Full Report
In other news: OpenAI agents hack a German wiki; Pentagon bill will allow cyber contractors; Five Eyes tells hacked companies to drop PR spin.
Analysis Summary
# Incident Report: Multi-Year BEC Campaign Targeting French Notaries
## Executive Summary
Over a four-year period, a sophisticated Business Email Compromise (BEC) campaign targeted the French notary sector, resulting in the theft of approximately €35 million. Attackers compromised over 500 notary offices (roughly 7% of the national total) to intercept and modify financial transaction details. The incident prompted a large-scale, non-public intervention by the French national cybersecurity agency, ANSSI, to stabilize the sector.
## Incident Details
- **Discovery Date:** Approximately 2024 (Active intervention by ANSSI began)
- **Incident Date:** 2022 – September 2026 (Ongoing for four years)
- **Affected Organization:** 500+ French Notary Offices; Conseil Supérieur du Notariat (CSN)
- **Sector:** Legal / Real Estate / Government Services
- **Geography:** France
## Timeline of Events
### Initial Access
- **Date/Time:** Commenced circa 2022
- **Vector:** Phishing
- **Details:** Hackers utilized phishing campaigns to harvest credentials and gain initial access to the internal networks of individual notary firms.
### Lateral Movement
- **Details:** Attackers maintained "deep access" within the compromised networks, allowing them to remain undetected for long periods while navigating internal systems.
### Data Exfiltration/Impact
- **Details:** The primary impact was the modification of bank wire transfer details. By silently altering transaction information, attackers hijacked payments related to real estate deals and other notarized acts, totaling €35 million. There were also significant concerns regarding the potential forgery of notarized acts (marriage certificates, property deeds).
### Detection & Response
- **Discovery:** Identified via recurring financial discrepancies across multiple firms.
- **Response Actions:** ANSSI spent two years (2024–2026) performing remediation and eviction of the threat actors. The CSN mandated new security protocols, including 2FA and the prohibition of sending banking details via email.
## Attack Methodology
- **Initial Access:** Phishing/Social Engineering.
- **Persistence:** Long-term network residency; persistent access to email and document systems.
- **Privilege Escalation:** Not specified, but sufficient to modify financial records.
- **Defense Evasion:** "Silent" modification of data to avoid triggering immediate alarms.
- **Credential Access:** Credential harvesting via phishing.
- **Discovery:** Internal reconnaissance of financial transaction workflows.
- **Lateral Movement:** Persistence across local office networks.
- **Collection:** Monitoring of email communications and financial transaction drafts.
- **Exfiltration:** N/A (Focused on transaction hijacking).
- **Impact:** Financial theft (€35M) and potential integrity compromise of public records.
## Impact Assessment
- **Financial:** Over €35 million in direct losses.
- **Data Breach:** Compromise of sensitive legal and identity documents; potential for forged public records.
- **Operational:** Significant changes to national notary workflows and banking verification procedures.
- **Reputational:** High; raised concerns regarding the legal validity of notarized acts in France.
## Indicators of Compromise
- **Network indicators:** Not publicly disclosed in the report.
- **File indicators:** Not publicly disclosed.
- **Behavioral indicators:** Unauthorized modification of IBAN/bank details in outgoing correspondence; suspicious logins to notary-specific software.
## Response Actions
- **Containment:** ANSSI intervention to identify and evict attackers from over 500 networks.
- **Eradication:** Widespread credential resets and system hardening.
- **Recovery:** Modification of banking procedures; banks added extra verification checks for notary transactions in 2024.
## Lessons Learned
- **Sector-wide Vulnerability:** A centralized or highly standardized sector (like notaries) can be systematically targeted if baseline security is low.
- **PR and Disclosure:** The incident was managed privately for years by ANSSI before becoming public, highlighting a strategy of quiet remediation to prevent panic regarding legal document integrity.
- **Process over Technology:** Technical controls were insufficient; physical presence requirements for financial details were necessary to break the attack cycle.
## Recommendations
- **Multi-Factor Authentication (MFA):** Implementation of 2FA for all notary-specific applications and email.
- **Out-of-Band Verification:** Mandatory verbal or physical verification of all banking detail changes.
- **E-mail Encryption:** Use of secure portals rather than standard email for transmitting sensitive financial instructions.