France’s tax agency lost data on 678,000 people to a stolen login

The French tax agency breach exposed income and property data on 678,000 people and businesses. Attackers used a staff login and an authorised outsider's, not a software flaw. DGFiP cut the access, but its own checks missed the theft. It learned the scale when the hacker advertised the database.


France’s tax agency lost data on 678,000 people to a stolen login
Image Credits Credit: Christopher Macsurak

The French tax agency says an attacker took data belonging to 678,000 individuals and businesses. The intrusions happened in June and July. The agency did not establish that anything had left its systems until the attacker said so in August.

The Direction générale des Finances publiques set out what the attacker reached in a statement on 14 August. For individuals, that means reference tax income, family quotient, and withholding tax rate. For companies, it means the registered name and the SIREN number. The attacker also consulted cadastral records covering the addresses and floor areas of properties.

The agency was equally specific about what held. The intrusions did not compromise personal or professional accounts on impots.gouv.fr. The attacker took no taxpayer usernames and no passwords.

Credentials, not a zero-day

The way in was not a software flaw. Bercy says the attacker used the stolen identifiers of a DGFiP employee and of an authorised third party. The attacker also described bypassing multi-factor authentication, according to Help Net Security.

An authorised third party, in this context, means an outside body the tax agency has granted a route into its systems. Notaries, bailiffs, and local authorities all hold such access. Each one widens the number of logins that will open the door.

The pattern is becoming familiar. Attackers reached 75,000 Fortinet firewalls in June using old passwords, not a zero-day. The login is the perimeter now.

DGFiP says it cut off every account involved as soon as it detected the intrusions. The access checks it ran at that point revealed no sign that data had left. The agency attributes that failure to the sophistication of the attack.

The state found out from the criminal

On 12 and 13 August, someone using the alias ZeroBytes claimed the access on a cybercrime forum. They offered a database for sale. DGFiP opened in-depth investigations the same day, and those investigations produced the figure of 678,000.

“I’m still logged into the panel, so if you want, you can buy it along with the database,” the forum post read, in the version Help Net Security reported.

Nobody outside the agency can test that claim. It sits against DGFiP’s account that it closed every compromised account on detection. The agency has since gone further, shutting off access to sensitive systems as a precaution, and it is working with the finance ministry’s security office and with ANSSI, the national cybersecurity agency.

The numbers do not agree

ZeroBytes claimed the portal held records on roughly 20 million French citizens. They said they had pulled 252,149 records covering more than two million people, and that scraping the rest would have taken months. The government’s figure is 678,000 individuals and businesses.

DGFiP says its investigations continue. It has not yet fixed the precise volume of data extracted, nor the final number of users concerned.

A gap of this kind has opened before. When a breach hit France’s own sovereign messenger in June, officials and the hacker disagreed over how bad it was.

What the crisis meeting produced

Prime Minister Sébastien Lecornu chaired an interministerial crisis cell on the French tax agency breach on Monday. A judicial investigation was already running before it met, Bloomberg reported.

Lecornu asked ANSSI to audit the incident and establish its causes, INCYBER reported. He separately requested an audit of the security of DGFiP’s systems, with operational conclusions due in September. The Paris prosecutor has opened an investigation covering fraudulent extraction of data and criminal conspiracy.

Notifications began that evening by email and run through the week. Each message names the data the attacker may have consulted or extracted, and the precautions to take. DGFiP has referred the matter to CNIL, the data protection regulator, and says it will lodge a criminal complaint.

The same door, twice

The government announced a plan to strengthen state cybersecurity at the end of April. It carries €200mn in additional investment. It also sets a target that from 2027 every ministry spends 5% of its digital budget on cybersecurity.

The DGFiP intrusions took place in June and July. INCYBER notes that someone obtained fraudulent access to FICOBA, the national register of bank accounts, a few months earlier, and that stolen credentials opened that door as well. Help Net Security counts a third incident, at France Titres, in April.

Other European public bodies have lost data on the same principle. France’s statistics office had its staff directory taken in June. In Liechtenstein, attackers reached the register naming the owners behind shell companies.

What the 678,000 face now

The exposed combination is an unusual one. Reference tax income and withholding rate together describe what a household earns. Cadastral data describes where that household lives, and how large the property is.

French authorities have warned that the data could feed scams and identity fraud. The concrete risk is a caller who already knows the target’s income and address, and who says they are from the finance ministry. Records like these travel: a telecoms company recently lost 1.6 million customer records to a phone call.

The hacker published a free sample of the files. France 24 tracked down a woman whose details appeared in it. She had heard nothing from anyone, and learned of it from the reporters who called her.

ANSSI reports in September. Its audit is meant to establish how the credentials of one employee and one authorised outsider opened a route to 678,000 tax records. It is also meant to explain why the agency’s own checks missed the theft. Until it lands, only two accounts of what happened exist: the one from the agency, and the one from the person who says they did it.

Get the TNW newsletter

Get the most important tech news in your inbox each week.