France's tax administration has disclosed that attackers used compromised employee credentials to access taxpayer and business information over several weeks, according to an audit by the national cybersecurity agency, ANSSI.
The incident affected the Directorate General of Public Finance (DGFiP) and its E-Contact messaging service. DGFiP said information relating to more than 350,000 individuals and over 250,000 businesses may have been accessed. Individual taxpayer account passwords were not exposed, the agency said.
Data potentially obtained included tax identifiers, contact information, household details, reference taxable income, withholding-tax rates and metadata related to messages sent to the administration. The contents of messages may have been accessed for a smaller subset of individuals and businesses.
Compromised passwords and weak access controls
ANSSI said the intrusion was enabled by stolen passwords associated with DGFiP staff accounts. Investigators believe the credentials may have been collected by information-stealing malware from unmanaged devices, potentially including personal computers.
The attackers reportedly used password-only access routes to reach internal government resources and DGFiP applications. ANSSI found that some sensitive applications were insufficiently segmented from the broader interministerial network, allowing accounts without elevated privileges to reach substantial volumes of information.
A separate access route involving a portal used by external partners, including land-surveying professionals, was also investigated. Authorities said a potentially compromised device at a private firm may have allowed an attacker to bypass an email-delivered one-time code.
Detection gaps prolonged the activity
The activity was first publicly identified after an online claim on August 12, roughly seven weeks after the initial data collection. ANSSI said existing security monitoring detected some suspicious searches and compromised accounts, leading to password resets. However, those actions did not consistently terminate active sessions in other systems.
The review found that the DGFiP security operations center did not monitor one of the affected access systems. It also did not correlate indicators such as overnight logins, VPN use, connections from suspicious addresses, elevated request volumes and automated page-by-page extraction activity. About 11 GB of data was transferred during one period without triggering an alert, according to the report.
Remediation measures
DGFiP has suspended staff access to the affected portals and disabled accounts linked to the external-partner route. The administration has also outlined plans to expand logging and monitoring across business applications, introduce stronger authentication and limit bulk access to data. ANSSI said a broader audit is still needed to identify all underlying weaknesses.
