Security2 publishers2 min readPublished
French notaries lost the money to intruders who lived on their networks and edited payment details before the instructions went out, which is why bank-side verification kept waving the transfers through.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Work back from the CSN's 7% and the French profession is on the order of 7,100 offices [14]. More than 500 of them were hit [3]. Divide the reported total, more than 35 million euros [1], across 500-plus victims and the average loss per office is around 70,000 euros [13]. That figure explains the silence better than any disclosure policy does: it is a sum a practice absorbs, or hands to an insurer [11], without issuing a statement.
Banks did try. Extra procedural checks on notary transactions went in during 2024, and the diversions continued [10]. Upstream tampering explains why. The instruction that reached the bank came from the real office on the real network; only the payment details had been altered beforehand, quietly, by an intruder already holding the network [2]. ANSSI sources told Le Monde the attackers were persistent and had deep access [6].
ANSSI has spent two years on the clean-up, working out of public view to help offices evict the intruders and rebuild defences [5]. The campaign is four years old [1], so roughly half of it ran before the national agency was in a position to coordinate an eviction [15].
French officials also weighed whether the intruders had issued fake notarised acts, or were selling that on demand as a service, with marriage certificates and real estate transfers as the outputs useful to illegal citizenship schemes [7]. Investigators report no forged documents so far, and say that if any exist, several years could pass before they surface [8]. The remedy the profession chose points at the same distrust: two-factor authentication on many notary-specific operations, and a rule that certain banking and financial details cannot travel by email at all and require a physical presence instead [9].
The reporting does not name an actor. No group has been named, no malware family identified, and no indicators released [17]. The account rests on the CSN's counts and on ANSSI sources speaking to Le Monde [3][6], relayed in the September 7 bulletin [12]. One profession over four years is not enough to say business email compromise generally has moved off the mailbox, but it does show that here the phishing email was the entry point rather than the fraud itself, and that the fraud took place where transaction data is assembled [2]. Controls built on the assumption that the mailbox is the crime scene could not catch tampering that happened upstream of it.
Ranked by verification strength, evidence, and original report placement.
Hackers stole more than 35 million euros from French notaries in a campaign running over the past four years.
The Risky Bulletin edition carrying the report is dated September 07, 2026.
The attackers breached companies via phishing, took over their networks, and slowly and silently modified transaction details to hijack wired payments.
According to French newspaper Le Monde, the campaign hit more than 500 victims, about 7% of all French notary offices, per France's notary supervisory agency, the Conseil Superieur du Notariat (CSN).
France's cybersecurity agency ANSSI spent the last two years working behind the scenes to help notaries kick out the hackers and shore up their defences.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One newsroom, one newspaper, no primary document
The €35 million total and the 500-plus victim count both reach readers through a single Risky Bulletin edition summarising Le Monde, which credits the CSN for the count and unnamed ANSSI sources for the portrait of the intruders. Nothing we hold is a primary record: no ANSSI advisory, no CSN statement, no court or supervisory filing. The specifics are internally consistent and precisely attributed upstream, which is why this sits mid-scale rather than low, but the chain has one link at every step.
Two rounds of controls, coverage unstated
Countermeasures are on the record in sequence: bank-side checks on notary transactions in 2024, which the reporting says did not stop the fraud, then two-factor authentication on notary operations and a ban on emailing certain banking details. What nobody supplies is reach. There is no figure for how many of the roughly 7,100 offices now operate under the new rules, and ANSSI's remediation is described only as two years of work behind the scenes.
Told smaller than it is
A four-year intrusion into 7% of a regulated profession, undisclosed until a newspaper found it, gets a headline and a paragraph inside a bulletin that also covers a hacked German wiki and a Pentagon contracting bill. Where the material invites a leap, the reporting declines it: the fake-notarised-acts scenario is presented as an official fear, immediately followed by the fact that no forged documents have been found. The framing runs behind the underlying facts rather than ahead of them.
Sponsored page, self-reported count
The newsletter discloses an identity-vendor sponsor in its first line, and the remedy at the centre of the story is identity: two-factor authentication on notary operations. Upstream, the victim count comes from the profession's own supervisory body and the persistence framing from ANSSI sources briefing anonymously after two years of quiet remediation, both parties with a stake in how a four-year undisclosed compromise reads. The disclosure is visible and the attributions are named where they can be, which keeps this from scoring higher.
Coherent account, unverified chain
The detail is specific enough to be checkable in principle: dates, a named supervisory body, a named newspaper, an identified control change in 2024. It has not been checked anywhere in our coverage, and the two items we hold are one edition published twice. Treat the mechanism and the direction of the response as solid, and the numbers as one newspaper's figures until a French official record confirms them.
security
Agent Tesla v4 hides in emoji and never hits disk: an email-rule problem, not a new-malware one2 publishers
leadership
Fraud budgets are moving ahead of the loss data in Experian's survey of 200 firms1 publisher
build
Munich Re's reported $575M for At-Bay reprices cyber underwriting, if the deal is real1 publisher
product
France's tax agency lost 678,000 records through logins it had issued itself1 publisher
Publishers with included, body-backed reporting in this cluster.
1 article · September 6, 2026
2 articles · September 6, 2026