2026 ANTS / France Titres — national identity portal (~18–19M citizens; IDOR; Apr)
Data compromised
Names, contact details, birth metadata, identity-process status, and related account fields per government and press summaries
Technical writeup
France’s Agence nationale des titres sécurisés (ANTS), which operates the France Titres national portal for identity cards, passports, and driver licenses (moncompte.ants.gouv.fr), disclosed a major incident detected around April 15, 2026, with the Ministry of Interior and national press describing potential exposure on the order of roughly 18–19 million citizen accounts—among the largest French administrative data incidents on record. Early technical reporting attributed exploitation to a basic insecure direct object reference (IDOR)–style flaw in which API requests could retrieve other users’ records by altering identifiers without adequate authorization checks. Public summaries described fields such as names, emails, dates and places of birth, addresses, phone numbers, and account or workflow metadata for individuals and some professional accounts; criminal forums reportedly advertised related data. Official statements emphasized investigation, remediation, and regulatory coordination; treat precise per-field scope as subject to ongoing government confirmation.
Root cause
API authorization flaw (IDOR-style access) cited in press; full forensic report pending
References
- https://www.lemonde.fr/pixels/article/2026/04/20/l-ants-qui-gere-les-cartes-d-identites-et-passeports-visee-par-une-attaque-informatique-des-donnees-potentiellement-divulguees_6681710_4408996.html
- https://www.lesnumeriques.com/societe-numerique/france-titres-ants-victime-d-une-cyberattaque-massive-cartes-d-identite-passeports-permis-19-millions-de-comptes-exposes-n254613.html
- https://www.clubic.com/actualite-609775-l-ants-piratee-a-cause-d-une-faille-basique-et-19-millions-de-francais-en-font-les-frais-une-fois-de-plus.html