AI Weekly Malaysia

Back to items Summaries

French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

ID
29996
Status
summarized
Published
30 Sep 2026, 1:47 AM
Fetched
30 Sep 2026, 4:16 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
5.5
Created
30 Sep 2026, 4:17 AM
Tags
Audience
developerssaas_startup_founders

What happened

An attacker used several dozen DGFIP staff passwords, likely harvested over three months by infostealers on computers the tax administration did not manage, to pull data on just over 350,000 individuals and 250,000 businesses from E-Contact, the taxpayer messaging tool on impots.gouv.fr. Two portals the attacker used, PIGP and ADER, accepted a password alone, so stolen credentials worked immediately. ANSSI's audit found weak login protection, poorly separated networks and monitoring gaps; the theft ran in June and July, was only known on August 12 when the attacker claimed it on an online forum, and the ministry initially attributed the delay to the attack's 'sophistication'.

Why it matters

The failure mode is not exotic: password-only login on internal portals plus infostealer malware on unmanaged devices, and nobody noticed for seven weeks. If your team runs any internal admin, support or messaging tool behind a password with no MFA, that is the exact DGFIP pattern — adding MFA/SSO and monitoring for bulk exports or anomalous logins on those tools is the concrete fix. Note also the DGFIP's own access checks did not surface the theft, and only 250 of 350,000 individuals had message content taken, so a breach's blast radius depends heavily on what your tooling stores and logs. There is no Malaysian or Southeast Asian element in this report; treat it as a design lesson, not local news.

Discussion angle

Which internal portals on your own stack still accept a password alone, and would you have detected a slow three-month credential theft followed by a quiet data pull — or would you also only find out when the attacker posted about it?

Top