The news
A French tax data breach that exposed records on about 353,000 individuals and 252,000 professionals went undetected for seven weeks, France's cyber agency ANSSI said on September 23. The attacker used stolen staff passwords; the theft surfaced only when the attacker claimed it.
On August 12, an actor calling itself Zerobytes claimed on an online forum to have stolen data from impots.gouv.fr, the site run by the Direction générale des Finances publiques (DGFiP), France's tax administration. ANSSI alerted the agency that afternoon. The data came from E-Contact, the messaging tool taxpayers use to write to the agency, and investigators found the main extraction had taken place on June 24 and 25, after several weeks of exploring DGFiP systems.
ANSSI found no attempt to guess passwords: the attacker already had them. Over three months it collected several dozen passwords belonging to DGFiP staff, probably stolen by infostealers, malware that harvests saved logins, on computers the agency did not manage. Two portals, including ADER, a gateway to internal applications, asked only for a password. The attacker reached ADER through the government's shared network, using a foothold in compromised Education Ministry systems.
DGFiP's security operations center did react, but not enough. On June 24 it reset the password of an account flagged for suspicious searches, yet the reset did not end the attacker's open session, and data kept flowing until 2:31 a.m. on June 25. ANSSI found the center was not monitoring ADER at all. The attacker returned for a second wave of extraction on July 22.
A second claim followed on August 13, covering land registry data. DGFiP traced it to the account of a surveyor at a private firm; the probable compromise of the surveyor's computer let the attacker get past a one-time code sent by email on APEX, a portal for partners such as notaries. Access and theft ran from July 27 to August 8, ANSSI said.
ANSSI concluded the breach was not the result of a sophisticated attack but of weaknesses in identity, network design and detection. The Hacker News reported that the Economy Ministry had cited the attack's sophistication in August, and that the stolen taxpayer data included tax IDs, contact details, family situation, taxable income and withholding rates. Cutting staff and partner access to the portals caused significant disruption to DGFiP services, ANSSI said.
The numbers
- Individuals in the E-Contact data (ANSSI)
- About 353,000
- Professionals in the E-Contact data (ANSSI)
- About 252,000
- Time between main extraction and discovery
- 7 weeks
- Staff credentials stolen over three months (ANSSI)
- Several dozen
- Land registry access and theft window (ANSSI)
- July 27 to August 8, 2026
Why CEOs should care
CISOs can take ANSSI's fixes almost word for word. Put multifactor authentication on every application, and choose a second factor that survives a stolen password: ANSSI warns that a code sent by email is weak if the mailbox opens with a password alone, and recommends hardware tokens or authenticator apps on a separate device. Make every password reset revoke active sessions everywhere. Feed every business application into your security monitoring, with limits on how many records or requests one account can pull in a set period. And bar personal devices from work systems, since that is where ANSSI believes the passwords leaked.
Chief operating officers and CFOs should look at the partner door and the cost of shutting it. One surveyor's probably compromised computer opened the land registry. Ask which outside firms log in to your systems, what second factor they use and from which devices. Budget for these controls now: DGFiP's emergency cutoff of staff and partner access caused significant disruption to its services, a cost that preventive controls would have avoided.
Boards should treat "sophisticated attack" as a claim to be tested, not an explanation. In this case the country's own cyber agency concluded the opposite. Ask management for plain root causes after any incident, and ask whether your threat intelligence service would catch every stolen employee password. ANSSI called DGFiP's feed a useful safety net that could not by itself cut the risk enough.
The bigger picture
Infostealers turn one employee's infected home computer into a key to company systems, and ANSSI found no sign of brute-force guessing: the attacker simply logged in. The case also shows how shared networks spread risk. An intrusion at the Education Ministry gave the attacker a route into the tax agency, a pattern that also applies to companies whose subsidiaries or acquisitions share one network.
What’s next
ANSSI says a full audit of the affected systems is planned, and DGFiP says staff access to ADER and the PIGP portal will not reopen. Watch for the audit's findings, for how quickly MFA reaches every DGFiP application, and for any action by France's data protection regulator, CNIL.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error





