France Tax Authority Breach Exposes Data of More Than 600,000 Taxpayers and Businesses

France's national cybersecurity agency, ANSSI, has disclosed details of a cyberattack against the country's tax administration that exposed data belonging to more than 350,000 individuals and 250,000 businesses.

The attacker used stolen passwords belonging to tax administration staff to access internal systems and extract taxpayer information between June and July 2026.

ANSSI said the attack was not technically sophisticated. Instead, the compromise succeeded because of weaknesses in authentication, network segmentation, session management, and security monitoring.

Taxpayer Data Exposed

The affected system was E-Contact, a service used by taxpayers to communicate with France's tax administration, known as the DGFIP.

For individuals, potentially exposed information included:

  • Tax identification number
  • Contact information
  • Family situation
  • Reference taxable income
  • Tax withholding rate
  • List of messages exchanged with the DGFIP

For fewer than 250 individuals, the contents of those messages may also have been accessed.

For businesses, exposed information included:

  • Company name
  • SIREN registration number
  • Address
  • Basic information about messages exchanged with the DGFIP

For fewer than 2,076 businesses, the contents of those messages may also have been accessed.

The DGFIP said taxpayers' own online accounts and passwords were not compromised.

Stolen Staff Passwords Used to Enter Internal Systems

According to ANSSI, the main intrusion began with several dozen DGFIP employee passwords that had been stolen over approximately three months.

Investigators believe the credentials were likely obtained through infostealer malware running on computers that were not managed by the DGFIP, potentially including employees' personal devices.

Two internal portals, PIGP and ADER, accepted password-only authentication.

PIGP provided access to email and human resources services, while ADER provided access to certain DGFIP applications through the French government's interministerial network.

The attacker was able to reach the government network through compromised Education Ministry systems connected to the same infrastructure.

Weak Network Segmentation Expanded Access

ANSSI found that sensitive DGFIP applications were insufficiently separated from other parts of the government network.

As a result, the attacker could reach systems that did not appear to require access from the compromised network segment.

Investigators also found evidence of attempts to move into other government organizations connected to the network.

The compromised accounts did not have special administrative privileges, but they nevertheless provided access to a significant amount of data.

Second Attack Path Targeted Land Registry Data

A separate intrusion path targeted land-registry information through APEX, a portal used by external partners such as notaries and land surveyors.

APEX required a password and a one-time code delivered through email.

DGFIP investigators determined that a land surveyor's computer at a private company may have been compromised, allowing the attacker to bypass the additional authentication step.

Data was accessed between July 27 and August 8.

A Senate finance committee note said the incident affected information associated with nearly 435,000 households.

Security Monitoring Failed to Detect the Data Theft

The DGFIP already had procedures for dealing with compromised employee accounts.

Its Security Operations Center would reset passwords when suspicious activity was detected or when external threat intelligence providers reported compromised credentials.

However, those controls did not stop the attack.

On June 7, activity involving a stolen account triggered an alert and the password was reset. The security team did not identify that the attacker had moved from PIGP to ADER.

On June 23, another compromised account generated an alert. The attacker began automatically extracting information from E-Contact through ADER several hours later.

The SOC reset the account the following morning, but the existing ADER session remained active.

As a result, the attacker continued extracting data for almost 16 additional hours, until June 25.

Automated Scraping Went Undetected

The attacker used automated tools to retrieve E-Contact information page by page.

The DGFIP's SOC was not monitoring ADER directly, and its monitoring systems did not correlate several suspicious indicators.

These included:

  • Night-time logins
  • VPN connections
  • Connections from Indian IP addresses
  • Connections from known malicious addresses
  • Large numbers of requests
  • Large volumes of exchanged data

Approximately 11 GB of data was exchanged between June 22 and June 25 without triggering an alert.

The number of requests made by individual accounts was also not monitored.

ANSSI said that while individual indicators could produce false positives, their combination could have identified the attack.

Network Monitoring Also Missed the Activity

ANSSI's own monitoring infrastructure did not detect the data theft.

Its sensors were positioned at the entry and exit points of the government network and the internet, but ANSSI did not have access to the application-level logs needed to identify the activity.

Because the attacker was using legitimate employee credentials, the network traffic did not immediately appear malicious.

ANSSI said the overall request volume should nevertheless have generated an alert.

The Education Ministry's security team had also previously shared indicators of compromise with government security teams following an incident on its network.

One of the addresses involved in that warning was later reused by the attacker.

Breach Discovered After Attacker Claimed Theft

The stolen data was first publicly linked to the incident on August 12, when the attacker claimed the theft on an online forum.

This occurred approximately seven weeks after the first batch of data was extracted.

The incident prompted Prime Minister Sébastien Lecornu to request an in-depth ANSSI investigation.

The DGFIP subsequently restricted access to several systems involved in the attacks.

Security Changes Implemented

The DGFIP disabled staff access to ADER beginning August 13 and PIGP beginning August 18.

The APEX portal was locked on August 14, and the affected surveyor account was disabled.

The DGFIP has also developed an action plan covering:

  • Stronger authentication
  • Broader security monitoring
  • Limits on accessible data
  • Detection of unusual data access volumes
  • Additional protection for business applications
  • Restrictions on access from personal devices

E-Contact, which previously did not require a second authentication factor, is also planned to receive stronger authentication.

ANSSI Recommendations

ANSSI recommended several security improvements following the investigation:

  • Revoke all active sessions across applications and portals whenever a password is reset.
  • Investigate the activity of an account from the likely date it was compromised.
  • Deploy MFA across all applications.
  • Use authentication factors that remain secure even when a password is stolen.
  • Avoid relying solely on email-delivered one-time codes when the attacker may also have access to the user's email account.
  • Prefer hardware security tokens or authenticator applications, ideally on a separate device.
  • Monitor all business applications through a SIEM.
  • Establish quotas and alerts for records accessed, requests generated, and data transferred.
  • Prevent personal devices from accessing sensitive work resources.
  • Improve network segmentation between government organizations and sensitive applications.

Key Takeaway

The French tax administration incident demonstrates how attackers can obtain substantial access without using highly sophisticated malware or exploits.

Stolen employee credentials, weak authentication, insufficient network segmentation, persistent sessions, and incomplete application-level monitoring allowed the attacker to access and extract large amounts of sensitive tax information.

The incident also highlights why detecting a compromised account requires more than simply resetting its password. Existing sessions, application activity, data volumes, network location, and unusual access patterns must also be monitored and correlated.