An attacker used stolen passwords of staff at France's tax administration, the DGFiP, to take tax data on hundreds of thousands of taxpayers and businesses during June and July, and neither the tax administration nor France's national cybersecurity agency ANSSI detected the exfiltration. ANSSI's report, published on Tuesday, describes an attack that was not sophisticated: it worked because of weak login protection, poorly separated networks and gaps in monitoring. The data came from E-Contact, the tool taxpayers use to message the tax administration; the DGFiP says taxpayers' own online accounts and passwords were not compromised. For individuals, the data that may have been viewed or copied includes tax ID, contact details, family situation, reference taxable income and tax withholding rate, plus a list of the messages exchanged with the DGFiP; for fewer than 250 people the message contents themselves may also have been taken. For businesses the exposure covers company name, SIREN registration number, address and message basics, with message content possibly seen for fewer than 2,076 businesses. The theft became known on 12 August, when the attacker claimed it on an online forum — seven weeks after the first batch was taken — prompting action from Prime Minister Sébastien Lecornu. The ministry's August explanation that access checks had not revealed the theft "because of the sophistication of the attack" is now contradicted by its own agency's findings.
| Attribute | Detail |
|---|---|
| Sector | Government |
| Date | 2026-09-30 |
| Source | The Hacker News |
| Reliability | Tier 2 |