Over four years, a methodical and largely invisible campaign of phishing and network infiltration drained more than €35 million from over 500 French notary offices — institutions whose authority rests on the legal sanctity of the documents they produce. The attackers did not simply steal money; they occupied the inner workings of a profession built on trust, raising the deeper fear that the very paperwork underpinning property, identity, and family law may have been quietly falsified. France's cybersecurity agency worked in the shadows for two years to expel the intruders, and the sector has s
BEC campaign steals €35M from French notaries over four years
Attackers modified transaction details to quietly redirect wire payments
So this was a phishing campaign, but it wasn't just stealing credentials and moving on. The attackers stayed inside the networks for years?
Exactly. They got in through phishing emails, but once they were inside, they didn't ransack the place. They modified transaction details—slowly, carefully—to redirect wire payments. It's the kind of attack that works because it doesn't announce itself. The notaries didn't know they were being robbed.
How many notaries actually discovered this themselves versus being told by ANSSI? Because if most of them didn't notice, that's a different story than if they caught it and reported it.
The reporting doesn't specify. ANSSI spent two years working behind the scenes, so it's likely many offices never knew until the agency showed up. That's part of what made it so effective.
And the fear about forged documents—marriage certificates, real estate deeds—that's not just about money, is it? That's about the integrity of the entire legal system.
Right. If someone can forge a notarized deed, they can transfer property that isn't theirs. They can create false marriages for citizenship schemes. The €35 million is real damage, but the potential damage to the legal system is what kept officials up at night.
But they haven't found any forged documents yet. So we don't actually know if that happened.
No, we don't. And investigators said it could take years to find them if they exist. A forged deed might sit in a registry for a long time before anyone notices something is wrong.
So the notary sector responded by requiring two-factor authentication and banning email transfers of sensitive information. Did that work?
Partially. Banks added extra checks in 2024, but the attacks continued for months after that. It took time for the entire ecosystem to adapt.
The question is whether we're seeing the full picture now or if there are still breaches happening that haven't been discovered. Four years is a long time to operate undetected.
The Pulse
- For four years, attackers moved silently through notary networks, redirecting wire payments with surgical patience — some offices never knew they had been breached until investigators came to them.
- The theft of €35 million across 7% of France's notary sector is alarming enough, but authorities are more unsettled by what the attackers could have done: forge marriage certificates, real estate deeds, and property transfers that carry the weight of law.
- ANSSI spent two years quietly dismantling an adversary described as unusually entrenched — the kind that does not leave willingly once it has made a network its home.
- The sector has since mandated two-factor authentication, banned email transmission of sensitive banking details, and required clients to appear in person — yet even these measures did not immediately halt the campaign.
- The deepest uncertainty is not what was stolen, but what may have been silently inserted into the legal record — forged documents, if they exist, could take years to surface and longer still to untangle.
Over four years, a methodical and largely invisible campaign of phishing and network infiltration drained more than €35 million from over 500 French notary offices — institutions whose authority rests on the legal sanctity of the documents they produce. The attackers did not simply steal money; they occupied the inner workings of a profession built on trust, raising the deeper fear that the very paperwork underpinning property, identity, and family law may have been quietly falsified. France's cybersecurity agency worked in the shadows for two years to expel the intruders, and the sector has since hardened its defenses — yet the full reckoning may still be years away.
Over four years, hackers quietly dismantled the financial integrity of France's notary profession, stealing more than €35 million from over 500 offices — roughly 7 percent of all notaries in the country. Their method was unhurried and precise: phishing emails opened the door, persistent network access kept it open, and incremental alterations to transaction records redirected wire payments before anyone noticed. The Conseil Supérieur du Notariat confirmed the scale of the breach, and Le Monde brought it into public view.
What unsettled French authorities most was not the theft itself, but the shadow it cast over something more fundamental. Notaries in France are custodians of legal reality — they authenticate marriages, property transfers, and identity documents. Officials feared the attackers may have exploited their deep access to forge such records, potentially enabling identity fraud or illegal citizenship schemes. No forged documents have been confirmed, but investigators are candid: if they exist, they may not surface for years.
France's cybersecurity agency, ANSSI, spent two years working largely out of public view, helping notaries identify and expel intruders described as unusually patient and deeply embedded. Some offices discovered the breach only because ANSSI came to them. The financial damage fell unevenly — some absorbed losses directly, others leaned on cyber insurance — but the profession as a whole was forced into a reckoning it had long deferred.
New safeguards followed: two-factor authentication became standard, sensitive banking details can no longer travel by email, and clients must now appear in person to authorize certain transfers. Banks added their own verification layers in 2024. Yet even these measures did not immediately end the campaign, which continued for months afterward. The episode leaves behind a more vigilant profession — and an open question about what, if anything, was quietly written into the legal record during four years of undetected access.
Over the past four years, hackers orchestrated one of France's most persistent financial crimes, stealing more than €35 million from the country's notary offices through a campaign of phishing emails and network infiltration. The attackers' method was methodical and quiet: they breached companies through deceptive emails, established themselves deep within corporate networks, and then methodically altered the details of financial transactions to redirect wire payments into their own accounts. According to reporting by Le Monde and confirmed by France's notary supervisory body, the Conseil Supérieur du Notariat, the campaign compromised more than 500 notary offices—roughly 7 percent of all notaries operating in France.
What made this campaign particularly alarming to French authorities was not just the scale of the theft, but the potential for something far worse. Government officials worried that the attackers might have used their access to forge notarized documents—marriage certificates, real estate deeds, property transfers—the kind of official paperwork that could facilitate identity fraud or illegal citizenship schemes. The fear was not merely that money was being stolen, but that the entire legal foundation of transactions could be undermined. Investigators have found no evidence that forged documents were actually created, though officials acknowledge that if such forgeries exist, they could take years to surface in the system.
France's cybersecurity agency, ANSSI, spent two years working largely out of public view to help notaries expel the attackers and rebuild their defenses. Sources within ANSSI described the intruders as unusually persistent and deeply entrenched in their victims' systems—the kind of adversary that does not leave easily once it has established a foothold. The attackers were patient, moving slowly through networks and making incremental changes to transaction records, which made detection difficult. Some notaries discovered the breaches only after ANSSI's intervention; others never knew they had been compromised until the agency came knocking.
The financial toll was distributed unevenly across the sector. Some notary offices absorbed the losses directly; others had cyber insurance policies that covered portions of the theft. But after four years of quiet infiltration and systematic theft, the entire profession began to take the threat seriously in ways it had not before. The notary sector implemented new procedural safeguards: many operations now require two-factor authentication, and sensitive banking and financial information can no longer be transmitted by email—clients must appear in person to authorize such transfers. Banks themselves added extra verification steps when processing notary transactions starting in 2024, yet even these measures did not immediately stop the attacks. The campaign continued for months after the banking sector tightened its procedures.
What remains uncertain is whether the full scope of the damage has been discovered. Investigators have not confirmed any forged documents, but the absence of evidence is not evidence of absence. If the attackers did create false notarized acts and those documents entered the legal system, it could take years before they are identified and the consequences become clear. The French notary sector is now more vigilant, more skeptical of routine requests, and more willing to invest in security infrastructure. But the campaign serves as a reminder that even highly regulated professions with formal procedures and institutional oversight can be systematically compromised by patient, well-resourced attackers who understand how to move through networks without triggering alarms.
Notable Quotes
ANSSI sources described the hackers as particularly persistent and with deep access to their victims' systems— ANSSI sources speaking to Le Monde