Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

French tax data breach went unnoticed for 7 weeks, until the hacker claimed it online

France's cyber agency says the attacker simply logged in with stolen staff passwords, and neither the tax agency nor ANSSI caught the theft before it was claimed.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1ANSSI says data on about 353,000 individuals and 252,000 professionals left France's tax agency seven weeks before anyone knew.
  • 2The attacker used several dozen staff passwords, probably stolen by infostealer malware on computers the agency did not manage.
  • 3ANSSI blames weak authentication and gaps in monitoring, not a sophisticated attack, and calls for MFA on every application.

The news

A French tax data breach that exposed records on about 353,000 individuals and 252,000 professionals went undetected for seven weeks, France's cyber agency ANSSI said on September 23. The attacker used stolen staff passwords; the theft surfaced only when the attacker claimed it.

On August 12, an actor calling itself Zerobytes claimed on an online forum to have stolen data from impots.gouv.fr, the site run by the Direction générale des Finances publiques (DGFiP), France's tax administration. ANSSI alerted the agency that afternoon. The data came from E-Contact, the messaging tool taxpayers use to write to the agency, and investigators found the main extraction had taken place on June 24 and 25, after several weeks of exploring DGFiP systems.

ANSSI found no attempt to guess passwords: the attacker already had them. Over three months it collected several dozen passwords belonging to DGFiP staff, probably stolen by infostealers, malware that harvests saved logins, on computers the agency did not manage. Two portals, including ADER, a gateway to internal applications, asked only for a password. The attacker reached ADER through the government's shared network, using a foothold in compromised Education Ministry systems.

DGFiP's security operations center did react, but not enough. On June 24 it reset the password of an account flagged for suspicious searches, yet the reset did not end the attacker's open session, and data kept flowing until 2:31 a.m. on June 25. ANSSI found the center was not monitoring ADER at all. The attacker returned for a second wave of extraction on July 22.

A second claim followed on August 13, covering land registry data. DGFiP traced it to the account of a surveyor at a private firm; the probable compromise of the surveyor's computer let the attacker get past a one-time code sent by email on APEX, a portal for partners such as notaries. Access and theft ran from July 27 to August 8, ANSSI said.

ANSSI concluded the breach was not the result of a sophisticated attack but of weaknesses in identity, network design and detection. The Hacker News reported that the Economy Ministry had cited the attack's sophistication in August, and that the stolen taxpayer data included tax IDs, contact details, family situation, taxable income and withholding rates. Cutting staff and partner access to the portals caused significant disruption to DGFiP services, ANSSI said.

The numbers

Individuals in the E-Contact data (ANSSI)
About 353,000
Professionals in the E-Contact data (ANSSI)
About 252,000
Time between main extraction and discovery
7 weeks
Staff credentials stolen over three months (ANSSI)
Several dozen
Land registry access and theft window (ANSSI)
July 27 to August 8, 2026

Why CEOs should care

CISOs can take ANSSI's fixes almost word for word. Put multifactor authentication on every application, and choose a second factor that survives a stolen password: ANSSI warns that a code sent by email is weak if the mailbox opens with a password alone, and recommends hardware tokens or authenticator apps on a separate device. Make every password reset revoke active sessions everywhere. Feed every business application into your security monitoring, with limits on how many records or requests one account can pull in a set period. And bar personal devices from work systems, since that is where ANSSI believes the passwords leaked.

Chief operating officers and CFOs should look at the partner door and the cost of shutting it. One surveyor's probably compromised computer opened the land registry. Ask which outside firms log in to your systems, what second factor they use and from which devices. Budget for these controls now: DGFiP's emergency cutoff of staff and partner access caused significant disruption to its services, a cost that preventive controls would have avoided.

Boards should treat "sophisticated attack" as a claim to be tested, not an explanation. In this case the country's own cyber agency concluded the opposite. Ask management for plain root causes after any incident, and ask whether your threat intelligence service would catch every stolen employee password. ANSSI called DGFiP's feed a useful safety net that could not by itself cut the risk enough.

The bigger picture

Infostealers turn one employee's infected home computer into a key to company systems, and ANSSI found no sign of brute-force guessing: the attacker simply logged in. The case also shows how shared networks spread risk. An intrusion at the Education Ministry gave the attacker a route into the tax agency, a pattern that also applies to companies whose subsidiaries or acquisitions share one network.

What’s next

ANSSI says a full audit of the affected systems is planned, and DGFiP says staff access to ADER and the PIGP portal will not reopen. Watch for the audit's findings, for how quickly MFA reaches every DGFiP application, and for any action by France's data protection regulator, CNIL.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

DGFiPANSSIFranceData breachInfostealers

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.