
French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
An attacker used stolen passwords of DGFIP staff to take tax data on more than 350,000 individuals and 250,000 businesses in June and July. ANSSI says the theft went unnoticed for seven weeks.
In June and July 2026 an attacker took tax data on hundreds of thousands of taxpayers and businesses using stolen passwords of staff at France's tax administration, the DGFIP. Neither the administration nor France's cybersecurity agency, ANSSI, saw the data leave. ANSSI says the attack was not sophisticated: weak login protection and gaps in monitoring made it possible.
The data came from E-Contact, the tool taxpayers use to message the DGFIP. The theft covers a little over 350,000 individuals and a little over 250,000 businesses; taxpayers' own accounts and passwords were not compromised. For individuals the data that may have been viewed includes tax ID, contact details, family situation and tax withholding rate, while for businesses it covers the company name, SIREN number and address.
How the Attacker Got In
The attacker used two routes. The first began with suspicious logins in early May and led to E-Contact; it relied on several dozen DGFIP staff passwords stolen over three months, probably by infostealers on personal devices. Two portals, PIGP and ADER, asked only for a password. He reached the RIE, the ministries' network, through compromised Education ministry systems, and sensitive DGFIP applications were not separated from the rest of it. The second route ran through APEX, a portal for notaries and land surveyors.
Why No One Saw the Theft
The theft became known on August 12, when the attacker claimed it on an online forum, seven weeks after the first batch was taken. In August the ministry overseeing the DGFIP blamed the sophistication of the attack, while ANSSI describes a routine operation. The DGFIP's security operations center (SOC) reset passwords whenever an account was flagged.
On June 7, searches with a stolen account set off an alert and a same-day reset, but the SOC missed his move from PIGP to ADER. On June 23 another account was flagged, and at 4:26 a.m. the next day he began scraping E-Contact via ADER. The reset did not end the open ADER session, and data kept flowing for almost 16 more hours.
In July the SOC again caught searches but not the theft. It was not monitoring ADER at all, and no system linked night logins or connections from VPNs and addresses in India. The 11 GB exchanged between June 22 and 25 raised no alert, and ANSSI's own sensors sit only at the RIE and internet boundaries.
What Changed and What ANSSI Recommends
DGFIP staff accounts have been shut out of ADER since August 13 and out of PIGP since August 18, and the DGFIP does not expect to reopen either portal to them. An action plan extends monitoring to all business applications, adds strong authentication and limits the data that can be accessed. ANSSI also recommends revoking every active session whenever a password is reset, using multi-factor authentication everywhere, and monitoring every business application in a SIEM.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.