1. Executive summary
A four-year business email compromise (BEC) and network-intrusion campaign has stolen more than €35 million from French notaries, affecting more than 500 victims — approximately 7% of all French notary offices, per the Conseil Supérieur du Notariat (CSN). Attackers gained initial access via phishing, took over victim networks, and silently modified transaction details to hijack wired payments. None of the compromises were previously disclosed; ANSSI has spent the last two years working behind the scenes on remediation. No CISA-KEV entries, CVSS scores, or named threat actors are associated with this item — no verified reference data resolved for it, and no attribution is confirmed in the source material. The bottom-line risk for EMEA financial services: this is a demonstrated, long-dwell payment-diversion playbook against a professional sector that initiates high-value real-estate and inheritance transfers, and the same procedural weaknesses (email-borne payment instructions, weak out-of-band verification) apply to any client that processes conveyancing, escrow, or corporate treasury payments.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 19: reporting of major ICT-related incidents to competent authorities | The notary compromises went undisclosed for four years while losses accumulated — the item is, at its core, a case study in the cost of non-reporting of a major ICT-related incident. | Financial entities processing notary-linked payments should treat suspected payment-diversion intrusions as potentially reportable major incidents and prepare the classification evidence (Art. 18) needed to make that call quickly, rather than deferring disclosure. |
| NIS2 Art. 23: incident reporting obligations | The campaign demonstrates multi-year, undisclosed compromise of an essential-adjacent professional sector (notaries handling real-estate and civil-status records) with cross-border payment impact. | NIS2-scoped entities should verify their early-warning and incident-notification paths cover third-party-originated payment fraud, not only direct system compromise. |
No other specific DORA/NIS2 article is directly engaged by this item. The trigger for Art. 19 and Art. 23 is the demonstrated reporting failure and its consequences, which is distinctive to this item; generic mappings (e.g. "an incident occurred, therefore Art. 17") are not made.
3. Technical analysis & attack chain
This is a fraud-campaign item, not a vulnerability item. The source is a single newsletter item summarising reporting by Le Monde, with statements attributed to ANSSI sources and the CSN. Technical depth is correspondingly limited; everything below is drawn strictly from the source, and the campaign detail is single-sourced (Le Monde via Risky Bulletin); verify before enforcement.
Confirmed attack chain, as reported:
- Initial access — phishing. Attackers breached notary offices via phishing. No specific lure, malware family, or delivery mechanism is named in the source.
- Network takeover. Following the phishing foothold, attackers "took over their networks." ANSSI sources described the hackers as "particularly persistent and with deep access." No malware names, C2 infrastructure, persistence mechanisms, or tooling are disclosed.
- Silent transaction manipulation. Attackers "slowly and silently modified transaction details to hijack wired payments" — a long-dwell BEC variant in which payment diversion happens inside compromised business systems rather than (or in addition to) via spoofed email threads. This is the defining characteristic of the campaign: the compromise of the transaction record itself, not merely of the communication channel.
- Monetisation. More than €35 million stolen across more than 500 victim offices over approximately four years. Some notaries absorbed losses directly; others claimed against cyber insurance.
- Feared escalation — forged notarial acts. Government officials were concerned the attackers had issued fake notarised acts, or were selling on-demand access to a service that could — for example, forged marriage certificates or real-estate transactions usable in illegal citizenship-acquisition schemes. Investigators have found no signs of any forged documents to date. This is a concern, not a confirmed impact; if forgery did occur, investigators expect it could take several years to surface.
Observed defensive response (per the source): many notary-specific operations now require two-factor authentication; certain banking and financial details may no longer be sent by email and require physical presence. French banks added extra procedural checks for notary transactions in 2024 — the BEC attacks and illegal transactions continued after those checks were in place, which is the most operationally important fact in the item for payment-verification teams.
Confidence caveat: All campaign specifics — €35M figure, 500+ victims, 7% of notary offices, four-year duration, ANSSI's two-year remediation involvement — trace to a single Le Monde investigation relayed by one newsletter. No actor name, MITRE profile, malware family, CVE, IOC, or technical artefact is present in the source. Treat the campaign as real but unverified in its details; do not build enforcement actions on uncorroborated specifics.
4. Mitigation & containment
There are no patches, CVEs, or vendor fixes associated with this item. Mitigation is procedural and process-level, aimed at the payment-verification and third-party-transaction controls this campaign actually defeated.
P1 — within 24 hours
- Assess exposure of notary/conveyancing-linked payment flows. If your institution processes payments initiated by or on instruction from notaries, law firms, escrow agents, or similar professional intermediaries in France (or EMEA-wide), pull the last 12 months of those transactions and review for mid-stream changes to beneficiary account details (IBAN/name changes on previously known payees).
- Verify out-of-band, not in-band. The attackers modified transaction details inside compromised networks — any verification conducted through the compromised party's own email or systems is attacker-controlled. Confirm beneficiary changes by callback to a previously known number, never one supplied in the transaction chain. Note that the source states bank-side procedural checks added in 2024 did not stop the attacks — review whether your checks depend on data originating from the counterparty's potentially compromised systems.
- Flag the pattern for your fraud operations team: long-dwell, low-and-slow transaction modification following a phishing-borne network compromise, not a one-shot wire fraud request.
P2 — within 72 hours
- Restrict email as a channel for payment-critical data. Mirror the notaries' corrective measure: banking and financial details (account numbers, beneficiary changes) should not be accepted or transmitted by email alone; require an authenticated portal, physical presence, or signed instruction for changes.
- Enforce phishing-resilient controls on payment-approval roles. The initial access vector was phishing. Ensure staff who can create or modify payment instructions are on phishing-resistant MFA (FIDO2/equivalent) and that payment-approval authority is separated from email/mailbox administration.
- Hunt for the dwell, not the intrusion. ANSSI characterised the attackers as persistent with deep access over years. If you have any professional-intermediary clients with long-standing, unexplained payment discrepancies, treat it as a potential long-dwell compromise and escalate to full incident response rather than a fraud write-off.
P3 — within 7 days
- Add notary/professional-intermediary transaction changes to retrospective fraud review, with a lookback horizon of years, not weeks — the source notes forged-document impact, if any, could take years to surface.
- Exercise the incident-classification decision path. Given the demonstrated cost of non-reporting in this case, walk your fraud and IR teams through when a payment-diversion incident becomes a reportable major ICT incident under your regulatory regime, and who makes that call.
5. Indicators of compromise
No indicators of compromise available in the source material.
Behavioural indicators (derived from the reported campaign behaviour; no atomic indicators were published):
| Behaviour | Where to observe | Confidence |
|---|---|---|
| Modification of transaction/beneficiary details on previously established payees, occurring gradually after a long dwell period | Payment processing systems; transaction audit logs; beneficiary master-data change history | Medium — described in source, no technical detail given |
| Phishing followed by sustained network access at a professional intermediary (notary/law firm) initiating payments to your institution | Counterparty-side; observable indirectly via anomalous instruction patterns | Medium — single-sourced |
| Payment instructions from notary counterparties that continue to divert despite standard bank-side procedural checks (post-2024) | Fraud operations; exception queues on notary-linked transactions | Medium — explicitly stated in source |
6. Detection
Insufficient indicators to author detection rules.
The source contains no malware artefacts, strings, hashes, filenames, registry keys, command lines, or network indicators. The behavioural indicators in §5 are procedural patterns observable in payment and fraud systems, not log signatures; they are best implemented as fraud-rule tuning (beneficiary-change velocity and lookback windows on professional-intermediary payment corridors) rather than YARA/Sigma content.
7. Sources
- Risky Business (Risky Bulletin), "BEC campaign steals €35 million from French notaries," https://news.risky.biz/risky-bulletin-bec-campaign-steals-eur35-million-from-french-notaries/, 2026-09-07. (Summarises reporting by Le Monde; statements attributed to ANSSI sources and the Conseil Supérieur du Notariat.)
8. Adverse Trace position
This is a high-impact, low-technical-detail item. The €35M loss across ~7% of French notary offices demonstrates a payment-diversion playbook that defeats both email-hygiene controls and bank-side procedural checks by compromising the transaction record inside the victim's network over a long dwell — the lesson for EMEA financial services is that verification must be out-of-band and independent of the counterparty's own systems, and that beneficiary-detail changes on professional-intermediary corridors deserve multi-year retrospective review. Severity of the underlying campaign is significant, but we do not inflate it beyond the source: no CVSS, KEV, malware, or attribution data exists for this item, and all campaign specifics are single-sourced through Le Monde — clients should verify independently before taking enforcement or client-notification action against any specific counterparty. Adverse Trace will monitor for the underlying Le Monde investigation, any ANSSI public statement, and any IOC release or actor attribution; this advisory will be revised if corroborating technical detail emerges.
Published via PulseTrace — Adverse Trace threat intelligence.