GOVERNMENT BREACH

Stolen Passwords, No Alarms

How France's Tax Agency Lost Data on 600,000 Taxpayers and Businesses. An attacker used several dozen stolen staff passwords to take data from France's tax administration for seven weeks without being detected.

Matt Lucas  |  September 29, 2026  |  5 min
Editorial hero illustration
350,000+
individuals exposed
250,000+
businesses exposed
7 weeks
before public disclosure
~16 hours
data flow after password reset
TL;DR
  • What: An attacker used several dozen DGFIP staff passwords, probably stolen by infostealers, to scrape France's E-Contact taxpayer messaging tool in June and July without detection.
  • Impact: Tax and contact data on a little over 350,000 individuals and 250,000 businesses was exposed, plus land-registry data on nearly 435,000 households through a second route.
  • Fix / mitigation: ANSSI's audit points to weak login protection, poor network separation and monitoring gaps, including password-only portals and a SOC that never watched ADER.
  • Who's at risk: French taxpayers and businesses that used E-Contact, and any organization whose staff can reach internal portals with a password alone from devices it does not manage.

Several dozen stolen staff passwords, two portals that asked for nothing more, and a security operations center that reset the wrong door. That is how an attacker walked out of France's tax administration with data on a little over 350,000 individuals and a little over 250,000 businesses in June and July. Neither the DGFIP nor ANSSI, France's national cybersecurity agency, saw the data leave. The theft became known on August 12, when the attacker claimed it on an online forum, seven weeks after the first batch was taken.

The key line in ANSSI's report, published Tuesday, is its verdict: the attack was not sophisticated. That contradicts the ministry overseeing the DGFIP, which said in August that access checks had not revealed the theft "because of the sophistication of the attack." ANSSI, which Prime Minister Sébastien Lecornu asked for an in-depth audit, puts it down to weak login protection, poorly separated networks and gaps in monitoring. (Source: The Hacker News, reporting on the ANSSI report.)

What was taken

The data came from E-Contact, the tool taxpayers use to message the tax administration behind impots.gouv.fr. For individuals, the data that may have been viewed or copied includes tax ID, contact details, family situation, reference taxable income, tax withholding rate and a list of messages exchanged with the DGFIP. For fewer than 250 people, the messages themselves may also have been taken. For businesses it covers company name, SIREN registration number, address and basic message details. For fewer than 2,076 businesses, message content may have been seen. Taxpayers' own online accounts and passwords were not compromised.

A second route reached land-registry data through APEX, a portal for partners such as notaries and land surveyors that required a password and a one-time code sent by email. The DGFIP found that a land surveyor's computer at a private firm had possibly been compromised, which let the attacker bypass that code. That data was taken between July 27 and August 8 and concerns nearly 435,000 households, according to a September 4 Senate finance committee note reported by Public Sénat.

How the attacker got in

The reset that left the session open

On June 23 a threat intelligence provider flagged an account, and a SOC ticket opened at 8:50 p.m. Paris time. At 4:26 a.m. the attacker began scraping E-Contact through ADER. The SOC handled the ticket at 10:40 a.m. by resetting the password. That resolved the PIGP alert but did not end the attacker's open ADER session. Data kept flowing for almost 16 more hours, until 2:31 a.m. on June 25.

Why no one saw it

The DGFIP already had a routine for stolen logins: when the SOC detected a compromised account or a provider flagged one, it reset the password. That routine fired several times. On June 7, searches from a stolen account triggered an alert and a same-day reset, but the SOC missed the attacker's move from PIGP to ADER. In July it happened again. The attacker restarted automated extraction on July 22 with another stolen account. The SOC spotted suspicious searches the next day and reset the account on July 24.

The SOC was not monitoring ADER at all. Nothing linked the warning signs: night logins, VPN connections, addresses in India, addresses known to be malicious. The 11 GB exchanged between June 22 and 25 raised no alert. Per-user request counts were not checked, even though scraping takes one request per page. ANSSI acknowledges that each signal alone usually produces many false alarms, but says that together they could have raised an alert.

ANSSI's own monitoring missed the theft too. Its sensors sit only at the entry and exit points of the RIE and the internet, and it has no access to application logs. Because the traffic came from real staff accounts, it looked legitimate. The agency still says the total request volume should have raised alerts. On June 9, the Education ministry's security team sent 17 indicators of compromise to all ministries. The attacker had already used one of those addresses and used it again in late June.

The RedEye take

The DGFIP did not have a detection problem. It had a response problem. Its alerts fired at least three times across June and July, and each time the result was a password ticket instead of an intrusion investigation. A password reset is account housekeeping. It does not contain an intrusion. When nearly 14 hours pass between a ticket and a reset, and the reset leaves the live session running, the attacker decides how long the incident lasts.

The second lesson is about who controls the perimeter. Here it was set by machines the DGFIP did not own: staff personal devices carrying infostealers, a private surveyor's laptop, another ministry's network. The August claim of sophistication did not hold up against the audit. Public bodies that explain a breach before it has been investigated put their credibility at risk. The open question is the one ANSSI left out of scope: why accounts with no special privileges could reach this much data.

What defenders should learn

Questions about your exposure?

RedEye Security provides assessments for organizations that need to understand their real risk.

Talk to us