Skip to main content Skip to search Skip to main navigation
Menu
Important Cybersecurity Score: 8/10

French ID Card Authority Hacked - 11.7 Million Records Compromised

Unknown attackers stole millions of user records from the French authority ANTS. The data set is already being offered on the black market.

What happened? - Key facts about the cyberattack

The French agency for secure identity documents (ANTS) has fallen victim to a serious cyberattack. Unknown attackers gained access to the state institution's database and stole the personal data of 11.7 million online accounts. The authority detected the incident on 15 April and informed the public six days later.

Particularly explosive: French media reports suggest that the stolen data set is already being offered for sale on the black market. The listing even promises 19 million records, well above the officially confirmed figure. The reason for this discrepancy has not yet been clarified.

The details - Scope and type of the stolen data

According to official information from ANTS, the compromised records contain the following information:

  • Username
  • Form of address, first and last name
  • Email address
  • Date of birth
  • Account number

For some of the affected accounts, the following data was also stolen:

  • Postal address
  • Place of birth
  • Telephone number

ANTS emphasises that, according to the current state of the investigation, no biometric data or attached documents were affected by the attack. The attackers were evidently unable to obtain this sensitive information, which is normally required for identity document applications.

About the affected authority

ANTS, also known as France Titres, is a department of the French Ministry of the Interior. It is responsible for issuing various important documents, including:

  • Passports and identity cards
  • Driving licences for road vehicles and motorboats
  • Vehicle registration documents
  • Residence permits and visas
  • Further documents for residence and border crossings

The actual production of the documents is handled by the French state printing works (Imprimerie nationale).

Assessment - Why this incident is particularly critical

This cyberattack is especially worrying for several reasons. ANTS manages highly sensitive identity data belonging to millions of French citizens and, as a government authority, is a strategic target for cybercriminals. The stolen data can be misused for various criminal activities, from identity theft through to targeted phishing attacks.

The fact that the data set is already being offered on the black market shows the commercial motivation behind the attack. The differing figures between the officially confirmed 11.7 million and the advertised 19 million records allow for various interpretations: either the seller is exaggerating, or accounts with several requested documents are being counted more than once.

Response and measures taken by the authorities

The French authorities have informed all affected users about the incident by email. The official recommendation is limited to users changing their ANTS password the next time they log in. No further specific precautions have been issued by the Ministry of the Interior.

Exactly how the attackers were able to penetrate the database is still the subject of the ongoing investigation. ANTS has so far not disclosed any details about the attack method, which is quite usual while a forensic analysis is still under way.

Outlook - Consequences for security in public authorities

This incident is likely to trigger a more intensive discussion about cybersecurity in French public authorities. Government institutions that manage sensitive citizen data are increasingly in the sights of cybercriminals, making a review and reinforcement of security measures necessary.

For the citizens affected, the data theft represents a potential threat to their privacy and security. Over the coming months they should be particularly alert to suspicious emails or calls that could use their stolen data for fraud attempts.

The case also demonstrates the importance of robust security concepts in every area where sensitive data is processed. This applies not only to government institutions, but also to private companies and organisations that manage similarly valuable information.