An attacker used stolen passwords of French tax administration staff to steal tax data from hundreds of thousands of taxpayers and businesses in June and July.
See also: French Football Federation reveals data breach

Neither the tax administration nor France's national cybersecurity agency detected the leaked data. The attack was not sophisticated, according to ANSSI ,which said it succeeded due to weak connection protection, poorly segregated networks and gaps in monitoring.
The tax administration, known as DGFIP, runs France’s tax website, impots.gouv.fr. The data was obtained from E-Contact, the tool taxpayers use to communicate with the tax administration. The stolen data includes information on over 350,000 individuals and over 250,000 businesses. Taxpayers’ personal accounts and passwords were not compromised.
For individuals, the data that may have been viewed or copied includes their tax number, contact information, marital status, reportable taxable income, tax withholding rate, and a list of messages exchanged with the DGFIP. For fewer than 250 individuals, the messages themselves may also have been retrieved.
For businesses, the stolen data includes the company name, SIREN registration number, address and basic details of their messages. For fewer than 2,076 businesses, the content of these messages may have been accessed.
The data theft became known on August 12, when the attacker claimed responsibility on an online forum, seven weeks after the data was initially taken. Prime Minister Sébastien Lecorny then called for a thorough audit by ANSSI. In August, the ministry that oversees the DGFIP provided a different explanation, stating that the DGFIP’s access controls did not reveal the theft “due to the complexity of the attack.”
The attacker used two separate methods to gain access. The first began with suspicious logins in early May and led to E-Contact. This route relied on several dozen passwords belonging to DGFIP staff, which were stolen over a three-month period, likely via infostealers—malware that quietly copies stored logins—from computers not managed by DGFIP, likely personal devices of staff.
See also: French National Bank Authority: 1.2 million accounts breached

The attacker exploited two portals, PIGP and ADER, which required only a password, allowing the stolen passwords to work immediately. PIGP is a web portal used by DGFIP staff for email and HR services, while ADER provides access to some DGFIP applications via RIE, the network connecting French government ministries.
The attacker gained access to RIE through compromised Ministry of Education systems. Sensitive DGFIP applications were not adequately segregated from the rest of RIE, allowing access from parts of the network without apparent need. Researchers also found evidence of attempts to infiltrate other government bodies on the network.
The accounts used by the attacker did not have special privileges, but they were able to access a significant amount of data. ANSSI did not investigate how user rights were managed for this report.
The second method led to cadastral data via APEX, a portal for partners such as notaries and surveyors, which required a password and a one-time code sent via email. The DGFIP investigation suggested that a surveyor's computer at a private company may have been compromised, allowing the attacker to bypass the code. The data was obtained between July 27 and August 8, affecting nearly 435,000 households, according to a note from the Senate Finance Committee dated September 4.
The DGFIP had a routine for handling stolen staff logins, as reported by ANSSI. Its security operations center (SOC) monitors for attacks. When the SOC detected a compromised account or a threat intelligence provider flagged it, it reset the password. This routine detected some of the attacker’s activity but failed to prevent the theft.
See also: AI Data Centers: California Tightens Rules
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

On June 7, searches using a stolen account raised an alarm, but the response was insufficient to stop the breach.
