thehackernews.com 29 Sept 2026, 17:47 UTC

Stolen Staff Passwords Exposed Tax Data on 600,000 in France

CyberSIXT Evidence Panel Source marked as original reporting

AN attacker used stolen passwords belonging to staff at France’s tax administration (DGFIP) to access tax data on hundreds of thousands of taxpayers and businesses during June and July. The breach went undetected as data flowed out; officials say the theft exploited weak login protection, poor network segmentation, and gaps in monitoring. The data involved comes from E-Contact, the taxpayer messaging tool, and affects just over 350,000 individuals and just over 250,000 businesses.

Personal online account credentials were not compromised, but messages and some account details could have been viewed. For a subset, the content of messages could also have been accessed.

Investigators traced two routes into the system. The first used several dozen DGFIP staff passwords obtained over three months and used two portals, PIGP and ADER, that accepted only a password. Access came via the RIE network, through compromised Education Ministry systems, with sensitive DGFIP applications not properly separated from other government components.

The second route involved land-registry data via the APEX portal, where a land surveyor’s private-system compromise potentially bypassed a one-time code sent by email. SOC monitoring failed to identify ongoing data extraction, with data exfiltration continuing for days even after password resets. ANSSI has since recommended extending monitoring, enforcing strong authentication (MFA on all portals), revoking sessions on password resets, and tightening data access controls. A fuller audit is planned to identify all exploitable weaknesses and to prevent recurrence.

View full article

Article by CyberSIXT