Skip to content
>_ITDITDWeb Security Platform

Security Guides

What leaked was not your ID but a list of people with ID paperwork in progress — the France Titres (ANTS) breach and how to spot fake ANTS messages

France Titres (ANTS), which handles French ID card, passport, driving licence and vehicle registration applications, detected a breach on April 15, 2026. The Interior Ministry says about 11.7 million accounts may be affected; attachments and biometrics were not. What users should do, from official French guidance.

Published 2026-09-30 Updated 2026-09-30 Last verified 2026-09-30 14 min read

For: anyone who has used France Titres (ANTS) for an ID card, passport, driving licence or vehicle registration, including foreign residents who exchanged their licence for a French one, and anyone worried about messages that pretend to be about official paperwork. This article is based on announcements by the French Interior Ministry and the government information site info.gouv.fr, the government's answer in the National Assembly, and guidance from the CNIL and cybermalveillance.gouv.fr (the government's victim-assistance service). It does not cover attack techniques.

What users should do today

1

Use the ANTS notification to check whether you are affected

According to the government, ANTS has been sending individual information emails to affected users (all professional-account users had been emailed by April 21; individual users were being emailed in turn). Fake copies of that email can circulate too. Even to check a real notice, do not use a link in the email: type ants.gouv.fr into your browser yourself and log in there. If you exchanged a foreign driving licence for a French one, that application is made on the ANTS website (per Service-Public.fr), so your account may be included.

2

Change your password the next time you log in

The one concrete action the government asks for is changing the account password at the next login. It says the leaked data does not allow anyone to log in to your account, but recommends the change as good digital hygiene. If you used the same password anywhere else, change it there too (the CNIL recommends starting with important accounts such as email, tax and banking, and never reusing passwords). ANTS says two-step authentication has been in place since April 29.

3

Treat texts, calls and emails about ANTS, licences or registration as suspect

The government asks users to be extremely careful with suspicious texts, calls and emails that appear to come from ANTS or France Titres. The CNIL's advice: do not open attachments, do not reply, do not click links, and type the official website address yourself. cybermalveillance.gouv.fr states that no serious administration or company will ask for your bank details or passwords by email or phone (see What is phishing?).

4

Check the status of an application only through official channels

If a message says your application is blocked or a fee is unpaid, do not call the number in the message. Use the "Aide et contact" section of ants.gouv.fr or the ANTS citizen contact centre listed by the Interior Ministry (34 00 from mainland France; 09 70 83 07 07 from overseas France and abroad). The official ANTS application sites are ants.gouv.fr and its subdomains, such as permisdeconduire.ants.gouv.fr, immatriculation.ants.gouv.fr and passeport.ants.gouv.fr.

5

Report suspicious messages

According to cybermalveillance.gouv.fr, you can report a scam text by forwarding it to 33700, a suspicious email to Signal Spam, and a fake website to Phishing Initiative. Reporting also helps protect other people receiving the same message.

6

If your identity is misused: police, bank and account check

If you suspect identity theft (usurpation d'identité), the CNIL advises checking cybermalveillance.gouv.fr for guidance, filing a complaint (plainte) with the police or gendarmerie as soon as possible, alerting your bank(s), and checking whether accounts have been opened in your name, for example through FICOBA, the national bank account register (via impots.gouv.fr).

7

No need to replace your ID card, passport or licence

The government says that, apart from the password change, no particular action is expected from users. Since attachments and biometric data are described as not affected, replacement has not been advised. Rushing into a replacement also makes you more likely to respond to fake "start your replacement here" messages.

Name, title, email address

+ the fact that you use ANTS

↓

"Dear Madame/Monsieur X, this is ANTS"

→ Skip the link; open ants.gouv.fr yourself

Date and place of birth

(place of birth for some accounts)

↓

A call that "verifies" you with your real birth date

→ Knowing it proves nothing. Hang up, call the official line

Phone number, postal address

(some accounts)

↓

A text asking for a fee to ship your licence or registration

→ Forward to 33700; do not pay

Not included (per the government): application attachments such as ID scans, and biometric data

The data described as exposed, the kind of message it makes convincing, and how to check (data items from the Interior Ministry; checks from government and CNIL guidance).

What happened (from the Interior Ministry and government announcements)

Everything below is as stated in the Interior Ministry's press releases (April 20, 21 and 24), the government explainer on info.gouv.fr, the government's answer in the National Assembly (published May 13), and ANTS's replies to users.

  1. Wed April 15, 2026

    ANTS detected a security incident that may have exposed data from individual and professional accounts on ants.gouv.fr, and began internal technical investigations.
  2. April 20

    The Interior Ministry announced the incident. Under Article 33 of the GDPR it was notified to the CNIL, a report was sent to the Paris public prosecutor, and ANSSI (the national cybersecurity agency) was alerted.
  3. April 21

    Progress update: about 11.7 million accounts may be affected; investigations rule out the disclosure of attachments and biometric data. All professional-account users had been emailed; individual users were being emailed. The Interior Minister asked the General Inspectorate of Administration (IGA) to establish the chain of responsibility.
  4. April 22

    The government information site info.gouv.fr published an explainer (updated April 24).
  5. April 24, 7:30 p.m.

    ANTS put its application pages into maintenance to continue strengthening security. Information pages stayed online, and applications completed before the shutdown continued to be processed.
  6. April 29

    According to ANTS, two-step authentication was put in place; the portal was later described as fully accessible again.
  7. Published May 13

    In the National Assembly, the minister delegate said data from 11.67 million individual and professional accounts had been extracted. The judicial investigation was entrusted to the Anti-Cybercrime Office.
~11.7M
Accounts that may be affected (Interior Ministry, April 21)
3 kinds
Procedures on the portal: ID and passport / driving licence / vehicle registration
Not included
Application attachments and biometric data (per the government)
April 29
Two-step authentication introduced (per ANTS)
Data described as exposed, and not exposed (Interior Ministry)
Individual accounts
Login ID, title, surname, first names, email address, date of birth, unique account ID. For some accounts, postal address, place of birth and phone number
Professional accounts
According to the government's answer in the National Assembly, also authorisation or approval numbers
Not included
Additional data submitted for procedures (attachments, biometric data). The ministry says the leaked data does not allow illegitimate access to the account
Cause (government account)
Investigations by ANTS and the competent services aim to establish the origin and scale. In the National Assembly the government said a major attack led to the extraction of the data. Technical details have not been published
Reports and inquiries
Notification to the CNIL; report to the Paris prosecutor (judicial investigation entrusted to the Anti-Cybercrime Office); ANSSI alerted. The Interior Minister referred the matter to the IGA to establish responsibilities
ANTS measures
Individual emails to users; the phone menu updated with the incident as a reason for calling, with more call capacity; application pages taken into maintenance; two-step authentication introduced

How to read the numbers: 11.7 million is accounts

The ministry's figure counts accounts, not people; the government's answer in the National Assembly gives 11.67 million. Larger numbers circulating online are not government figures and are not used here. The info.gouv.fr explainer gives the detection date as "March 15", but the Interior Ministry's press releases and the government's answer in the National Assembly both say April 15, and this article follows them.

A list from an ID-document portal is a ready-made script for scams

The kinds of data described here are not very different from those in a typical online-shop or membership-site breach. What differs is where it came from. Having an ANTS account means a person has dealt with an ID card, passport, driving licence or vehicle registration. That is exactly the "plausible reason" a scam message needs.

What a typical membership-site list enables

  • "There is a problem with your account"
  • "Your order could not be delivered"
  • Many recipients can tell they have no such account or order

What an ID and licence portal list enables

  • "Your licence exchange application is incomplete"
  • "A fee is needed to ship your registration certificate"
  • The people who really did the paperwork are the ones most likely to believe it

In the Odido case in the Netherlands, ID document numbers leaked (the Odido breach). In the Times Car case in Japan, images of driving licences leaked (the Times Car breach). According to the French government, neither numbers nor images leaked from ANTS. The reason to stay alert is that the paperwork context leaked.

This site's view: the breach notice itself becomes the template for fakes

After a breach, an organization emails the people affected, as ANTS did. From the moment it arrives, that notice is also a template for fakes: copy the subject and wording, swap the link, and it looks official.

As a user, decide in advance that you will never use the link, however real the message looks. Only log in from a bookmark or from ants.gouv.fr typed by hand. Then you never have to tell real from fake at all.

For organizations sending breach notices, the lesson is just as clear: put no login link in a breach notice, say plainly "this email contains no links; go to our website yourself", and name one official contact channel. If the real notice has no link, you can give users a simple rule: a notice with a link is fake. ANTS added two-step authentication after the incident; how the options compare is covered in Choosing multi-factor authentication.

For another French case disclosed in 2026 in which patient lists left a single system, see the Cegedim Santé patient data breach.

Sources (public record)

The facts in this article come from the public sources below. Claims by the party that took the data, speculation in media coverage, and undisclosed figures or causes are not used.

  • French Interior Ministry, "Incident de sécurité relatif au portail ants.gouv.fr" (April 20, 2026) — interieur.gouv.fr
  • French Interior Ministry, "Incident de sécurité relatif au portail ants.gouv.fr : point d'étape du 21 avril 2026" — interieur.gouv.fr (archived copy)
  • French Interior Ministry, "Fermeture du portail ants.gouv.fr pour maintenance" (April 24, 2026; FAQ and contact numbers) — interieur.gouv.fr
  • French government, "France Titres : le point sur l'incident de sécurité" (published April 22, updated April 24, 2026) — info.gouv.fr (archived copy)
  • French National Assembly, "Question orale n° 727 : Fuite des données ANTS" (government answer, published May 13, 2026) — assemblee-nationale.fr
  • France Titres (ANTS) reply to a user (May 13, 2026; two-step authentication since April 29) — plus.transformation.gouv.fr
  • CNIL, "Fuite ou vol de données : comment savoir si cela vous concerne et que pouvez-vous faire ?" — cnil.fr
  • cybermalveillance.gouv.fr, "Hameçonnage (phishing)" — cybermalveillance.gouv.fr
  • Service-Public.fr, "Échange de permis de conduire obtenu hors Europe (UE/EEE)" (checked June 1, 2026) — service-public.gouv.fr
  • France Titres (ANTS) official site — ants.gouv.fr

Update history

2026-09-30: First version, based on the Interior Ministry's press releases (April 20, 21 and 24), the government explainer (April 24 update), the government's answer in the National Assembly (published May 13), ANTS's reply to users (May 13), and CNIL and cybermalveillance.gouv.fr guidance. The technical cause and the findings of the IGA inquiry have not been published; this article will be updated if they are.

FAQ

QWhat data was exposed in the ANTS (France Titres) breach?
A

According to the French Interior Ministry, for individual accounts the data includes login ID, title, surname and first names, email address, date of birth and a unique account ID, and for some accounts a postal address, place of birth and phone number. In the National Assembly, the minister delegate to the Interior Minister said that for professional accounts it also includes authorisation or approval numbers.

QWere copies of ID cards or licences, photos or fingerprints exposed?
A

The Interior Ministry says the investigations so far rule out the disclosure of the additional data submitted for the various procedures, such as attachments (pièces jointes) and biometric data. The government's answer in the National Assembly also said none of the supporting documents needed to obtain a secure document, and no biometric data, were involved.

QHow many people were affected?
A

In its April 21, 2026 update, the Interior Ministry said about 11.7 million accounts (11,7 millions de comptes) may be affected. In May, the minister delegate told the National Assembly that data from 11.67 million individual and professional accounts had been extracted. These are account counts, not a count of people.

QDo I need to replace my ID card, passport or driving licence?
A

The government says no particular action is expected from users other than changing the account password at the next login, and it asks them to be very careful with suspicious texts, calls and emails that appear to come from ANTS. Because attachments and biometric data are described as not affected, document replacement has not been advised.

QDoes this affect people who exchanged a foreign driving licence for a French one?
A

According to Service-Public.fr, the French government's administrative information site, applications to exchange a driving licence obtained outside Europe are made online on the France Titres (ANTS) website. Anyone who created an ANTS account for that purpose may therefore be affected. ANTS has been emailing affected users individually.

QWhat caused the breach?
A

The Interior Ministry says the investigations are being led by ANTS teams and the competent services to determine the origin and scale of the incident. In the National Assembly, the government said a major attack led to the extraction of data from 11.67 million accounts. The Interior Minister asked the General Inspectorate of Administration (IGA) to establish the chain of responsibility, and the judicial investigation opened after a report to the Paris prosecutor was entrusted to the Anti-Cybercrime Office. Technical details of the cause have not been officially published.