French Tax Agency Suffers Seven-Week Data Breach via Stolen Staff Credentials
Hundreds of thousands of French taxpayers and businesses had their data exfiltrated over seven weeks due to a breach at the national tax administration, exploiting stolen staff credentials and weak security controls.

France's tax administration, the DGFIP, has disclosed a significant data breach that saw sensitive information belonging to hundreds of thousands of individuals and businesses accessed and exfiltrated over a two-month period. The attack, which occurred in June and July, went undetected for seven weeks by both the tax agency and France's national cybersecurity authority, ANSSI. The breach exploited compromised staff credentials, highlighting critical weaknesses in the agency's security posture, including insufficient network segmentation and monitoring gaps.
The compromised data originated from E-Contact, a tool used by taxpayers to communicate with the DGFIP. For individuals, the stolen information includes tax identification numbers, contact details, family situations, taxable income, tax withholding rates, and potentially the content of messages exchanged with the tax authority. For businesses, the exfiltrated data encompasses company names, registration numbers, addresses, and message details, with a subset also having message content exposed. Notably, taxpayers' own online accounts and passwords remained secure, and the breach did not involve sophisticated exploitation techniques.
The attacker gained initial access through two primary routes. The first involved leveraging dozens of DGFIP staff passwords, likely stolen via infostealer malware from devices outside the agency's direct management. These credentials were used to access portals like PIGP (for email and HR) and ADER, which provided entry into the RIE, the network connecting French government ministries. The attacker exploited the fact that these portals required only a password, and sensitive DGFIP applications were not adequately isolated within the RIE, allowing unauthorized access from less secure network segments.
The second infiltration vector targeted land-registry data through the APEX portal, which typically requires a password and a one-time code. Investigators believe a land surveyor's computer at a private firm was compromised, enabling the attacker to bypass the two-factor authentication. This route led to the exfiltration of data concerning nearly 435,000 households between late July and early August.
The prolonged undetected period of the breach is attributed to significant gaps in the DGFIP's security monitoring. While the agency's Security Operations Center (SOC) did detect some suspicious activity and reset compromised accounts, it failed to identify the full scope of the attacker's movements, particularly the lateral movement from PIGP to ADER. Automated scraping tools used for data extraction continued to operate for extended periods even after alerts were triggered and accounts were reset, as the SOC was not monitoring the ADER system and did not correlate various warning signs like unusual login times, foreign IP addresses, or high data volumes.
ANSSI's own network monitoring also proved insufficient. Its sensors are primarily positioned at network entry and exit points, and the agency lacks access to application-level logs. Because the attacker utilized legitimate staff credentials, the network monitoring did not flag the activity as anomalous. Even the sheer volume of data transfers failed to trigger alerts, underscoring a critical lack of integrated threat detection and response capabilities within the DGFIP's security infrastructure.
The breach came to light on August 12 when the attacker claimed responsibility on an online forum, seven weeks after the initial data theft. This prompted Prime Minister Sébastien Lecornu to order a comprehensive audit by ANSSI. The incident has raised serious concerns about the security of sensitive government data and the effectiveness of existing cybersecurity measures within French public administration, particularly in light of the unsophisticated nature of the attack and the prolonged period of undetected compromise.