The theft of French tax information affecting hundreds of thousands of individuals and businesses is a particularly useful case study because investigators found no need for a zero-day, custom malware, or highly sophisticated exploitation chain. According to ANSSI’s investigation, the attacker relied largely on stolen staff credentials, weak authentication controls, insufficient network segmentation, and gaps in security monitoring to access and systematically extract data from systems belonging to France’s Directorate General of Public Finances, or DGFiP. The activity began in June and continued into July and August 2026, yet the theft itself was not recognized until the attacker publicly claimed responsibility on August 12.

The primary affected application was E-Contact, the system used for communications between taxpayers and the French tax administration. DGFiP says data relating to a little over 350,000 individuals and more than 250,000 businesses was involved in that part of the incident. For individuals, potentially accessed information included tax identifiers, identity and contact information, family situation, reference taxable income, withholding-tax rates, and lists of messages exchanged with the administration. For fewer than 250 people, the contents of those messages may also have been accessed. For businesses, exposed information included company names, SIREN registration numbers, addresses, and information about communications with DGFiP; the content of messages may have been viewed for fewer than 2,076 businesses.

The incident should not be confused with a compromise of taxpayers’ own accounts on impots.gouv.fr. France’s Ministry of Economy says the personal and professional online tax spaces themselves were not compromised, and taxpayers’ passwords were not part of the breach. The stolen identities belonged to public-sector staff, not the taxpayers whose information was later retrieved.

That distinction is important because it demonstrates a recurring enterprise-security problem: an attacker does not necessarily need the victim’s credentials if they can obtain the credentials of someone who is already authorized to view the victim’s information.

According to the ANSSI findings summarized by The Hacker News, several dozen DGFiP employee passwords had been stolen over roughly three months. Investigators believe many were probably harvested by information-stealing malware running on computers not managed by DGFiP, potentially employees’ personal devices. Two portals used by the attacker, PIGP and ADER, relied on password-only authentication, so possession of the stolen credential was enough to gain access.

That creates a very ordinary but dangerous attack chain:

personal or unmanaged endpoint infected by infostealer → employee password stolen → password-only government portal accessed → attacker reaches internal government network → sensitive application becomes reachable → legitimate staff identity used to query data → automated scraping extracts records

Nothing in that sequence requires breaking encryption or defeating a modern endpoint-security platform inside the tax authority itself.

The compromise begins somewhere else entirely.

This is why unmanaged endpoints can become part of an organization’s effective attack surface even when the organization does not own them. If an employee accesses corporate or government systems from a personal computer, malware on that device can steal authentication material that is subsequently used against the organization’s infrastructure.

ANSSI’s findings therefore reinforce the importance of device trust as well as identity trust. A valid username and password should not automatically establish that the device presenting them is trustworthy.

The situation was made worse by the architecture of France’s interministerial government network, known as the RIE. The attacker reportedly reached this network through compromised systems belonging to the Ministry of Education. Sensitive DGFiP applications were then accessible from areas of the government network that apparently had no operational need to reach them. Investigators also identified evidence of attempts to move toward other government entities.

This is an important segmentation failure.

Large government networks naturally provide connectivity between ministries and agencies, but connectivity should not imply transitive trust. A user who compromises one ministry should not automatically gain a useful network position from which to reach sensitive applications belonging to another.

Modern architecture should instead assume that one department, one endpoint, or one identity will eventually be compromised and limit what that compromise can reach.

The fact that the stolen DGFiP accounts reportedly did not hold unusual administrative privileges makes the incident even more instructive. Ordinary accounts still had enough access to retrieve large quantities of taxpayer information. That means privilege assessment should not focus exclusively on domain administrators or highly privileged technical accounts.

An ordinary application account capable of reading hundreds of thousands of records is highly privileged from a data-access perspective, even if it cannot administer a server.

This is where many organizations underestimate authorization risk.

Access may be technically legitimate while still being excessive in scale.

A tax employee may reasonably need to retrieve a taxpayer’s record.

It does not follow that the same identity should be able to retrieve hundreds of thousands of records without triggering additional controls.

That is why modern application security increasingly needs to enforce not just whether access is permitted, but also how much access is normal.

ANSSI’s investigation identified precisely this weakness. The attacker used automated scraping tools to retrieve data page by page, yet the number of requests, total records accessed, and quantity of data transferred did not trigger effective alerts. Between June 22 and June 25 alone, approximately 11 GB of data was exchanged, according to the report summarized by The Hacker News.

Eleven gigabytes moving through a sensitive government application under unusual circumstances is not necessarily malicious in isolation.

But that was not the only signal.

The activity also involved late-night logins, VPN connections, addresses associated with India, IP addresses already regarded as malicious, suspicious searches, stolen accounts, and unusually high request volumes. ANSSI’s criticism is essentially that the defensive systems looked at these indicators separately instead of correlating them into one incident.

This is one of the clearest lessons from the breach.

Modern security operations cannot function effectively as a collection of isolated alarms.

One strange login may be noise.

One unusual IP may be noise.

One large query may be noise.

One late-night session may be noise.

But:

stolen credential + VPN address + unusual geography + nighttime access + excessive queries + large data transfer

is no longer noise.

It is context.

The failure to correlate that context allowed the attacker to operate for weeks.

One incident on June 23 is especially revealing. A threat-intelligence provider flagged an account being used by the attacker, and suspicious searches generated a SOC ticket. The attacker then began extracting data from E-Contact through ADER early the following morning. The SOC later reset the employee’s password, but the attacker’s existing ADER session was not revoked. Data extraction reportedly continued for almost another 16 hours.

That is an extremely important identity-security lesson.

Password reset is not session revocation.

Modern web applications commonly issue access tokens, session cookies, or refresh tokens after authentication. Once those artifacts exist, changing the password may have no immediate effect on the active session.

An attacker can therefore remain logged in with a valid session even though administrators believe the compromised account has been secured.

This is why ANSSI specifically recommends revoking all active sessions across all applications and portals whenever a compromised password is reset.

That recommendation should apply far beyond government systems.

Whenever an account is believed to be compromised, incident response should normally include password reset, session revocation, refresh-token invalidation, OAuth review, device-session removal, API-token review, and retrospective analysis of what the identity did after the estimated compromise time.

Resetting the password and closing the ticket is no longer enough.

The monitoring gap around ADER was equally consequential. DGFiP’s SOC was apparently monitoring suspicious activity through PIGP, but not the attacker’s activity once it moved into ADER. This created a visibility discontinuity in which one part of the identity journey generated alerts while another part effectively disappeared from security monitoring.

Attackers naturally exploit such gaps.

Security monitoring should follow the identity across the entire authentication and application chain, not end when the user transitions from one portal to another.

Centralized SIEM integration is therefore critical. Authentication events, application queries, network telemetry, data-access volume, session creation, session continuation, and administrative actions should be correlated under the same identity.

ANSSI itself also had visibility limitations. Its network sensors monitored traffic around entry and exit points of the RIE and Internet connectivity but did not have access to detailed application logs. Because the attacker was using valid staff accounts, much of the traffic looked legitimate at the network level.

This demonstrates the limitations of perimeter-centric monitoring.

Network sensors can identify unusual destinations, traffic volumes, or malicious infrastructure, but they may not know that one authenticated user has suddenly accessed 50,000 taxpayer records.

Application telemetry provides that context.

For sensitive systems, security teams need both.

The attack also demonstrates why MFA implementation matters, not merely MFA presence. The second intrusion route targeted land-registry information through another portal, APEX, which required a password and a one-time code sent by email. Investigators believe the computer of a land surveyor at a private firm may have been compromised, potentially giving the attacker access to both the password and the email account receiving the OTP.

This is technically MFA, but the two factors can collapse into one compromise domain if both are accessible from the same infected endpoint.

If malware steals the primary credential and controls the mailbox receiving the second factor, the attacker effectively has both.

ANSSI consequently recommends stronger authentication using factors that remain independent when a password is stolen, such as authenticator applications or hardware tokens, preferably on a separate device.

Phishing-resistant authentication such as FIDO2 security keys or passkeys can go further by binding authentication to the legitimate service and reducing the value of stolen passwords.

For highly sensitive government systems, this should increasingly be the standard rather than the exception.

The land-registry incident also highlights third-party access risk. Government systems frequently need to provide access to notaries, surveyors, contractors, legal professionals, and other external organizations. Those partner environments may not have the same endpoint-security maturity as the government agency they connect to.

An attacker who cannot compromise the government directly may therefore target the weakest trusted partner.

Zero-trust architecture exists precisely for this reason.

Partner access should be narrowly scoped, independently authenticated, restricted to the records necessary for the partner’s function, and continuously monitored rather than trusted because the connection originates from an approved organization.

The scale of the cadastral exposure appears significant. The Senate finance committee reportedly estimated that the land-registry theft affected nearly 435,000 households, with data extracted between July 27 and August 8.

This is separate from the E-Contact dataset and should not simply be added together without accounting for possible overlap between individuals.

The French data-protection authority CNIL says the broader incidents involved tax information such as reference income, family quotient, withholding-tax rates, corporate SIREN information, and cadastral information such as property addresses and surface areas. It has opened oversight activity around the breaches and may investigate whether security measures met applicable requirements under French and European data-protection law.

The downstream fraud risk is substantial even though taxpayer passwords and banking credentials were not directly exposed in this particular DGFiP incident.

Tax identifiers, family status, taxable income, withholding rates, property information, phone numbers, addresses, and official communication history provide criminals with unusually credible material for targeted impersonation.

France’s Ministry of Economy specifically warns that exposed information may be used in phishing, fraudulent phone calls, fake adviser schemes, executive impersonation, and identity-fraud attempts.

This means affected taxpayers may receive scams that contain accurate information.

A caller may know their tax status.

A phishing email may reference their income bracket or withholding rate.

A criminal may know that they recently communicated with the tax authority.

That accuracy should not be interpreted as proof that the caller or message is legitimate.

This is one of the most damaging consequences of government-data breaches: stolen official data can be weaponized to make fraudulent communications look authoritative.

The breach also illustrates the long-tail consequences of infostealer malware.

A password may be stolen from an employee’s personal computer months before it is actually used.

The malware infection can disappear.

The attacker still retains the credential.

Those credentials may be aggregated into stealer logs, sold to access brokers, searched by criminal groups, and reused much later.

Organizations therefore need external credential-exposure monitoring alongside traditional internal SOC visibility.

When employee credentials appear in stealer datasets, the response should not merely be to change that single password. Security teams should identify which other accounts may have used the same credentials, whether the compromised endpoint stored browser sessions or VPN credentials, and whether any access occurred before the reset.

The incident is also a useful reminder that government networks are ecosystems, not single systems.

The attacker moved through employee credentials, PIGP, ADER, the RIE, Education Ministry infrastructure, DGFiP applications, partner portals, and private-sector endpoints.

The security failure did not exist entirely inside one application.

It existed in the assumptions between systems.

That makes architectural security far more important than isolated controls.

The eventual remediation measures reflect this. DGFiP reportedly shut staff access to ADER and PIGP while controls were reviewed, locked down APEX, disabled compromised accounts, and developed plans to extend monitoring across business applications, deploy stronger authentication, establish limits on accessible data volumes, and prevent access from personal devices.

ANSSI also recommends quotas or thresholds for records accessed, requests generated, and data transferred over defined periods. That is particularly valuable for systems such as tax databases because legitimate users often have predictable access patterns.

A staff member viewing 20 records may be normal.

A staff member viewing 200,000 records at 3 a.m. through a VPN should not require an attacker to publish a forum post seven weeks later before somebody becomes curious.

The broader cybersecurity lesson is that this incident was fundamentally an identity-and-observability failure.

The attacker used legitimate usernames.

Legitimate passwords.

Legitimate government portals.

Legitimate application functionality.

And legitimate data-query mechanisms.

From the application’s perspective, many requests were authorized.

From a security perspective, the behavior was clearly abnormal.

That is exactly why modern defenses cannot rely entirely on binary checks such as:

“Did the password match?”

Security also needs to ask:

Is this the expected device? Is MFA present? Is this location normal? Is this session still trusted? Is this application usually accessed from here? Is this amount of data reasonable? Is this identity suddenly behaving unlike itself?

The attack path can be summarized as:

infostealer compromises unmanaged device → government employee password stolen → password-only portal accessed → interministerial network reached → insufficient segmentation exposes sensitive DGFiP application → automated scraping extracts taxpayer data → SOC detects individual account anomalies but does not correlate them → password resets fail to kill active sessions → extraction continues → attack remains undetected until public claim

There is no exotic malware in that sequence.

No zero-day is required.

No advanced persistence framework is essential.

The attacker mainly succeeds because systems continue trusting credentials after the human behind those credentials is no longer the person using them.

That may be the most important lesson from the French tax breach.

A valid credential proves that somebody possesses the credential. It does not prove who that somebody is.

And when hundreds of thousands of sensitive government records sit behind that distinction, password-only trust becomes a very expensive assumption.


An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency saw the data leave. The attack was not sophisticated, the agency, ANSSI, says in a report (in French) published on Tuesday: it worked because of weak

Source: French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks via The Hacker News — published 29 Sep 2026.