A major security breach at France’s tax administration has compromised the personal and professional tax records of hundreds of thousands of citizens and businesses. The incident, which unfolded across June and July, was orchestrated by an attacker who capitalized on stolen employee credentials, weak login protections, poorly segmented government networks, and systemic gaps in internal security monitoring.

According to an incident report published on Tuesday by France’s national cybersecurity agency, ANSSI, the operation was executed without advanced technical sophistication. Despite the massive exfiltration of sensitive fiscal data, neither the French tax administration nor the national cybersecurity agency noticed the information leaving government servers as it happened. The breach only came to light weeks later after the perpetrator publicly claimed responsibility on an online forum.

The targeted institution, the Direction Générale des Finances Publiques (DGFIP), operates the official French tax portal, impots.gouv.fr. The stolen information was harvested primarily from E-Contact, the digital messaging tool that taxpayers use to communicate directly with tax authorities regarding their accounts, liabilities, and inquiries.

Official figures released by the DGFIP indicate that the compromised records affect just over 350,000 individuals and slightly more than 250,000 commercial entities. Crucially, authorities have confirmed that taxpayers’ individual online accounts, personal passwords, and banking credentials were not compromised during the incident.

For individual taxpayers, the data exposed to potential viewing or copying includes tax identification numbers, contact details, family status data, reference taxable incomes, and tax withholding rates. It also included historical listings of messages exchanged with the DGFIP. For a very small subset of fewer than 250 individuals, the actual text content of those messages may have also been accessed.

For businesses, the breach encompassed corporate names, SIREN registration numbers, physical addresses, and basic metadata regarding their official communications. For fewer than 2,076 business entities, the specific contents of those messages were potentially viewed by the attacker.

Discovery and Initial Official Response

The security lapse became public knowledge on August 12, roughly seven weeks after the initial wave of data extraction began, when the attacker stepped forward to boast about the breach on an online forum. In the wake of the public disclosure, Prime Minister Sébastien Lecornu formally requested an in-depth audit from ANSSI to determine how the intrusion occurred.

Initially, the government ministry overseeing the DGFIP offered a different interpretation of events. In August press statements, officials asserted that internal access checks had failed to detect the unauthorized extraction immediately because of the extreme sophistication of the cyberattack. However, ANSSI’s subsequent forensic investigation flatly contradicted that narrative, concluding that the incident succeeded not because of complex hacking tools, but due to fundamental vulnerabilities in cybersecurity hygiene and network architecture.

How the Attacker Gained Access to Government Systems

The ANSSI investigation revealed that the attacker exploited two distinct entry routes to infiltrate government databases. The first vector began with suspicious login activities in early May and ultimately granted access to the E-Contact messaging infrastructure.

This initial route relied on dozens of employee passwords that had been harvested over a three-month period. Investigators believe the credentials were captured using infostealers—malware designed to quietly harvest saved login details from web browsers and local systems—operating on unmanaged personal devices used by DGFIP staff outside of formal IT oversight.

French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

The perpetrator targeted internal portals named PIGP and ADER. At the time of the attack, these systems required nothing more than a standard username and password for authentication, allowing the stolen credentials to grant immediate access. PIGP functioned as an internal web portal utilized by DGFIP staff for email and human resources services, while ADER provided access to specialized DGFIP applications through the RIE, the secure network interconnecting French government ministries.

The attacker successfully leveraged compromised systems belonging to the Ministry of Education that were interconnected with the broader government network. Because sensitive DGFIP applications lacked proper network segmentation and isolation from the rest of the RIE, the intruder was able to traverse freely from less secure areas into highly sensitive environments. Digital forensics later uncovered extensive evidence indicating that the attacker had also probed for pathways into other government bodies connected to the shared network.

Although the accounts utilized by the attacker possessed no elevated administrative privileges, the lack of internal access controls allowed them to navigate unhindered to vast repositories of sensitive data. ANSSI noted that an evaluation of user privilege management fell outside the scope of its specific technical report.

The second primary entry route targeted land-registry records through APEX, a specialized portal utilized by external partners such as notaries and land surveyors. Unlike the internal staff portals, APEX required both a password and a one-time verification code delivered via email.

The DGFIP’s internal investigation determined that the computer of a land surveyor at a private firm had likely been compromised, enabling the attacker to intercept or bypass the secondary email verification codes. This vector allowed the extraction of land-registry data between July 27 and August 8. According to a Senate finance committee note published in September and reported by Public Sénat, this portion of the breach affected nearly 435,000 households.

Why Internal Monitoring Systems Failed to Catch the Theft

The DGFIP maintained standard protocols for handling compromised employee credentials. The agency’s Security Operations Center (SOC)—the internal team tasked with monitoring network traffic and identifying active threats—routinely reset passwords whenever a credential was flagged by threat intelligence providers or internal detection mechanisms.

While this routine occasionally disrupted the attacker’s activity, it consistently failed to halt the ongoing data theft. On June 7, unauthorized search queries executed via a compromised account triggered an alert, prompting a same-day password reset. However, the SOC failed to notice that the attacker had already transitioned from the PIGP portal to the ADER network.

A similar pattern emerged later in the month. On June 23, a threat intelligence provider flagged another account used by the attacker. Subsequent search queries opened a SOC ticket at 8:50 p.m. Paris time. Hours later, at 4:26 a.m. on June 24, the attacker began siphoning data from E-Contact via ADER using automated scraping tools designed to extract information page by page.

When the SOC finally processed the ticket at 10:40 a.m. that morning, staff reset the password to address the PIGP alert. Crucially, the intervention failed to terminate the attacker’s active session on the ADER network. As a result, data extraction continued unabated for nearly 16 additional hours, stopping only at 2:31 a.m. on June 25.

A similar oversight occurred in July. When the attacker resumed automated data harvesting on July 22 using a freshly compromised account, the SOC detected suspicious search patterns the following day and ordered a password reset on July 24.

French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

ANSSI concluded that the DGFIP’s SOC lacked proper monitoring of the ADER portal entirely. No automated correlation systems linked individual warning signs, such as nighttime login spikes, connections routed through commercial VPNs, or traffic originating from Indian IP addresses and known malicious endpoints. Furthermore, the sheer volume of data transferred—including an 11-gigabyte data transfer recorded between June 22 and June 25—failed to trigger automated volume-based security alarms.

The volume of individual requests generated by the automated scraping tools was likewise left unchecked, despite the reality that scraping inherently requires distinct requests for every page accessed. While isolated instances of such indicators frequently generate false positives, ANSSI emphasized that combining these warning signals should have immediately raised alarms.

ANSSI’s own national-level monitoring infrastructure also missed the unfolding extraction. The agency’s detection sensors are positioned exclusively at the entry and exit boundaries connecting the RIE network to the broader internet, and the agency lacks direct visibility into internal application logs. Because the attacker operated using legitimate staff credentials, perimeter network monitoring failed to flag the internal movement. Nevertheless, ANSSI noted that the cumulative volume of requests crossing the infrastructure should have been sufficient to warrant investigation.

Cross-agency communication channels also suffered from critical delays. On June 9, the Ministry of Education’s cybersecurity team notified peer institutions across the government about a security incident on its network, distributing 17 specific indicators of compromise and urging neighboring agencies to monitor connections originating from ministry IP addresses. The attacker had already utilized one of these addresses and repeated the tactic later in the month. ANSSI stressed that the time required to analyze and propagate such critical threat indicators across government departments must be drastically reduced in future incidents.

By August 6, ANSSI managed to forward two suspicious IP addresses to the DGFIP after reviewing historical sensor logs. The DGFIP promptly blocked the addresses and reset five associated accounts, yet neither agency recognized that a massive data theft had already taken place until the perpetrator publicly claimed responsibility on August 12.

Remediation Efforts and Future Security Recommendations

In the immediate aftermath of the incident, sweeping emergency measures were implemented across French government IT infrastructure. By the time the ANSSI report was finalized, DGFIP staff accounts had been entirely blocked from accessing the ADER portal as of August 13, and access to the PIGP portal was cut off on August 18. Officials indicated that neither portal is expected to be reopened to staff in its previous form.

The APEX portal was locked down, the compromised surveyor account was disabled on August 14, and all other accounts associated with the private surveying firm were deactivated four days later. These emergency shutdowns caused noticeable disruptions to various administrative services provided by the DGFIP and its external professional partners.

A comprehensive action plan has since been formulated to extend security monitoring across all DGFIP business applications, mandate robust multi-factor authentication, and enforce strict limits on the volume of data accessible to individual users. ANSSI noted that only a much broader, pre-planned audit will uncover the full scope of structural vulnerabilities lingering within the government’s digital architecture.

The E-Contact portal, which previously lacked a secondary verification step during login, is slated to receive multi-factor authentication alongside advanced detection tooling capable of spotting abnormal data access volumes, according to the Senate advisory note. Furthermore, policy changes implemented by the time of the Senate report completely prohibit staff from accessing sensitive DGFIP internal tools from personal, unmanaged devices.

Leave a Reply

Your email address will not be published. Required fields are marked *