French Tax Data Breach: 'Unsophisticated' Attack Exposes Hundreds of Thousands of Records
France's tax administration, the **DGFIP**, suffered a significant data breach in June and July, compromising tax data for hundreds of thousands of individuals and businesses. The attack, deemed 'unsophisticated' by France's national cybersecurity agency, **ANSSI**, exploited weak login protections, poor network segmentation, and monitoring gaps.
An attacker leveraged stolen staff passwords at France's tax administration, the **DGFIP**, to exfiltrate tax data belonging to hundreds of thousands of taxpayers and businesses. The breach, which occurred in June and July, went undetected by both the **DGFIP** and **ANSSI** until the attacker publicly claimed it.
**ANSSI**'s subsequent report, published on Tuesday, highlighted that the attack was not sophisticated. Instead, it succeeded due to fundamental security weaknesses: inadequate login protection, insufficient network segregation, and critical gaps in monitoring systems.

### Scope of the Breach
The stolen data originated from **E-Contact**, the tool taxpayers use for communication with the **DGFIP** via impots.gouv.fr. The **DGFIP** confirmed that data for over **350,000 individuals** and **250,000 businesses** was compromised. Crucially, taxpayers' own online accounts and passwords were not directly affected.
For individuals, the exposed data includes tax IDs, contact details, family situation, reference taxable income, tax withholding rates, and a list of messages exchanged with the **DGFIP**. For a smaller subset of fewer than 250 individuals, the content of these messages may also have been accessed.
Business data compromised includes company names, **SIREN** registration numbers, addresses, and basic message details. For fewer than 2,076 businesses, the content of their messages may have been viewed.
The breach came to light on August 12 when the attacker posted about it on an online forum. This prompted Prime Minister **SΓ©bastien Lecornu** to request an in-depth audit from **ANSSI**, contradicting an earlier explanation from the ministry overseeing the **DGFIP** that cited the 'sophistication of the attack' as the reason for its undetectability.
### Attack Vectors Employed
The **ANSSI** report details two distinct entry points used by the attacker.
The first route, initiated with suspicious logins in early May, targeted **E-Contact**. This relied on dozens of **DGFIP** staff passwords, likely stolen over three months by infostealers β malware that quietly copies saved credentials β from unmanaged devices, most likely personal computers.
Two portals, **PIGP** (a web portal for email and HR services) and **ADER** (providing access to **DGFIP** applications via the **RIE**, the French government's inter-ministerial network), were vulnerable as they only required a password for access. The attacker gained access to the **RIE** through compromised systems belonging to the **Education Ministry**.
Critically, sensitive **DGFIP** applications were not adequately isolated within the **RIE**, allowing access from network segments that had no legitimate need. Investigators also found evidence of attempts to pivot into other government bodies on the network. Despite using accounts with no elevated privileges, the attacker could access a significant volume of data. **ANSSI**'s report did not delve into user rights management.
The second vector led to land-registry data via **APEX**, a portal for partners like notaries and land surveyors. This portal required a password and a one-time code sent via email. The **DGFIP**'s investigation indicated that a land surveyor's computer at a private firm was likely compromised, enabling the attacker to bypass the one-time code. This data, affecting nearly **435,000 households**, was exfiltrated between July 27 and August 8.
### Why the Theft Went Unnoticed
The **DGFIP** had a routine for handling stolen staff logins, with its Security Operations Center (**SOC**) responsible for threat monitoring. While the **SOC** detected some of the attacker's activities, it failed to identify the data theft.
On June 7, suspicious searches from a stolen account triggered an alert and a password reset. However, the **SOC** missed the attacker's lateral movement from **PIGP** to **ADER**.
On June 23, another compromised account used by the attacker was flagged. While the **SOC** created a ticket, the attacker began automated data extraction from **E-Contact** via **ADER** hours later, continuing for almost 16 hours after the **SOC** reset the password, as the reset did not terminate the attacker's active session on **ADER**.
Similar incidents occurred in July, where the **SOC** detected suspicious searches but not the subsequent data exfiltration.
A major oversight was the **DGFIP**'s **SOC** not monitoring **ADER** at all. Furthermore, warning signs such as night-time logins, connections from VPNs, Indian IP addresses, or known malicious IPs were not correlated. Data volumes, including the **11 GB** exchanged between June 22 and 25, also failed to trigger alerts. The number of requests per user, crucial for detecting data scraping, was not checked.
**ANSSI**'s own monitoring also missed the theft. Its detection sensors are positioned only at the entry and exit points of the **RIE** and the internet, lacking access to application logs. As the attacker used legitimate staff accounts, **ANSSI**'s network monitoring did not flag the activity, though the agency believes the total request volume should have raised alarms.
Timely communication was also an issue. On June 9, the **Education Ministry**'s security team shared indicators of compromise with other ministries, but one of the attacker's addresses had already been used and was reused later in June. **ANSSI** stressed the need to minimize the time taken to analyze and share such indicators.
### Remediation and Recommendations
Following the report, **DGFIP** staff accounts were locked out of **ADER** and **PIGP** in mid-August, with no plans to reopen these portals to them. The **APEX** portal was also secured, and the compromised surveyor's account disabled, causing significant disruption to some **DGFIP** services and partner organizations.
An action plan has been initiated to extend monitoring to all **DGFIP** business applications, implement strong authentication, and set limits on data access. **ANSSI** emphasized that a comprehensive audit is needed to identify all exploitable weaknesses.
**E-Contact** will now incorporate multi-factor authentication, and tools to detect unusual data volumes will be deployed. Access to **DGFIP** tools from personal devices has also been restricted.
**ANSSI**'s key recommendations for the **DGFIP** include:
* Revoking all active sessions across all applications and portals whenever a password is reset.
* Thoroughly investigating an account's activity from the likely compromise date when reported as compromised.
* Implementing multi-factor authentication (**MFA**) on all applications, using a second factor that remains secure even if the password is stolen (e.g., hardware tokens or authenticator apps on a separate device, rather than email-based one-time codes).
* Monitoring all business applications within a Security Information and Event Management (**SIEM**) system, with quotas on accessed records, requests, and data exchanged.
* Prohibiting personal devices from accessing work resources.