Skip to content

France's DGFiP breach: 350k+ people hit via stolen passwords

ANSSI's report on the French tax administration breach: attackers used stolen staff credentials against password-only portals, exfiltrating data on 350k+ individuals over seven undetected weeks.

Published 3 min read

France's national cybersecurity agency ANSSI has published its report on the breach of the Direction Générale des Finances Publiques (DGFiP) — the tax administration behind impots.gouv.fr. Attackers used stolen staff credentials to walk into portals that asked for nothing but a password, and exfiltrated data on hundreds of thousands of taxpayers over roughly seven weeks before anyone noticed.

The DGFiP's own statement confirms illegitimate access "in June, July and August 2026," and that a malicious actor claimed the theft on August 12–13. ANSSI's incident report, published September 23, is the primary account of how it happened.

What was taken

Per ANSSI's figures, the exposed data covers roughly 353,000 individuals and 252,000 professionals; reporting puts the total population potentially affected at more than 678,000 once a separate land-registry exposure is counted. Data types include tax identifiers, contact details, family situation, reference taxable income, and withholding rates. For a small number of people (fewer than ~250), message content with the tax authority was also accessed.

Crucially, the DGFiP states that impots.gouv.fr personal accounts and their passwords were not compromised, and no bank details (RIB/IBAN, cards) were exposed. The theft came through internal back-office portals, not user-facing accounts.

How it happened

The intrusions relied on usurpation of the credentials of a DGFiP agent and an authorized third party — consistent with infostealer-harvested passwords reused against internal systems. Two portals, reported as PIGP and ADER, required only a password to authenticate, so a stolen credential was immediately usable. A separate vulnerability on the portail des successions vacantes (vacant-estates portal) was found on August 17.

Detection status

This is the part that should worry any org running back-office portals: exfiltration ran for about seven weeks and was detected by neither the DGFiP's own monitoring nor ANSSI's — it surfaced only when the actor publicly claimed the theft on a forum. ANSSI was alerted a few hours after that claim.

Action checklist

  1. Kill password-only auth on internal portals today. The single control that would have blunted this is MFA on back-office access. A stolen password should never be a complete credential.
  2. Assume infostealer exposure for staff. Credentials harvested from personal devices are the likely entry vector. Rotate portal credentials, hunt for infostealer infections, and block credential reuse across personal and corporate contexts.
  3. Instrument exfiltration detection on internal apps. Seven undetected weeks means volume/rate anomalies on internal portals weren't alarmed. Add egress and query-rate baselines to systems that hold bulk PII.
  4. Inventory "low-value" internal portals. The vacant-estates portal shows the long tail matters — every internet-reachable back-office app is attack surface.
  5. If you're an affected taxpayer, expect targeted phishing using your real tax data; treat any "impôts" message asking for payment or login as hostile.

Context

This lands the same week ANSSI is in the headlines for the Citrix NetScaler zero-day advisory, and it fits a pattern we keep documenting: initial access via stolen or infostealer-sourced credentials, then password-only internal systems doing the rest. The novel detail here isn't the tooling — it's that a national agency's crown-jewel data sat behind single-factor auth, and that the first alarm was the attacker's own bragging.

Related stories