Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Exposing the vulnerabilities of France's tax administration: A tale of stolen staff passwords, compromised networks, and undetected data theft


French tax administration's lack of security measures led to the theft of hundreds of thousands of sensitive tax data records, highlighting the importance of robust password protection, secure network monitoring, and effective incident response.

  • Hundreds of thousands of individuals and businesses had sensitive tax data stolen due to lack of security measures.
  • The breach began with stolen staff passwords obtained by hackers over three months.
  • The attackers used two separate routes to gain access to the DGFIP's systems, including compromised Education ministry systems.
  • The breach was not detected by the DGFIP's security operations center or national cybersecurity agency despite receiving warnings.
  • The French government has taken steps to strengthen the DGFIP's security measures, including multi-factor authentication and monitoring.



  • In a stunning revelation, the French tax administration's lack of security measures has allowed for the theft of sensitive tax data, with hundreds of thousands of individuals and businesses compromised. The attack, which occurred over a period of seven weeks, highlights the importance of robust password protection, secure network monitoring, and effective incident response.

    The breach began with the use of stolen staff passwords, which were obtained by hackers over a period of three months. The passwords were used to gain access to the DGFIP's E-Contact tool, which allows taxpayers to message the tax administration. The attackers then used this access to steal sensitive data, including tax IDs, contact details, and financial information.

    The attackers used two separate routes to gain access to the DGFIP's systems. The first route involved using stolen passwords to gain access to the PIGP and ADER portals, which provided access to certain DGFIP applications. The second route involved using compromised Education ministry systems to gain access to the RIE network, which connects French government ministries.

    Despite the attackers' sophisticated methods, the breach was not detected by the DGFIP's security operations center (SOC) or the national cybersecurity agency (ANSSI). This was due in part to the fact that the attackers used real staff accounts, which were not properly monitored or flagged. The SOC also failed to detect the attackers' activity, despite receiving warnings from the Education ministry's security team.

    The breach was not discovered until the attackers claimed responsibility on an online forum, seven weeks after the initial attack. The French government has since launched an investigation and taken steps to strengthen the DGFIP's security measures, including revoking active sessions on all applications and portals, implementing multi-factor authentication, and monitoring every business application in a SIEM.

    This breach highlights the importance of robust password protection, secure network monitoring, and effective incident response. It also underscores the need for organizations to prioritize security and take proactive steps to prevent similar breaches. By learning from this incident, organizations can take steps to improve their security posture and protect their sensitive data.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Exposing-the-vulnerabilities-of-Frances-tax-administration-A-tale-of-stolen-staff-passwords-compromised-networks-and-undetected-data-theft-ehn.shtml

  • https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html


  • Published: Tue Sep 29 14:30:16 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us