← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

French Tax Data Stolen Using Staff Passwords, Undetected for Seven Weeks

🔄 Updated 2d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Attacker used stolen staff passwords to access tax data.
  • Data on over 350,000 individuals and 250,000 businesses was taken.
  • Breach went undetected for seven weeks.
  • ANSSI cited weak login protection and network issues as causes.

Data Theft Details

An attacker accessed and copied tax data belonging to hundreds of thousands of French taxpayers and businesses between June and July. The data was taken from E-Contact, a tool used by taxpayers to communicate with the tax administration (DGFIP). The DGFIP confirmed that data for over 350,000 individuals and 250,000 businesses was affected.

For individuals, the stolen data included tax ID, contact details, family situation, taxable income, tax withholding rate, and a list of messages exchanged with DGFIP. For a smaller number of individuals (fewer than 250), the content of messages may also have been compromised. For businesses, the data included company name, SIREN registration number, address, and basic message details, with message content potentially exposed for fewer than 2,076 businesses. Taxpayers' personal online accounts and passwords were not directly compromised.

Detection Failure and Initial Response

The data theft went undetected by both the DGFIP and France's national cybersecurity agency (ANSSI) for seven weeks. The breach became public on August 12 when the attacker claimed responsibility on an online forum. This prompted Prime Minister Sébastien Lecornu to request an in-depth audit from ANSSI.

Initially, the ministry overseeing the DGFIP stated that the theft was not detected due to the "sophistication of the attack." However, ANSSI's subsequent report contradicted this, describing the attack as unsophisticated and attributing its success to weak login protection, poorly separated networks, and monitoring deficiencies.

Attack Vector

According to the ANSSI report, the attacker used two separate routes to gain access. The primary method involved using several dozen DGFIP staff passwords that were stolen over a three-month period, likely via infostealer malware on unmanaged devices, such as personal computers of staff members.

The attacker exploited two portals, PIGP and ADER, which only required a password for access. PIGP is a web portal for DGFIP staff email and HR services, while ADER provides access to certain DGFIP applications via the RIE, the network connecting French government ministries.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

An attacker stole tax data from hundreds of thousands of French taxpayers and businesses using compromised staff passwords, remaining undetected for seven weeks. The breach was attributed to weak login protection, poor network segmentation, and monitoring gaps within the tax administration's systems.