France Tax Agency Breached Seven Weeks via Stolen Passwords

An attacker used infostealer-harvested passwords to breach France's DGFIP tax portals for seven weeks, exposing millions of taxpayer and business records.
Table of Contents
    Add a header to begin generating the table of contents

    An attacker logged into two portals belonging to France’s Direction Generale des Finances Publiques, the country’s tax administration, using employee passwords stolen by infostealer malware, and remained inside the systems for roughly seven weeks before detection. France’s national cybersecurity agency, ANSSI, published a report on the intrusion detailing how single-factor logins and unmonitored infrastructure let the breach persist.

    Stolen Credentials From Personal Devices Opened DGFIP Portals

    According to ANSSI, the attacker obtained staff login credentials that had been harvested by infostealer malware installed on personal, unmanaged devices, not DGFIP-issued equipment. Those stolen passwords were then used to log directly into two DGFIP portals, identified as PIGP and ADER, both of which required only a password for access with no additional authentication factor.

    The intrusion ran for approximately seven weeks across June and July 2026 before it was identified. ANSSI’s report attributes the extended dwell time to a specific gap in DGFIP’s incident response: when suspicious activity triggered password resets on one of the two portals, those resets did not terminate active sessions on the other portal, allowing the attacker to keep working. Compounding the gap, DGFIP’s security operations center was not monitoring the ADER portal at all during the intrusion window.

    Infostealer malware of the kind ANSSI describes typically operates by silently harvesting saved browser credentials, session cookies, and autofill data from an infected personal computer, then packaging that stolen material for sale or direct use by other criminal actors. Because the credentials in this case came from personal, unmanaged devices rather than DGFIP-issued hardware, the agency’s own endpoint security controls would not have had visibility into the initial infection that produced the stolen passwords, leaving the password-only portal login as the only defensive layer standing between the attacker and the two systems.

    Tax and Land-Registry Data Exposed for Over a Million People and Businesses

    The attacker accessed tax identification numbers, contact details, family situation records, taxable income figures, and withholding-rate data for more than 350,000 individuals through the compromised portals. Message content stored within the systems was accessed for fewer than 250 of those individuals, a much smaller subset than the total whose account-level data was exposed.

    For businesses, the attacker obtained company names, registration numbers, addresses, and message summaries covering more than 250,000 entities, with full message content accessed for under 2,076 of them. A separate attack route tied to the same intrusion also exposed land-registry data belonging to 435,000 households, broadening the breach’s reach beyond the tax portals themselves.

    ANSSI Attributes the Breach to Weak Login Protection, Not Sophistication

    ANSSI’s report states plainly that the breach succeeded because of weak login protection, poorly segmented networks, and monitoring gaps inside DGFIP’s infrastructure, rather than because the attacker used advanced techniques. The agency’s framing places responsibility on the tax administration’s own security architecture: a password-only login on a government portal handling sensitive financial data, combined with a security operations center blind spot on one of the two affected systems, gave an attacker armed with commodity-malware-harvested credentials a seven-week window to operate.

    DGFIP Response Includes MFA Rollout and Personal-Device Ban

    Following the discovery of the intrusion, DGFIP disabled staff access to both the PIGP and ADER portals. The agency is now implementing multi-factor authentication across its applications, a control that would have blocked the stolen-password login method used in this case had it been in place beforehand. DGFIP is also deploying data-volume monitoring tools intended to flag unusual bulk access to taxpayer records, and has prohibited staff from using personal devices to access work systems, directly addressing the infostealer-on-personal-device vector ANSSI identified as the intrusion’s starting point.

    The scale of exposure, spanning individual taxpayers, businesses, and households tied to land records, places DGFIP among the larger European government data breaches disclosed this year. Because the stolen data includes taxable income and withholding-rate figures tied to verified tax identification numbers, affected individuals face an elevated risk of targeted phishing or fraud attempts that reference accurate financial details to appear legitimate. The seven-week gap between initial access and detection also raises questions for other government agencies relying on password-only authentication for internal portals handling comparably sensitive records.

    Related Posts