Skip to content

Anatomy of an attack

CASE FILE 2026-ANTS

ANTS / France Titres: 11.7 Million Accounts Exposed - The Full Autopsy

For two years, the French State warned about fake vehicle-registration sites and emails impersonating the ANTS. In April 2026, the ants.gouv.fr portal itself leaked: 11.7 million accounts exposed — and fresh fuel for the very same scams.

Thomas Ferreira 19 min read
CASE FILE 2026-ANTS ANTS / France Titres: 11.7 Million Accounts Exposed - The Full Autopsy

On 21 April 2026, the French Interior Ministry put a number on the ants.gouv.fr “security incident”: “11.7 million accounts are believed to be affected” (our translation). Nine days later, the Paris prosecutor’s office revealed the other side of the case: “between 12 and 18 million lines of data” offered for sale on cybercrime forums by a hacker going by “breach3d” — and the police custody of a 15-year-old teenager, presumed innocent, suspected of having contributed to the leak.

The second installment of our “Attack autopsies” series after the France Travail case file, this investigation reconstructs the affair from primary sources only: the Interior Ministry’s statements, the Paris prosecutor’s statement, and the official alerts of the ANTS, ANTAI and the DGCCRF. And it tells a two-act story the individual statements do not: before it was the victim of a breach, the ANTS was already the favorite bait of an entire phishing ecosystem. The April 2026 leak did not create that risk — it supercharges it.

Key takeaways

  • The scale: “11.7 million accounts are believed to be affected” by the disclosure of data from the ants.gouv.fr portal (Interior Ministry, update of 21 April 2026); the Paris prosecutor refers to “between 12 and 18 million lines of data” offered for sale on cybercrime forums (statement of 30 April 2026). Lines are not accounts: the two figures coexist, each with its source.
  • The data: identification data — login identifier, title, last name, first names, email address, date of birth, unique account identifier, plus, where present, postal address, place of birth, phone number. Attachments and biometric data are excluded at this stage of the investigations, and this data “does not allow illegitimate access to the named account on the portal” (Interior Ministry, 20-21 April 2026, our translation).
  • The timeline: unusual network activity confirmed on 13 April 2026 (prosecutor), incident detected on Wednesday 15 April (ministry), prosecutor informed on 16 April, public announcement on 20 April, police custody on 25 April, judicial investigation on 29 April.
  • The vector: not officially disclosed. Neither the ministry nor the prosecutor describes the modus operandi; the investigations aim to “determine precisely the origin of the incident and its scope”.
  • The suspect: a 15-year-old minor, placed in police custody on 25 April 2026, suspected of hiding behind the pseudonym “breach3d”. His indictment and placement under judicial supervision were requested by the prosecution on 29 April — the statement does not say they were pronounced. He is presumed innocent.
  • The lesson: the leak directly feeds the ecosystem of fake vehicle-registration sites, fake fines and fake “ANTS” emails that ANTAI, the ANTS and the DGCCRF had been documenting since 2024-2025. The State itself urges users to exercise “the greatest vigilance” toward messages “appearing to come from the ANTS”: the loop is closed.

The case in numbers

11.7M

accounts affected

French Interior Ministry, 21 April 2026

12-18M

lines of data offered for sale

Paris prosecutor, 30 April 2026

5 days

between detection (15 April) and public announcement (20 April)

French Interior Ministry, 20 April 2026

10 days

from detection to an arrest in custody

Paris prosecutor, 30 April 2026

Timeline

Timeline

How events unfolded

  1. 18 October 2024

    ANTAI warns about fake fines

    "For several months, fraudulent text messages, emails or letters have been offering to settle or contest unpaid fines on fake administrative sites, unlawfully collecting your personal data or bank details" (our translation). The fake sites harvest "tax number, driving licence number, identity card or passport, vehicle sale or destruction certificate…".

    Source — ANTAI, news item of 18/10/2024

  2. 7 and 12 January 2025

    Automobile professionals phished

    Fraudulent emails titled "Contrôle de conformité - Statut de votre AGRÉMENT SIV" and "Contrôle de Conformité - Vérification de VOTRE CLÉ SIV" are sent out, with a sender address spoofing dgfip.finances.gouv.fr, to steal access credentials for the vehicle registration system (SIV).

    Source — ANTS / France Titres, alert of 14/01/2025

  3. 14 January 2025

    The ANTS publishes its official alert

    "A phishing operation aimed at unduly harvesting the SIV access data of authorized automobile professionals is under way" (our translation). The agency reminds professionals that "no State service will ask authorized automobile professionals for information about their SIV authorizations or approval, digital certificates or secret codes" (our translation).

    Source — ANTS / France Titres, 14/01/2025

  4. 10 February 2025

    The DGCCRF documents fake government sites

    Bercy Infos publishes the consumer-protection authority's guide to "mirror sites" impersonating public administrations. Vehicle registration and driving licences are explicitly listed among the targeted procedures: "some sites charge for vehicle registration even though the procedure can be carried out on the official website of the Agence nationale des titres sécurisés (ANTS)" (our translation).

    Source — DGCCRF / Bercy Infos Particuliers, 10/02/2025

  5. April 2026

    12 to 18 million lines for sale

    "OFAC (the anti-cybercrime office) had been informed in April of a cyberattack against the agency" (our translation). Between 12 and 18 million lines of data were offered for sale on cybercrime forums by a hacker going by "breach3d", the prosecutor writes.

    Source — Paris prosecutor, statement of 30/04/2026

  6. 13 April 2026

    Unusual network activity

    "The ANTS confirmed unusual activity on its network on 13 April 2026, and the authenticity of the resold data" (our translation).

    Source — Paris prosecutor, statement of 30/04/2026

  7. 15 April 2026

    Incident detected

    "On Wednesday 15 April 2026, the national agency for secure documents (ANTS) detected a security incident potentially involving a disclosure of data from individual and professional accounts on the ants.gouv.fr portal" (our translation).

    Source — French Interior Ministry, statement of 20/04/2026

  8. 16 April 2026

    The Paris prosecutor opens an investigation

    The cybercrime section of the Paris prosecutor's office, once informed, immediately opens an investigation for fraudulent access to and presence in a State-operated automated personal data processing system and fraudulent data extraction — "offences carrying a penalty of 7 years' imprisonment and a 300,000 euro fine" (our translation).

    Source — Paris prosecutor, statement of 30/04/2026

  9. Week of 13 April 2026

    First emails to users

    "Direct communication to users began last week", states the 21 April update: by 21 April, all holders of an affected professional account had been informed by email; notification of individual users was still in progress.

    Source — French Interior Ministry, update of 21/04/2026

  10. 20 April 2026

    The public announcement

    The Interior Ministry publishes its press statement: incident notified to the CNIL under Article 33 of the GDPR, report transmitted to the Paris public prosecutor under Article 40 of the code of criminal procedure, ANSSI alerted.

    Source — French Interior Ministry, statement of 20/04/2026

  11. 21 April 2026

    11.7 million accounts

    Progress update: "11.7 million accounts are believed to be affected" (our translation). The judicial investigation has "since been entrusted to the Office Anti-Cybercriminalité"; the Interior Minister "is referring the matter in parallel to the Inspection générale de l'administration to establish the chain of responsibility in this serious incident" (our translation). Users are asked to change their password at next login.

    Source — French Interior Ministry, update of 21/04/2026

  12. 22 April 2026

    info.gouv.fr recaps — with a typo

    The government portal publishes its page "France Titres : le point sur l'incident de sécurité" (updated 24 April). It mistakenly dates the detection to "15 March" — the Interior Ministry's statements of 20 and 21 April both date it to Wednesday 15 April 2026.

    Source — info.gouv.fr, 22/04/2026; Interior Ministry, 20-21/04/2026

  13. 25 April 2026

    A 15-year-old teenager in police custody

    "On 25 April, a 15-year-old minor was placed in police custody, suspected of having contributed to the data leak against the ANTS" (our translation). The investigations led investigators to suspect him of hiding behind the pseudonym "breach3d". He is presumed innocent.

    Source — Paris prosecutor, statement of 30/04/2026

  14. 29 April 2026

    Judicial investigation opened

    "A judicial investigation was opened on 29 April 2026 by the Paris prosecutor's office. The indictment and judicial supervision of the minor were requested" (our translation) — requested by the prosecution, not stated as pronounced. "The investigations now continue under the direction of the investigating judge" (our translation).

    Source — Paris prosecutor, statement of 30/04/2026

  15. 30 April 2026

    The prosecutor's office communicates

    Press statement by the Paris public prosecutor, Laure Beccuau, recapping the investigation, the custody and the opening of the judicial investigation.

    Source — Paris prosecutor, 30/04/2026

  16. 9 July 2026

    Cybermalveillance.gouv.fr recalls the traps

    The national assistance scheme publishes "Doing your administrative procedures online while avoiding the traps": payment scams, account hijacking and phishing — "no administration will contact you to ask for your personal and banking information, copies of identity documents or your passwords" (our translation).

    Source — Cybermalveillance.gouv.fr, 09/07/2026

Act One: The ANTS, the Scammers’ Favorite Bait (2024-2025)

To understand what the April 2026 leak really changes, you first need to measure what existed before it. The Agence nationale des titres sécurisés — rebranded France Titres — runs the online procedures for vehicle registration (the French carte grise), driving licences and identity documents. Mandatory, stressful, often paid-for procedures: the ideal hunting ground.

Fake Fines and Fake Sites (ANTAI, October 2024)

On 18 October 2024, ANTAI — the agency that manages traffic fines — published an alert with an unambiguous title, “Beware of fraudulent texts, emails and websites!”: “For several months, fraudulent text messages, emails or letters have been offering to settle or contest unpaid fines on fake administrative sites, unlawfully collecting your personal data or bank details” (our translation). The agency even flagged fake paper letters — penalty notices and reminder letters — pointing to fraudulent sites built to harvest “tax number, driving licence number, identity card or passport, vehicle sale or destruction certificate…” (our translation). And it recalled a simple rule: ANTAI never sends text messages.

Automobile Professionals Targeted (ANTS, January 2025)

On 14 January 2025, it was the ANTS itself that raised the alarm: “A phishing operation aimed at unduly harvesting the SIV access data of authorized automobile professionals is under way” (our translation). The emails, sent on 7 and 12 January 2025, carried highly credible administrative subject lines — “Contrôle de conformité - Statut de votre AGRÉMENT SIV”, “Contrôle de Conformité - Vérification de VOTRE CLÉ SIV” — spoofed a sender address at dgfip.finances.gouv.fr (the French tax administration), and were fraudulently signed “ANTS - Expertise et Services, Service Vérification”.

The target deserves attention: not individuals, but the professionals authorized on the SIV, the vehicle registration system. In other words, the garages, dealerships and service providers holding privileged access to the system. The parallel with the France Travail case, where the attack came through a partner’s accounts, is striking: in both cases, the attackers go after the authorized link in the chain, not the fortress. The ANTS said it plainly at the time: “no State service will ask authorized automobile professionals for information about their SIV authorizations or approval, digital certificates or secret codes” (our translation).

The “Mirror Sites” (DGCCRF, February 2025)

On 10 February 2025, Bercy Infos published the DGCCRF’s overview of fake government websites: “web pages that imitate the official sites of public administrations, to make you believe you are accessing a public service and thereby steal your money or your personal information” (our translation). Among the targeted procedures, the guide explicitly cited vehicle registration — “some sites charge for vehicle registration even though the procedure can be carried out on the official website of the Agence nationale des titres sécurisés (ANTS)” (our translation) — and the driving licence, with its “excessive fees” for checking points or requesting a duplicate.

The DGCCRF also described the institutional impersonation playbook: fake “official” emails, dressed up with “a Marianne header or logo and the French flag”, purportedly sent by the social security administration, the DGFIP, the CAF or the national police.

By late 2025, the stage is set: around France’s secure documents revolves a well-oiled ecosystem of fake sites, fake fines and fake emails, officially documented by three administrations. It lacks only one thing to change scale: fresh, reliable data on the people who actually hold an ANTS account.

Act Two: The Breach (April 2026)

What the Official Statements Say

On 20 April 2026, the Interior Ministry published its statement: “On Wednesday 15 April 2026, the national agency for secure documents (ANTS) detected a security incident potentially involving a disclosure of data from individual and professional accounts on the ants.gouv.fr portal” (our translation).

The data scope, “subject to the ongoing investigations”, is precise: “login identifier, title, last name, first names, email address, date of birth, unique account identifier; and where applicable, other data not systematically present in the accounts: postal address, place of birth, phone number” (our translation). The statement also drew the boundary of what did not leak: “The disclosure of data does not concern the additional data transmitted in the course of carrying out the various procedures, such as attachments. This personal data does not allow illegitimate access to the portal account” (our translation).

The next day, 21 April, the progress update supplied the figure: “11.7 million accounts are believed to be affected” (our translation). And it added an important exclusion: “At this stage, the investigations conducted rule out the disclosure of additional data transmitted in the course of carrying out the various procedures, such as attachments and biometric data” (our translation).

What the Courts Say

The statement by the Paris public prosecutor, Laure Beccuau, dated 30 April 2026, sheds light on what preceded the detection: “OFAC (the anti-cybercrime office) had been informed in April of a cyberattack against the agency. Between 12 and 18 million lines of data were offered for sale on cybercrime forums, by a hacker going by ‘breach3d’. The ANTS confirmed unusual activity on its network on 13 April 2026, and the authenticity of the resold data” (our translation).

In other words: it is the sale of the data that crystallizes the case, and the agency confirms both unusual activity on its network — as early as 13 April according to the prosecutor, with the incident detected on the 15th according to the ministry — and the authenticity of what is circulating on the forums.

The judicial sequence is swift. “The cybercrime section of the Paris prosecutor’s office, informed on 16 April 2026, had immediately opened an investigation” for fraudulent access to and presence in a State-operated automated personal data processing system and fraudulent data extraction — “offences carrying a penalty of 7 years’ imprisonment and a 300,000 euro fine” (our translation). On 25 April, “a 15-year-old minor was placed in police custody, suspected of having contributed to the data leak” (our translation). The investigations led investigators “to suspect the minor of hiding behind the pseudonym ‘breach3d’” (our translation).

On 29 April, a judicial investigation was opened: “The indictment and placement under judicial supervision of the minor were requested” (our translation) for offences against a State-operated automated personal data processing system (access, presence, extraction, transmission, possession, obstruction) and possession of equipment or software enabling such offences. An essential precision: the statement says the indictment was requested by the prosecution, not that it was pronounced by the investigating judge. The suspect is a minor — no identifying details may be published — and he is presumed innocent. Ten days separate the incident’s detection from that police custody.

What Nobody Says: The Vector

On the modus operandi of the intrusion, the official sources are silent. The 20 April statement says only that the investigations “aim to determine precisely the origin of the incident and its scope” and that “security reinforcement measures to ensure the continuity of the portal’s services and the protection of data have been put in place” (our translation). As of this article’s publication date, no technical vector has been publicly confirmed — not by the ministry, not by the prosecutor, not by the CNIL. We therefore stick to the established facts, and the attack chain below is built on what is documented: the pre-existing ecosystem, the sale, the detection, the response.

The Attack Chain: What Is Documented

Attack chain

How the intrusion unfolded

Defensive reconstruction — every link you understand is a link you can break.

  1. A bait ecosystem already in place

    From 2024-2025, fake vehicle-registration and driving-licence sites, fake fines and fraudulent emails impersonating the ANTS or the DGFIP target individuals and professionals — documented by ANTAI (18/10/2024), the ANTS (14/01/2025) and the DGCCRF (10/02/2025).

  2. An intrusion with an undisclosed vector

    Official sources do not describe the modus operandi: the investigations "aim to determine precisely the origin of the incident and its scope" (Interior Ministry, 20/04/2026, our translation). No technical vector has been publicly confirmed.

  3. The sale on the forums

    Between 12 and 18 million lines of data are offered for sale on cybercrime forums by a hacker going by "breach3d"; OFAC is informed in April (Paris prosecutor, 30/04/2026).

  4. Confirmation and detection

    The ANTS confirms unusual activity on its network on 13 April and the authenticity of the resold data (prosecutor, 30/04/2026); the incident is detected on 15 April (ministry, 20/04/2026).

  5. The institutional response

    CNIL notification (Article 33 GDPR), Article 40 report to the Paris public prosecutor, ANSSI alerted, investigation entrusted to OFAC, Inspection générale de l'administration seized (ministry, 20 and 21/04/2026).

  6. The phishing feedback loop

    The leaked identification data lends credibility to precisely the act-one scams: the State itself urges "the greatest vigilance" toward messages "appearing to come from the ANTS" (ministry, 20/04/2026, our translation).

What makes this chain unusual is its first and last links. The ANTS case does not begin on 13 April 2026: it begins in a criminal ecosystem that had been making its living off France’s secure documents for months. And it does not end with the sale: every resold line of data is ammunition for the next campaigns. The ministry’s 20 April statement says as much, in its own way: “No action is expected from users. We nevertheless recommend that they exercise the greatest vigilance regarding any suspicious or unusual messages they may receive (text, call, email, etc.) appearing to come from the ANTS” (our translation). When the main official advice after a leak is “beware of messages that seem to come from us”, the leak has changed nature: it has become a phishing problem.

The Compromised Data

Let us restate the ministry’s list: login identifier, title, last name, first names, email address, date of birth, unique account identifier — and, for a subset of accounts, postal address, place of birth and phone number.

No usable password, no banking data mentioned, no attachments or biometrics: at first glance, a “benign” leak compared with France Travail’s 25 GB. That would be a dangerous reading, for two reasons.

First, context is gold. Knowing that a specific email address belongs to an ANTS account holder, along with their full civil status and phone number, lets an attacker craft the perfect fraudulent message: the “incomplete vehicle registration file” reminder, the “driving licence ready for dispatch”, the “non-compliant identity photo”. Every true data point woven into the message — your exact name, your date of birth — raises its credibility. That is the mechanism behind every effective fraudulent email: the true in service of the false.

Second, the act-one ecosystem is ready to consume this data. The fake vehicle-registration sites described by the DGCCRF, ANTAI’s fake fines, the fake “ANTS - Expertise et Services” emails: that entire fraud infrastructure existed before the leak. It had bait; it now has a qualified target file of 11.7 million people. That is the very definition of a feedback loop: phishing targeted the ANTS, and the ANTS leak now feeds the phishing.

Finally, on the figures, caution cuts both ways. The prosecutor’s “12 to 18 million lines” do not contradict the ministry’s “11.7 million accounts”: a line is not an account (duplicates, multiple records, split fields), and a listing on a criminal forum is also a sales pitch its author has every interest in inflating. The investigations into the exact “scope” were still ongoing as of the statements’ dates.

The State’s Response

Notification, Report, Referrals

On the regulatory and judicial front, the 20 April statement lays out the full machinery: “In accordance with Article 33 of the General Data Protection Regulation (GDPR), the incident was notified to the Commission nationale de l’informatique et des libertés (CNIL) and a report was transmitted to the Paris public prosecutor under Article 40 of the code of criminal procedure with a view to the opening of an investigation. The national cybersecurity agency (ANSSI) was alerted” (our translation).

The 21 April update adds two elements. The judicial investigation has “since been entrusted to the Office Anti-Cybercriminalité” — OFAC, the specialist police office. And the Interior Minister “is referring the matter in parallel to the Inspection générale de l’administration to establish the chain of responsibility in this serious incident, digital security being a major collective challenge” (our translation): beyond the criminal investigation into the attacker, an internal administrative inquiry into accountability.

Informing the Users

Direct notification of users began in the week of 13 April: by 21 April, “all users holding a professional account affected by the incident [had] been informed by email”, with notification of individual users “still in progress” (our translation). The ANTS’s voice server was modified to include the incident as a call reason, and call-handling capacity was increased. As for instructions: no mandatory action, “notwithstanding changing the account password at the next login, in a spirit of reinforced digital hygiene” (our translation), and vigilance toward messages appearing to come from the ANTS.

Compared with the France Travail case — detection on 29 February 2024, public announcement on 13 March — the ANTS sequence is fast: detection on Wednesday 15 April, national statement on Monday the 20th, a public figure on the 21st, and police custody by the 25th. Note also the promise of method: “In a spirit of transparency about the public action taken, progress updates will be issued whenever necessary” (our translation).

A Note on Dates

Two date traps await anyone documenting this case. First, the recap page on info.gouv.fr (published 22 April, updated 24 April) writes that France Titres detected the incident “on 15 March” — a manifest typo: the Interior Ministry’s two statements, the primary sources, date the detection to “Wednesday 15 April 2026” (15 March 2026 was, incidentally, a Sunday). Second, the prosecutor mentions “unusual activity” on the network confirmed by the ANTS “on 13 April”, two days before the ministry’s “detection” of the 15th: the two formulations are not contradictory — confirming a network signal is not yet qualifying a security incident — but they illustrate why every date must be cited with its source.

What an SME Should Take Away

A State-level leak, a teenage suspect, OFAC and an inspectorate general: all of this may seem far removed from a company of 20 or 200 people. The underlying mechanisms are not.

1. Your Breach Is Tomorrow’s Phishing — Aimed at Your Customers

The central lesson of the ANTS file: a leak of “mere” identification data arms phishing campaigns against the people in the file. If your customer database leaks, it is your customers who will receive fake emails under your letterhead, quoting their real orders. Build that scenario into your incident response plan: who informs customers, how fast, with what vigilance message? The ministry did it in five days, with a figure on the sixth — that is the standard you will be measured against, and it is also what Article 34 of the GDPR requires when the risk is high.

2. Watch What Is Being Sold — a Leak Often Shows Up Outside Before Inside

In this case, OFAC is informed of a sale on cybercrime forums, and the ANTS then confirms the unusual activity and the authenticity of the data. External monitoring (mentions of your domain, your employees’ credentials in dumps, listings citing your brand) is a detection sensor in its own right, complementary to your internal logs — which the France Travail case showed the cost of not watching.

3. Your Brand Is Bait: Treat Typosquatting as a Security Risk

The ANTS was being impersonated long before it was breached. Your customers, too, can receive invoices in your company’s name, and your suppliers “bank detail changes” signed by your accountant. Monitor domain registrations close to yours, and lock down email spoofing of your domain: SPF, DKIM and DMARC properly configured — the January 2025 ANTS alert, with a spoofed DGFIP sender address, shows why. When in doubt about a message you received, our email header analyzer shows what the technical channel really says.

4. Minimize What You Store: Nobody Can Steal What You Do Not Have

The ANTS leak is “limited” to identification data because attachments and biometrics were not affected — and that is what separates a serious incident from a catastrophe. Ask the question for every field in your CRM and every stored document: do we still need it? A scanned ID kept “just in case” is a liability, not an asset.

5. Train Your Teams on “Government Agency” Scenarios

A social-charges reminder, a fine to settle, the company vehicle’s registration file, a “compliance check”: administrative pretexts work because they are credible, urgent and impersonal — and act one of this case proves they are being industrialized at scale, including against professionals. The human factor is involved in 62% of data breaches (Verizon DBIR 2026 — see our phishing statistics for France). Phishing simulations built on these very scenarios remain the most direct way to measure, and then reduce, your team’s real-world exposure.

Verdict

The ANTS file will stand as a textbook case, for three reasons. Its subject, first: the portal that issues the French Republic’s secure documents — vehicle registrations, driving licences, identity papers — that is, the very infrastructure of administrative trust. Its judicial tempo, second: ten days between detection and a suspect in custody, a record among French mega-breaches — even if the judicial investigation, concerning a presumed-innocent minor whose indictment has only been requested, is just beginning.

Above all, its loop structure. The official history of this case, laid end to end, reads like this: scammers impersonate the ANTS for two years; the ANTS suffers a leak; the State advises the victims to beware of… messages that seem to come from the ANTS. Every leak of identification data strengthens the impersonation ecosystem that, often, preceded it. That is true for a State agency with 11.7 million accounts; it is true, at scale, for any company and its customer file.

Find this incident and over 100 others in our French cyberattack database.

FAQ

Am I affected by the ANTS breach? Potentially, if you hold an individual or professional account on ants.gouv.fr: “11.7 million accounts are believed to be affected” (Interior Ministry, 21 April 2026). Email notification of users is under way; no action is required apart from changing your password at the next login and heightened vigilance toward messages appearing to come from the ANTS.

What data leaked? Identification data: login identifier, title, last name, first names, email, date of birth, account identifier, and for some accounts postal address, place of birth, phone number. Attachments and biometrics excluded at this stage; no illegitimate account access possible according to the ministry.

How do I recognize a fake carte grise website? Check the URL (the official site is ants.gouv.fr; beware of .com, .net and lookalike variants), unexpected payments for free procedures, legal notices and site quality — and trust neither sponsored top search results nor the HTTPS padlock (DGCCRF, 10 February 2025).

What can criminals do with the stolen data? Ultra-targeted phishing, smishing and vishing: identification data makes fake “ANTS” messages credible, funneling victims to the fake sites documented since 2024-2025 to steal bank details and identity documents this time.

Who is the suspect? A 15-year-old teenager, placed in police custody on 25 April 2026, suspected of hiding behind the pseudonym “breach3d”. His indictment was requested by the prosecution on 29 April — not stated as pronounced. He is presumed innocent (Paris prosecutor, 30 April 2026).

11.7 million or 12 to 18 million? 11.7 million accounts affected (ministry, 21 April); 12 to 18 million lines offered for sale (prosecutor, 30 April). A line is not an account, and the investigations into the exact scope continue.


Sources:

  • French Interior Ministry, “Incident de sécurité relatif au portail ants.gouv.fr”, press statement, 20 April 2026: interieur.gouv.frarchived version of 21/04/2026 (accessed 05/09/2026)
  • French Interior Ministry, “Incident de sécurité relatif au portail ants.gouv.fr : point d’étape du 21 avril 2026”, 21 April 2026: interieur.gouv.frarchived version of 22/04/2026 (accessed 05/09/2026)
  • French Government, “France Titres : le point sur l’incident de sécurité”, info.gouv.fr, published 22 April 2026, updated 24 April 2026: info.gouv.fr (accessed 05/09/2026). Note: this page dates the detection to “15 March”; it is a typo — the Interior Ministry’s statements of 20 and 21 April 2026 date the detection to Wednesday 15 April 2026.
  • Paris judicial court prosecutor’s office, press statement by the public prosecutor, “interpellation fuite de données ANTS”, 30 April 2026: tribunal-de-paris.justice.fr (PDF) (accessed 05/09/2026)
  • ANTS / France Titres, “Envoi de courriels frauduleux à destination des professionnels habilités à l’automobile”, 14 January 2025: ants.gouv.fr (accessed 05/09/2026)
  • DGCCRF / Bercy Infos Particuliers, “Démarches administratives en ligne : comment repérer un faux site gouvernemental ?”, 10 February 2025: economie.gouv.fr (accessed 05/09/2026)
  • ANTAI, “Attention aux SMS, courriels et sites frauduleux !”, 18 October 2024: antai.gouv.fr (accessed 05/09/2026)
  • Cybermalveillance.gouv.fr, “Faire ses démarches administratives en ligne en évitant les pièges”, 9 July 2026: cybermalveillance.gouv.fr (accessed 05/09/2026)
  • Verizon, Data Breach Investigations Report 2026: verizon.com (accessed 05/09/2026)

Note: official statements are frequently taken offline as websites are redesigned; the archive.org links above guarantee access to the versions cited. As the suspect is a minor, this article reproduces no identifying details about him, in accordance with the law. Since no official source has confirmed the technical vector of the intrusion, this article refrains from characterizing it.

Exhibits

The case exhibits

French Interior Ministry20 April 2026

Exhibit 01

“On Wednesday 15 April 2026, the national agency for secure documents (ANTS) detected a security incident potentially involving a disclosure of data from individual and professional accounts on the ants.gouv.fr portal. (our translation)”

French Interior Ministry — 20 April 2026 Press statement View source

Paris public prosecutor30 April 2026

Exhibit 02

“Between 12 and 18 million lines of data were offered for sale on cybercrime forums, by a hacker going by 'breach3d'. The ANTS confirmed unusual activity on its network on 13 April 2026, and the authenticity of the resold data. (our translation)”

Paris public prosecutor — 30 April 2026 Press statement View source

ANTS / France Titres14 January 2025

Exhibit 03

“A phishing operation aimed at unduly harvesting the SIV access data of authorized automobile professionals is under way. (our translation)”

ANTS / France Titres — 14 January 2025 Alert to authorized professionals View source

DGCCRF (Bercy Infos)10 February 2025

Exhibit 04

“Fake government websites are web pages that imitate the official sites of public administrations, to make you believe you are accessing a public service and thereby steal your money or your personal information. (our translation)”

DGCCRF (Bercy Infos) — 10 February 2025 How to spot a fake government website View source

Related articles