French Government Agency ANTS Confirms Data Breach Affecting Up to 19 Million Records
France’s ANTS reports a security incident affecting up to 19 million records, including names, emails and birth dates. See details and mitigations.
TL;DR
On April 15, 2026, France’s National Agency for Secure Documents (ANTS) detected a security incident that may have exposed up to 19 million citizen records, including names, emails, birth dates and partial contact details. The threat actor “breach3d” claimed the theft and offered the data for sale.
Context ANTS, operating under the French Ministry of the Interior, manages driver’s licenses, national IDs, passports and immigration documents via the ants.gouv.fr portal. The agency disclosed the incident yesterday, noting that the breach does not grant direct portal access but could enable phishing and social‑engineering attacks. ANTS has notified CNIL, the Paris Public Prosecutor and ANSSI, and is contacting affected individuals.
Key Facts The exposed data set includes login ID, full name, email address, date of birth, unique account identifier and, for some records, postal address, place of birth and phone number. On April 16, the actor using the moniker “breach3d” posted on hacker forums claiming possession of up to 19 million records and offering them for an undisclosed price. ANTS confirmed the detection date but has not validated the actor’s claim; the investigation remains ongoing.
What It Means Although the stolen information does not allow immediate login to ANTS services, attackers can combine it with publicly available data to craft convincing phishing emails or SMS messages that appear to come from the agency. Organizations should treat any unexpected communication requesting credentials or personal data as suspicious.
Mitigations - Enable multi‑factor authentication on all accounts linked to ANTS portals. - Monitor authentication logs for anomalous login attempts from unfamiliar IPs or geolocations (MITRE ATT&CK T1078). - Deploy email gateway rules that flag messages spoofing the ants.gouv.fr domain (DMARC, SPF, DKIM). - Educate users to verify unexpected requests via official channels before responding. - Apply the latest ANSSI security advisory for government portals and patch any known vulnerabilities in web‑application frameworks.
Watch for further statements from ANSSI or CNIL regarding the scope of the breach, any confirmed malware indicators, and whether the claimed 19‑million dataset appears on underground markets.
Continue reading
More in this thread
BreachLock Gains Gartner AEV Recognition with 40,000+ Engagements
Peter Olaleru
French Police Arrest 20‑Year‑Old Hacker HexDex Tied to 100 Breaches and 243,000 Teacher Records Leak
Peter Olaleru
Crypto Scammers Exploit Hormuz Standoff, Demand Bitcoin from Stranded Ships
Peter Olaleru
Conversation
Reader notes
Loading comments...