惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
人人都是产品经理
人人都是产品经理
爱范儿
爱范儿
aimingoo的专栏
aimingoo的专栏
博客园 - 叶小钗
H
Help Net Security
Microsoft Security Blog
Microsoft Security Blog
The Cloudflare Blog
S
SegmentFault 最新的问题
小众软件
小众软件
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 司徒正美
The GitHub Blog
The GitHub Blog
量子位
H
Hackread – Cybersecurity News, Data Breaches, AI and More
V
V2EX
Martin Fowler
Martin Fowler
博客园 - 【当耐特】
J
Java Code Geeks
D
DataBreaches.Net
云风的 BLOG
云风的 BLOG
F
Fortinet All Blogs
Blog — PlanetScale
Blog — PlanetScale
Last Week in AI
Last Week in AI

The Register - Security: Cyber-crime

Election interlopers register 5K+ domains, hope to catch some voting phish Palo Alto VPN bug graduates from advisory to active exploitation ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak Carnival confirms ShinyHunters cruised off with 6M customer records after April breach CrowdStrike, Google shatter Glassworm botnet MyPillow must decide whether to be firm or soft as ransomware crims demand pay A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Shai-Hulud copycat worm infects yet another npm package Grafana Labs admits all its codebase are belong to someone who popped its GitHub account Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files Cache-poisoning caper turns TanStack npm packages toxic 'CopyFail' attackers start cashing in on Linux flaw Cushman & Wakefield confirms vishing cyberattack ShinyHunters claims dump puts 119K Vimeo emails in the wild ShinyHunters claims 119K Vimeo emails in the wild Critical cPanel exploited: 'Millions' of sites could be hit Pro-Iran group turns Ubuntu DDoS into shakedown French prosecutors link 15-year-old to gov mega-breach UK business breach rate stuck at 43%... blame the phishing What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia Chinese spy group caught lurking in Poland, Asia networks Don’t pay VECT a ransom - your big files are likely gone Pitney Bowes the latest victim of ShinyHunters’ breach-spree Ongoing supply-chain attack targets security, dev tools Medical and utility tech companies admit digital breakins Burglar alarm biz gets burgled, ShinyHunters pursues ransom Crime crew impersonates help desk, abuses Teams chats ShinyHunters claim they have cruise giant Carnival’s booty
France's 'Secure' ID agency probes breach as crooks claim...
Carly Page · 2026-04-22 · via The Register - Security: Cyber-crime

France's National Agency for "Secure" Documents is explaining a potential data spill just as crooks online claim they've nicked a third of the country's ID information.

The French Interior Ministry this week confirmed a security incident affecting the ants.gouv.fr portal, run by the National Agency for Secure Titles – now rebranded as France Titers – which handles everything from passports and ID cards to driver's licenses and vehicle registrations. 

Officials say the data theft, detected on April 15, may have exposed personal data tied to user accounts, including login IDs, full names, email addresses, dates of birth, unique account identifiers, postal addresses, and telephone numbers.

"The disclosure of data does not include additional data submitted during the various procedures, such as attachments," the notice stressed. "This personal data does not allow unauthorized access to the portal account."

A cyber baddie operating under the aliases "breach3d" and "ExtaseHunters" has since popped up on criminal forums claiming they broke into the agency's internal infrastructure and walked off with between 18 and 19 million records. If true, that's roughly a third of France's population.

The criminal is actively shopping the data and insists it's the real deal, describing it as a fresh, "structural" compromise rather than the usual stitched-together dump of old leaks. 

"These 18 to 19 million files contain an impressive amount of personally identifiable information," the listing reads. "It seems the French government would do better to stick to the culinary arts: their digital defenses are as crumbly as their croissants."

So far, the government hasn't confirmed those numbers, and there's no detail on how the attackers got in or how long they may have had access. 

"Technical investigations, which began as soon as the incident was detected, are ongoing," the Ministry said. "They are being conducted by ANTS teams and the relevant services. They aim to determine precisely the origin and extent of the incident."

The timing falls in the middle of a run of public-sector security hiccups for France. The Education Ministry recently disclosed an intrusion tied to impersonation of an authorized staff account, which gave attackers access to a service linked to the ÉduConnect platform used by students and families. Earlier this year, attackers also got into part of France's national bank account registry, exposing data tied to around 1.2 million accounts.

Whether this latest info spill lives up to the forum hype or not, it's not a great look for an outfit whose entire job is supposed to be keeping identity data under lock and key. ®