Weak login protection and gaps in monitoring let attackers pull data on 350,000 individuals undetected
An attacker using stolen passwords belonging to staff at France's tax administration extracted data on hundreds of thousands of taxpayers and businesses over June and July, and neither the agency nor France's national cybersecurity body noticed the data leaving.
A report from ANSSI, France's cybersecurity agency, published Tuesday, concluded the attack succeeded not through sophistication but through weak login protection, poorly separated networks, and monitoring gaps.
The breach hit E-Contact, the messaging tool taxpayers use to communicate with the DGFIP, France's tax administration. The stolen data covers just over 350,000 individuals and roughly 250,000 businesses, according to the DGFIP, though taxpayers' own account passwords were not compromised.
For individuals, exposed data included tax IDs, contact details, family situation, and taxable income figures, with message content possibly accessed for fewer than 250 people. For businesses, exposure was largely limited to company names and registration numbers, with message content potentially seen for fewer than 2,076 companies.
According to ANSSI, there were two different methods through which the attacks were carried out. First, several dozen password credentials of DGFIP employees were stolen within three months. The attackers probably used the infostealer malware to steal the data on personal devices. There were two portals used by DGFIP employees that only required password credentials without any secondary verification.
The attackers accessed the internal network of DGFIP via the systems of the Education Ministry. That happened due to the lack of separation of sensitive applications from the rest of the government network.
Second, the attack was aimed at the land registry information and was conducted via the portal APEX that is used by the company’s partners, such as notaries and land surveyors. A private surveying company’s computer was hacked, allowing the attackers to circumvent their one-time email codes and extract the information about nearly 435,000 people from July 27 to August 8.
The DGFIP's security team did detect suspicious activity multiple times but consistently missed the actual data extraction. On June 23, a flagged account triggered a security ticket, but by the time staff reset the account's password the next morning, the attacker had already been pulling data for hours through a separate, still-active session.
Data continued flowing for nearly 16 more hours after the reset. The security team wasn't monitoring the ADER portal at all, and no system correlated warning signs like nighttime logins, VPN connections, or unusual data volumes, including an 11 GB transfer over three days that raised no alarm.