Skip to main content
Emerging ThreatsData Breaches

French Tax Authority Breach Exposes Data of 600,000 Taxpayers

Interior of French government office with computer workstations and employees.

The stolen data covers a little over 350,000 individuals and a little over 250,000 businesses, the DGFIP says.

Route 1: PIGP, ADER and the RIE — simple credentials, wide access

ANSSI’s report describes a low‑sophistication intrusion that leveraged dozens of DGFIP staff passwords stolen over three months. Those credentials were probably harvested by infostealers from staff devices that the tax administration did not manage. Two portals the attacker used — PIGP (staff email and HR services) and ADER (access to DGFIP applications via the RIE network) — required only a password, so stolen logins worked immediately.

The attacker reached the RIE through compromised systems in the Education ministry. Sensitive DGFIP applications were not isolated from the rest of the RIE, meaning ordinary staff accounts could reach large amounts of data despite having no special privileges. Investigators also found traces of attempts to move laterally into other government bodies on the same network.

Route 2: APEX and land‑registry data — one‑time codes bypassed

A second route targeted land‑registry records via APEX, a portal for partners such as notaries and land surveyors. APEX used a password plus a one‑time code sent by email, but the DGFIP’s investigation found that a private land surveyor’s computer had possibly been compromised, allowing the attacker to bypass that code. The land‑registry extraction occurred between July 27 and August 8 and, according to a Senate finance committee note reported by Public Sénat, concerned nearly 435,000 households.

Why the SOC and ANSSI did not spot the theft

Detection failures were procedural and architectural rather than the result of a novel malware strain, ANSSI concludes. The DGFIP SOC had routines for compromised logins — resetting passwords when accounts were flagged — and those routines blocked some activity. But resets did not terminate attacker sessions, and the SOC was not monitoring ADER at all.

Specific incidents show how the gaps unfolded: on June 7 a stolen‑account search triggered an alert and a same‑day reset, but the SOC missed lateral movement from PIGP to ADER. On June 23 a provider flagged another account and the SOC opened a ticket at 20:50; at 04:26 the next day the attacker began automated scraping via ADER. The SOC reset the account at 10:40 but did not terminate the attacker’s open session, and data continued to flow until 02:31 on June 25. Between June 22 and 25 the attacker exchanged about 11 GB of data without raising alarms.

ANSSI’s network sensors sat only at RIE and internet ingress/egress, and the agency had no access to application logs. Because the attacker used valid staff accounts, network monitoring largely treated the connections as legitimate. Even so, ANSSI says the total request volumes and other signals should have triggered alerts if they had been correlated; the DGFIP did not link warning signs such as night logins, VPN usage, or known‑malicious source addresses into a unified detection picture.

What was taken: E‑Contact messages, tax identifiers and business records

The data exfiltrated came mainly from E‑Contact, the message tool taxpayers use to communicate with the DGFIP. For individuals, the files that may have been viewed or copied include tax ID, contact details, family situation, reference taxable income, tax withholding rate and lists of exchanged messages; for fewer than 250 people the messages themselves may have been taken. For businesses the stolen fields include company name, SIREN number, address and basic message details; for fewer than 2,076 businesses the content of messages may have been seen.

The theft became public on August 12, when an attacker claimed responsibility on an online forum — seven weeks after the first data batch was taken. Prime Minister Sébastien Lecornu then asked ANSSI for an in‑depth audit; earlier in August the ministry overseeing the DGFIP had described the incident as undetected “because of the sophistication of the attack” (translated).

What has changed and ANSSI’s recommendations

By the time ANSSI’s report was written, DGFIP staff accounts had been cut off from ADER since August 13 and from PIGP since August 18, and APEX had been locked with the surveyor’s account disabled on August 14; the firm’s other accounts were disabled four days later. Those disruptions “significantly disrupted some DGFIP services and partner organizations,” the report notes. The DGFIP also drew up an action plan to extend monitoring to all business applications, implement stronger authentication and set limits on data access. E‑Contact will gain a second login step, tools to detect unusual data volumes will be deployed, and staff are no longer allowed to reach DGFIP tools from personal devices, according to the Senate note.

ANSSI’s formal recommendations include:

  • Revoke every active session, on all applications and portals, whenever a password is reset.
  • When an account is reported as compromised, check what it did from the likely date of compromise.
  • Use multi‑factor authentication (MFA) on every application, with a second factor that still protects the account if the password is stolen; a one‑time code sent by email is not enough if the same password opens the mailbox. Hardware tokens or authenticator apps, ideally on a separate device, are preferred.
  • Monitor every business application in a SIEM, and set quotas on the records accessed, requests made and data exchanged over a given period.
  • Do not allow personal devices to access work resources.

What this means for technologists, policymakers, and partner organizations

Technologists and security teams must assume that stolen legitimate credentials will be used and that session termination, per‑application monitoring and cross‑signal correlation are essential — not optional. Policymakers and regulators who oversee networks like the RIE will see ANSSI’s audit request and recommendations as the basis for compulsory changes to segmentation and logging. Partner organizations — notaries, land surveyors and the private firms that connect through APEX — should expect greater access controls and possible service interruptions while compromised accounts and endpoint security are remediated.

The facts in ANSSI’s report point to a familiar but stubborn lesson: simple credentials plus insufficient monitoring can open highly sensitive systems to large exposures. The DGFIP has since closed the immediate doors the attacker used and begun structural fixes, but ANSSI notes a fuller audit is already planned to identify all exploitable weaknesses — a task whose conclusions will determine how quickly public trust and operational continuity are restored.

Original story