromised credentials
- 13:49allowed 16 days of unseen access to a massive
- 13:52national registry. It proves that you don't need
- 13:54to, quote unquote, hack a bank to weaponize 1
- 13:57.2 million IBANs and identities. And this raises
- 14:00an important question for you to mull over. As
- 14:03we move toward increasingly digital and centralized
- 14:05lives, is the convenience of having all our financial
- 14:08and civic data in one secure government registry
- 14:11actually worth the risk of a single compromised?
- 14:14password exposing millions. Have we built a digital
- 14:18society where the blast radius of human error
- 14:20is just too large? That is a lingering thought
- 14:23right there. And it brings us to how you navigate
- 14:26this exposed digital world. Protecting against
- 14:29these kinds of credential -based vulnerabilities
- 14:31requires a proactive strategy. You can't just
- 14:34rely on the firewall anymore. Exactly. You need
- 14:36to monitor the behavior inside your networks.
- 14:39If you want to ensure your organization is prepared
- 14:41for these modern threats, you need to visit www
- 14:44.kinsoft .com .au to discuss your security and
- 14:48IT needs. They can help you build systems that
- 14:51actively look for anomalies and protect your
- 14:53data. The landscape has definitely shifted and
- 14:56our defenses have to shift with it. Absolutely.
- 14:58Well, that wraps up our discussion. Thank you
- 15:00for joining us on Tech Talks with Kinsoft. Remember
- 15:02to stay curious and stay secure. We'll catch
- 15:04you next time. Thanks for listening.