Full Report
Stolen details range from contact information to household finances and withholding rates
Analysis Summary
# Incident Report: Breach of French General Directorate of Public Finances (DGFiP)
## Executive Summary
The French tax authority (DGFiP) confirmed a data breach affecting approximately 600,000 individuals and businesses. An external threat actor, "ZeroBytes," claimed responsibility for accessing sensitive tax records, household financial data, and private communications. The authority has since suspended specific portals and initiated a mass notification campaign to warn of follow-on phishing risks.
## Incident Details
- **Discovery Date:** Week of August 10, 2026 (Confirmed by DGFiP "last week")
- **Incident Date:** Circa August 2026
- **Affected Organization:** Direction générale des Finances publiques (DGFiP)
- **Sector:** Government / Public Sector
- **Geography:** France
## Timeline of Events
### Initial Access
- **Date/Time:** August 2026
- **Vector:** Exploitation of a "technical vulnerability."
- **Details:** Attackers exploited a flaw in the government’s Vacant Successions Portal (PSV) and likely other interfaces to gain unauthorized access to the DGFiP information system.
### Lateral Movement
- **Details:** The threat actor moved from initial entry points to databases containing taxpayer records and internal messaging logs.
### Data Exfiltration/Impact
- **Data Stolen:** Tax identification numbers, marital status, contact details, household composition, tax income, withholding rates, and SIREN numbers for 250,000 businesses.
- **Sensitive Content:** For 250 individuals, the actual content of private messages exchanged with the tax authority was exfiltrated.
### Detection & Response
- **Detection:** Discovered following claims made by a threat actor named "ZeroBytes."
- **Response:** DGFiP suspended the Vacant Successions Portal (PSV) and began a forensic investigation. Notification emails/letters were sent to roughly 600,000 affected parties.
## Attack Methodology
- **Initial Access:** Exploitation of a technical vulnerability in public-facing portals (e.g., PSV).
- **Persistence:** Not explicitly disclosed; likely session or credential-based.
- **Defense Evasion:** Not detailed, though the investigation into the PSV portal vulnerability suggests the attackers bypassed standard authentication/authorization checks.
- **Collection:** Automated scraping or database querying of taxpayer records and messaging logs.
- **Exfiltration:** Large-scale transfer of records and PII (600k+ entities).
- **Impact:** Massive data breach and exposure of private citizen-state communications.
## Impact Assessment
- **Financial:** High potential for secondary fraud (CEO fraud, bank scams).
- **Data Breach:** ~600,000 entities; includes PII, financial status, and private correspondence.
- **Operational:** Suspension of the Vacant Successions Portal; diversion of resources to incident response.
- **Reputational:** Significant; follows a series of high-profile French public sector breaches (1.2M at Finance Ministry, 15.8M at Health Ministry).
## Indicators of Compromise
- **Network indicators:** hxxps[://]www[.]impots[.]gouv[.]fr/actualite/acces-illegitimes-au-systeme-dinformation-de-la-dgfip (Official advisory link)
- **File indicators:** Not disclosed in the report.
- **Behavioral indicators:** Unauthorized access to the PSV portal; unusual data export volumes from the taxpayer messaging system.
## Response Actions
- **Containment:** Suspension of the Vacant Successions Portal (PSV) to prevent further exploitation.
- **Eradication:** Investigation into the technical vulnerability to apply patches.
- **Recovery:** Restoration of services pending security audits; notification of all affected individuals via secure mail and post.
## Lessons Learned
- **Vulnerability Management:** Vulnerabilities in niche portals (like Vacant Successions) can serve as gateways to broader, more sensitive datasets.
- **Communication Security:** Storing private citizen-to-government messages in a format accessible via web-facing vulnerabilities poses a high privacy risk.
- **Sector-wide Risk:** The French public sector is currently a high-priority target for cybercriminals, requiring heightened vigilance.
## Recommendations
- **Zero Trust Architecture:** Implement stricter segmentation between public search portals and sensitive taxpayer databases.
- **Encryption at Rest:** Ensure that private correspondence and sensitive tax files are encrypted such that a system-level breach does not lead to clear-text exposure.
- **Phishing Education:** Given the specificity of the stolen data (withholding rates, family quotient), citizens must be warned that future phishing attempts will be highly personalized and convincing.