A 15-year-old operating under the alias “breach3d” allegedly pierced the defenses of France’s Agence Nationale des Titres Sécurisés, or ANTS. Millions of records spilled out. Passports. ID cards. Driver’s licenses. The breach hit hard, exposing data on up to a third of the population.
France Titres—formerly ANTS—manages the nation’s most sensitive documents. On April 15, 2026, its teams spotted unusual network activity. By April 13, they confirmed the intrusion. Personal details flooded underground forums: login IDs, full names, emails, birth dates, unique account numbers, postal addresses, phone numbers. No scans or photos leaked, officials stressed. But the haul was massive. “Breach3d” boasted 18 to 19 million records, taunting, “It seems the French government would do better to stick to the culinary arts: their digital defenses are as crumbly as their croissants.” (The Register)
Prosecutors moved fast. France’s cybercrime office, OFAC, got wind in early April. ANTS verified the samples’ authenticity. April 16: Paris prosecutors launched a probe. April 25: Police detained the teen. Public Prosecutor Laure Beccuau announced charges on April 30. Fraudulent access to a state data system. Data extraction. Each counts seven years in prison, €300,000 fine—for adults, anyway. France favors re-education for minors. Judicial supervision followed. (The Register)
Officials notified the CNIL, France’s data watchdog, per GDPR Article 33. ANSSI, the cybersecurity agency, joined in. Personalized alerts went to users. “Exercise utmost vigilance against suspicious messages,” warned the Interior Ministry. No account takeovers possible from the leaked info, they claimed. But phishing risks soared. Identity theft. Fraud. The portal stayed online, bolstered by new safeguards. (French Interior Ministry)
And this wasn’t isolated. France reels from attacks. January: An 18-year-old leaked a million records from the French Shooting Federation. Earlier April: 20-year-old “HexDex” hit over 100 targets—government, sports, businesses. OSINT expert Seb@seblatombe tracked “breach3d.” Days before arrest, the teen bragged about compromising three million public servants, extracting 600 million lines total from France Titres. Compromised API keys. IDOR flaws—change a number in the URL, pull any record. He slipped on opsec: IP traces, location hints. FrenchBreaches notified authorities. (The Record; Cybernews)
Basic mistakes enabled it all. Unpatched APIs. Credential stuffing. No zero-days. ANTS, guardian of a new age-verification app for kids under 15 on social media, exposed its own users. TechCrunch noted the hacker’s preemptive forum post, claiming 19 million before official word on April 20. Help Net Security flagged phishing alerts. The Register mocked the irony: “Secure” in name only. (TechCrunch)
Scale stuns. 12 to 19 million lines. Unique individuals? Perhaps 1 in 3 French citizens. Underground markets buzzed. Samples verified real. Prosecutors eye broader intrusions: maintaining access, data transmission, tool possession. The PDF communique from Paris Tribunal details it: investigation under juge d’instruction continues. (Paris Tribunal)
But why so vulnerable? Government portals lag private sector patching. Legacy systems. Insider risks—like the tax employee busted selling crypto holder data last year. France Titres handles immigration docs too. Residence permits. A goldmine for criminals. Europol watches. As one X post noted, not state actors. Just kids exploiting sloppiness.
Responses ramp up. Users urged two-factor authentication. Password managers. Vigilance. ANTS reinforces portals. Broader lessons: Audit APIs. Patch fast. Train youth away from dark paths. The teen faces re-education. France, a wake-up.
Incidents pile on. Scattered Spider’s Peter Stokes nabbed in Helsinki, hard drives full. France’s parade of teen hackers signals systemic gaps. Not sophisticated ops. Preventable flaws. Industry insiders know: Secure the basics. Or watch castles crumble.


WebProNews is an iEntry Publication