Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Data Breaches » Two-Year Cyberattack Campaign Hit 500+ French Notary Offices, Cost at Least $40M

Two-Year Cyberattack Campaign Hit 500+ French Notary Offices, Cost at Least $40M

By:
Last updated:September 4, 2026
Human Written
  • Internal records cited by Le Monde point to more than 500 notary offices affected by the campaign.

  • ANSSI estimated that hackers diverted €35 million to €40 million  ($40-$46 million USD), calling the figure a low estimate.

  • ANSSI feared the hackers could create fake notarial deeds, but investigators found no confirmed fake deed.

Cyberattack on French Notaries Exposed more than 500 Offices, Report Says

A major cyberattack hit France’s notarial profession and stayed active for nearly two years. Hackers broke into notary offices, got into trusted email accounts, and started sending out infected documents. They used this trick to pull off bank fraud and pretended to be CEOs to order money transfers.

This campaign started in December 2022. It came to light through an investigation, published on September 3, 2026, which was carried out by Le Monde. Internal documents from the French National Cyber Security Agency (ANSSI) and the High Council of Notaries (CSN) reveal how big this attack was.

The records point to more than 500 affected offices. That equals about 7% of French notary offices. The CSN gives a much lower figure. It says only three offices suffered a confirmed breach.

That difference matters. The 500 figure comes from wider network access found in internal records. It does not mean 500 offices had a full, confirmed breach.

Hackers Used Trusted Offices to Spread

The attackers did not rely only on random spam. They used access to trusted notary systems to send harmful emails and files to other professionals.

One case shows how far the campaign spread. On March 20, 2024, a hacked notary office in Brittany sent out infected documents to over 10,000 French officials. An ANSSI internal document revealed that most of the officials (about 80%) opened the document.

That gave the attackers a strong way to reach new targets. A message from a real notary looked more credible than one from an unknown sender. ANSSI described the hackers as very persistent. They kept access even after offices and banks added new security steps.

Le Monde also reported that a security firm traced the group to cybercriminals based in South America. The report did not name the group.

The Main Goal was to Steal Money

The hackers mainly wanted to divert payments. They used bank account fraud to send money to accounts they controlled. In some cases, they changed a customer’s bank details before a transfer.

They also used a scam known in France as “fraud by the president.” A criminal poses as a senior person and tells an employee to send money.

Notary offices make useful targets because they handle large sums during property sales and other legal deals. Their staff also hold private information that can help criminals make fake payment requests look real.

The campaign, according to the estimates by ANSSI in November 2O24, diverted between €35 million and €40 million. The agency called that figure a low estimate. Some losses will go through the notaries’ insurance coverage.

The money loss was serious. But investigators feared an even bigger problem. ANSSI warned that the hackers had gained deep access to some notary networks. That raised the risk that they could create or change fake notarial deeds. That could cause major harm.

Notably, a French Notary is in charge of real estate sales and purchases, donations, and marriage contracts. So a fake deed may have really serious consequences. That includes violation of property rights and breach of trust.

Investigators found no evidence that the hackers created an authentic fake deed. The CSN and sources cited by Le Monde said no confirmed fake notarial act had emerged from the campaign. The available evidence points to financial theft as the main goal.

Attackers also Reached the CSN

The campaign did not stop at local notary offices. Attackers also entered the computer system of the CSN, the body that represents France’s notaries.

Internal reports reviewed by Le Monde raised serious concerns about security across the profession. ANSSI also found that about half of the offices had never completed a security audit of their computer systems.

South Korea is strengthening cybersecurity staffing across government agencies. The government is adding 68 dedicated privacy and cybersecurity workers across 36 agencies, including the interior, justice, and foreign ministries. The move follows a rise in hacking and data breaches and aims to protect sensitive data amid growing AI and cloud adoption.

That gap made the sector easier to target. Offices used different systems and had different security practices. A weak office could then help attackers reach other targets. The CSN later said a deeper review confirmed an intrusion but found no concrete damage to its systems.

Notaries have Added New Security Steps

The campaign pushed the profession to tighten its defenses. Banks added extra checks for notary transfers in April 2024. Yet ANSSI later noted that fake transfers continued.

The CSN has since promoted stronger payment checks and extra login steps for some transactions. It also wants offices to limit the use of email when they send bank account details.

The profession has also increased cyber training and awareness. A 2O24 rule requires notaries to take steps to protect their computer systems. The CSN can also check those steps during inspections.

In July 2O25, the CSN and France’s Justice Ministry signed a new agreement. It included digital security goals for 2025 through 2028.

The case shows why notary offices are valuable targets for cybercriminals. They sit at the point where legal records, private data, and large money transfers meet. A stolen notary account can therefore do far more harm than a normal email account.

The worst fear in this case has not come true. Investigators have found no confirmed fake authentic notarial deeds. But the attack still exposed a serious security gap. It also showed how quickly criminals can move from one trusted office to another.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.