Major Breach at French Tax Agency: Stolen Credentials Exposure Data of 678,000 Taxpayers

Credential Compromise at DGFiP and the Scope of the Breach

The General Directorate of Public Finances of France (DGFiP) has experienced one of the most significant cybersecurity incidents involving state infrastructure in recent years. Unauthorized access to the agency’s internal systems led to the exposure of personal and financial records belonging to 678,000 individuals and corporate entities. The incident was triggered by the compromise of user credentials belonging to a tax authority employee and an external IT contractor hired for system maintenance.

The breach did not directly compromise user passwords or personal accounts on the official impots.gouv.fr portal. However, the stolen credentials allowed the threat actor to query internal databases over several weeks, retrieving land registry records and tax filing details. According to an official statement from the French Ministry of Economy and Finance, the threat was contained only after anomalous data exfiltration was detected by the National Cybersecurity Agency of France (ANSSI).

Categories of Exposed Information and Associated Risks

The compromised records included detailed information on taxpayers, posing substantial risks regarding spear-phishing attacks and social engineering. The table below outlines the specific data categories exposed during the incident.

Exposed Data Categories and Risk Assessment
Data Category Exposed Record Details Potential Risk
Personal Identifiers Full names, registered addresses, tax identification numbers (SPI) Identity theft and phishing attacks
Financial Records Income declarations, tax rates, historical tax relief data Targeted financial fraud and extortion
Property Registries Real estate details, cadastral numbers, property area (sq m) Property-related fraudulent schemes
Corporate Data Business registration numbers, corporate financial statements Business Email Compromise (BEC) and espionage

Attack Timeline and Threat Actor Activity

Initial evidence of the data breach appeared on the cybercrime forum PwnForums, where a threat actor using the alias ZeroBytes published sample data extracted from DGFiP databases. The actor claimed possession of full land registry records and financial indicators covering multiple administrative departments in France, offering the dataset for sale in cryptocurrency. Cyber threat intelligence analysts suggest the adversary used valid credentials to simulate legitimate administrative sessions, evading conventional intrusion detection systems (IDS) for weeks.

Following verification of the published samples, the French Ministry of Economy engaged the specialized cybercrime unit (OFAC) and the Paris Prosecutor’s Office to lead the criminal investigation. ANSSI specialists performed an emergency security audit of the compromised infrastructure, revoked all external contractor access tokens, and enforced mandatory multi-factor authentication for elevated privilege accounts.

Supply Chain Vulnerabilities in Public Infrastructure

The DGFiP incident underscores the critical risks associated with third-party service providers accessing state IT environments. Supply chain credential compromise remains one of the most effective techniques for bypassing network perimeters. In this case, the adversary did not require zero-day exploits, as valid authentication material granted direct access to internal tax administrative APIs.

  • Inadequate IP restriction policies for external contractors connecting via remote VPNs.
  • Permissive session limits that enabled large-scale data querying without triggering automated account suspension.
  • Delayed anomaly detection due to traffic originating from authenticated accounts with legitimate access rights.

Remediation and Guidance for Affected Entities

The French Tax Agency has initiated direct notifications to all 678,000 affected taxpayers via email and secure portal alerts. Authorities warn of a likely increase in phishing campaigns leveraging actual tax IDs and physical addresses to impersonate tax officials. Citizens are advised to verify any financial notices directly through the official impots.gouv.fr platform and refrain from clicking unverified links or email attachments.

The breach has also renewed regulatory discussions surrounding GDPR compliance for public sector bodies managing third-party vendors. Following the investigation, ANSSI is expected to release revised security baselines requiring mandatory Zero Trust Network Access (ZTNA) implementation across all French public service interfaces.

Pavlo Zaslonov
About The Author

Pavlo Zaslonov

Cybersecurity expert, knows everything about IP hiding and modern chatbot vulnerabilities.

0 Comments

Leave a Reply

2500
Please enter a comment
Please enter your name