French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
- ID
- 29996
- Status
- summarized
- Published
- 30 Sep 2026, 1:47 AM
- Fetched
- 30 Sep 2026, 4:16 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.5
- Created
- 30 Sep 2026, 4:17 AM
- Tags
- Audience
- developerssaas_startup_founders
What happened
An attacker used several dozen DGFIP staff passwords, likely harvested over three months by infostealers on computers the tax administration did not manage, to pull data on just over 350,000 individuals and 250,000 businesses from E-Contact, the taxpayer messaging tool on impots.gouv.fr. Two portals the attacker used, PIGP and ADER, accepted a password alone, so stolen credentials worked immediately. ANSSI's audit found weak login protection, poorly separated networks and monitoring gaps; the theft ran in June and July, was only known on August 12 when the attacker claimed it on an online forum, and the ministry initially attributed the delay to the attack's 'sophistication'.
Why it matters
The failure mode is not exotic: password-only login on internal portals plus infostealer malware on unmanaged devices, and nobody noticed for seven weeks. If your team runs any internal admin, support or messaging tool behind a password with no MFA, that is the exact DGFIP pattern — adding MFA/SSO and monitoring for bulk exports or anomalous logins on those tools is the concrete fix. Note also the DGFIP's own access checks did not surface the theft, and only 250 of 350,000 individuals had message content taken, so a breach's blast radius depends heavily on what your tooling stores and logs. There is no Malaysian or Southeast Asian element in this report; treat it as a design lesson, not local news.
Discussion angle
Which internal portals on your own stack still accept a password alone, and would you have detected a slow three-month credential theft followed by a quiet data pull — or would you also only find out when the attacker posted about it?