Build1 publisher3 min readPublished
France's ANSSI spent two years quietly evicting a crew that had been altering payment instructions inside notary networks. The procedural fix that landed takes bank details off email rather than checking whether they changed.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
Once the phish lands and the network is taken over, the attacker owns the record of a transaction before it becomes an instruction to a bank [2]. That ordering is the trick. The wire leaves with a legitimate sender and a legitimate file reference, carrying an account number that was edited in place, so the receiving bank has no anomaly to score. Which is why the extra procedural checks banks applied to notary transactions in 2024 did not end the campaign [8]. A check on the shape of a transaction does not catch a change to its content when the content is authored by the compromised party.
The arithmetic explains the four years. More than EUR 35 million across more than 500 offices [1][3] averages roughly EUR 70,000 per office [1]. Spread across four years, that is about EUR 8.75 million a year for the whole profession [2], and the 7% figure implies a population near 7,100 offices [3]. Per office, the loss is one payment, not a drained account. Nobody outside had a reason to correlate them: none of the intrusions had been disclosed before Le Monde's reporting [4].
The two procedural changes read as a diagnosis. Two-factor authentication on notary-specific operations addresses the entry [9]. Banning certain banking and financial details from email and requiring physical presence instead [9] concedes something larger, which is that no digital channel reaching the office was trusted to carry a payment detail intact. Requiring a human to turn up in order to hand over account details is a nineteenth-century control, and the reporting does not claim it has stopped the losses, only that it is now the rule [9].
Neither change reconciles anything. The report describes no check that re-reads an executed transfer against the account details on the signed instrument before the money settles [13]. That is the control this campaign argues for, because it is the only one that operates after the attacker has had their edit. Everything else operates before.
The evidence has real gaps. There is no dwell time per office, and no named group [14]. ANSSI's two years of remediation sit inside a four-year campaign [1][5], so approximately the back half ran while the agency was already evicting intruders and the banks' new checks were live [4][8], which is also the reason to treat 500 as a count of what was found rather than a total. On forgery, officials feared fake notarised acts, including marriage certificates and manipulated real estate deals usable in citizenship schemes [7]. Investigators have found none, while also saying such documents could take years to surface [10]. The clean result is bounded by that timeline, not by the thoroughness of the search.
For anyone running payments through a workflow where the same trusted party both authors and stores the instruction, the transferable part is narrow. Either the verification sits after the point where the record can be altered, or the detail leaves the reachable channel entirely. The notaries chose the second.
Ranked by verification strength, evidence, and original report placement.
Hackers stole more than EUR 35 million from French notaries in a campaign running over the past four years.
The attackers breached companies via phishing, took over their networks, and slowly and silently modified transaction details to hijack wired payments.
According to French newspaper Le Monde, the campaign hit more than 500 victims, or about 7% of all French notary offices, per France's notary supervisory agency, the Conseil Superieur du Notariat (CSN).
France's cybersecurity agency ANSSI spent the last two years working behind the scenes to help notaries kick out the hackers and shore up their defences.
ANSSI sources who spoke to Le Monde described the hackers as particularly persistent and with deep access.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One bulletin relaying Le Monde
Every load figure travels the same path: Risky Business summarising Le Monde, which cites the notaries' council for the 7% share and unnamed ANSSI sources for the description of the intruders. No agency advisory, council statement, or filing appears in our coverage. The two details that would let a reader test the account — who was behind it, and how long they held each office — are simply not in the reporting, and the loss total arrives as a round number with no methodology attached.
Response detailed, scale unclear
What has demonstrably spread is the fraud: more than 500 offices, about 7% of the profession, over four years. The response is described rather than counted — two-factor authentication on notary-specific operations, certain banking details barred from email, physical presence required, plus bank checks dated only to 2024. No figure tells us how many offices actually operate under the new rules, and the report concedes the bank-side checks did not stop the transfers.
Undersold in the reporting
A four-year fraud inside 7% of a national profession, remediated over two years by the state cyber agency and never disclosed, runs here as a bulletin item with no adjectives to spare. The restraint understates the story. Where the reporting is too generous is on the cure: taking bank details off email is presented as the sector's answer, yet an attacker who rewrites the destination account still passes every control listed.
Disclosure on the remediators' timetable
The newsletter carries a sponsor above the fold and trades in incident volume, which shapes what it covers more than how this is written. The heavier pull sits on the sources: the story emerges only after ANSSI finished two years of eviction work, the victim share comes from the body that supervises the victims, and the officials describing persistent deep-access intruders are unnamed. Each of those favours an account in which the problem has now been handled, and notary offices that ate losses quietly or claimed on cyber policies had four years of reasons to stay silent.
Consistent, and the only account
The item is specific and internally coherent. It is also the sole telling we have. Figures are round and second hand, countermeasures come without dates or mandates, and the largest open question is one the reporting raises itself: investigators have found no forged notarial acts, while conceding any that exist might take years to appear. Until that window closes, the harm ceiling stays unknown.
security
Four-year payment-diversion campaign drained 35 million euros from 7% of French notary offices2 publishers
security
Agent Tesla v4 hides in emoji and never hits disk: an email-rule problem, not a new-malware one2 publishers
leadership
Fraud budgets are moving ahead of the loss data in Experian's survey of 200 firms1 publisher
security
Dutch bill would let AIVD and MIVD tap a designated adversary for a year without pre-approval2 publishers
Publishers with included, body-backed reporting in this cluster.
1 article · September 7, 2026