1. What happened

A subcontractor of the operator of the user support module of TRACFIN's online reporting portal was compromised, leading to the theft of data between late June and mid-July 2026. The incident was disclosed on 30 September by the national cybersecurity agency, ANSSI, in the first progress report of REACTIV, its operation to respond to the wave of breaches hitting the French state.

TRACFIN is France's financial intelligence unit, attached to the Ministry of the Economy. It receives the suspicious transaction reports that banks, notaries, casinos, crypto service providers and other regulated professionals, known as assujettis, are legally required to file.

What was stolen, according to ANSSI:

  • the name, first name, job title, email address and phone number of 136 assujettis;

  • the content of 213 requests sent to technical support.

2. Why it matters

The stolen data is limited in volume but sensitive by nature. The people concerned are, in most cases, the compliance officers who report suspected money laundering and terrorist financing. French law protects the confidentiality of these reports. The leak does not reveal what they reported, but it links their identity to their role, and gives anyone holding the data the means to contact them directly.

That opens the door to targeted phishing: a fake TRACFIN email or call, citing real details from a support exchange, would be very credible. The content of support tickets can also reveal how a given institution uses the portal.

3. The context, and what to watch

The TRACFIN case is one of 99 data breaches reported to ANSSI since 1 August, of which 67 are confirmed. On 29 September, ANSSI also published its report on the summer breach at the tax administration (DGFiP), which exposed the tax data of about 350,000 taxpayers. It concluded that the attack was not sophisticated but exploited weaknesses in identity management, architecture and detection. Across the incidents, the agency's report points to recurring entry points: no multi-factor authentication, passwords stolen by malware, misconfigurations and compromised subcontractors.

Watch: notification of the people concerned, the identification of other victims of the same subcontractor, and the conclusions of the audit ordered by the Prime Minister's office in August.