Full Report
An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency saw the data leave. The attack was not sophisticated, the agency, ANSSI, says in a report (in French) published on Tuesday: it worked because of weak
Analysis Summary
# Incident Report: French Tax Administration (DGFIP) Data Theft
## Executive Summary
A non-sophisticated attacker utilized stolen staff credentials to infiltrate the French tax administration (DGFIP) systems, remaining undetected for seven weeks. The breach resulted in the theft of tax data belonging to over 350,000 individuals and 250,000 businesses. The incident was only discovered after the threat actor advertised the stolen data on an online forum.
## Incident Details
- **Discovery Date:** August 12, 2026
- **Incident Date:** June – August 2026
- **Affected Organization:** Direction Générale des Finances Publiques (DGFIP)
- **Sector:** Government / Public Sector
- **Geography:** France
## Timeline of Events
### Initial Access
- **Date/Time:** Early May 2026 (Initial suspicious logins)
- **Vector:** Stolen staff credentials (likely via infostealer malware)
- **Details:** Credentials for DGFIP staff were harvested from unmanaged personal devices and used to access the PIGP and ADER portals.
### Lateral Movement
- **Movement:** The attacker accessed the Interministerial State Network (RIE) via compromised Ministry of Education systems. Lack of network segmentation allowed the attacker to reach sensitive DGFIP applications (E-Contact) from unauthorized network segments.
### Data Exfiltration/Impact
- **Data Stolen:** Tax IDs, contact details, taxable income, and tax withholding rates for ~350,000 individuals; registration numbers and message metadata for ~250,000 businesses.
- **Land Registry:** Between July 27 and August 8, data for 435,000 households was accessed via the APEX portal.
### Detection & Response
- **Discovery:** Detected on August 12, 2026, via external threat intelligence (attacker post on a dark web forum).
- **Response Actions:** Investigation launched by ANSSI; audit requested by the Prime Minister; password resets for compromised accounts.
## Attack Methodology
- **Initial Access:** Valid accounts (Stolen credentials).
- **Persistence:** Utilization of multiple legitimate portals (PIGP, ADER, APEX).
- **Privilege Escalation:** Not required; standard user accounts had excessive access to broad datasets.
- **Defense Evasion:** Use of legitimate credentials and gaps in DGFIP’s monitoring/SOC visibility.
- **Credential Access:** Infostealer malware on unmanaged personal staff devices.
- **Discovery:** Exploitation of poorly separated networks (RIE).
- **Lateral Movement:** Pivot from Education Ministry systems to DGFIP applications via the RIE.
- **Collection:** Gathering data from the E-Contact messaging tool and land registry (APEX).
- **Exfiltration:** Data taken over a seven-week period without triggering egress alerts.
- **Impact:** Massive data breach of sensitive fiscal information.
## Impact Assessment
- **Financial:** Potential for long-term fraud and identity theft costs.
- **Data Breach:** Compromise of ~600,000 entities (350k citizens, 250k businesses) plus 435,000 land registry records.
- **Operational:** Significant audit and remediation resources required from ANSSI and DGFIP.
- **Reputational:** High; public contradiction between initial claims of "sophistication" and ANSSI’s findings of "weak protection."
## Indicators of Compromise
- **Network indicators:** Logins from non-standard locations/IPs (defanged: [h]ttps[:]//impots[.]gouv[.]fr).
- **Behavioral indicators:** Suspicious access to the E-Contact tool and APEX portal by accounts with no business need for such data; lateral movement from the Education Ministry to Tax applications.
## Response Actions
- **Containment:** Password resets for identified compromised accounts.
- **Eradication:** Investigation into the compromise of external partner computers (land surveyors).
- **Recovery:** Implementation of an in-depth security audit by ANSSI.
## Lessons Learned
- **Credential Vulnerability:** Single-factor authentication (SFA) on government portals is insufficient against modern infostealers.
- **Network Flatness:** The lack of segmentation between different government ministries on the RIE allowed for easy lateral movement.
- **Monitoring Gaps:** The SOC routine was reactive rather than proactive, failing to identify anomalous data volumes leaving the network.
## Recommendations
- **Enforce MFA:** Mandate Multi-Factor Authentication for all portals (PIGP, ADER, APEX), ideally using hardware tokens.
- **Zero Trust Architecture:** Implement strict network segmentation to ensure sensitive tax applications are not reachable from the general interministerial network.
- **Endpoint Security:** Prohibit the use of unmanaged personal devices for accessing professional portals or implement strict Conditional Access policies.
- **Data Loss Prevention (DLP):** Deploy monitoring tools to alert on unusual volumes of data exfiltration.