Breaking
Cyber CrimeDeveloping Story

French Tax Breach Hits 680K

France's tax agency says 678,000 people had data stolen in a credential-based attack.

··2 hours ago·3 min read
padlock on laptop with light trails
Photo by FlyD on Unsplash

For months, a thief quietly moved through the internal systems of France’s tax authority, and only now has the full scale of what was taken come into view. The Directorate General of Public Finances (DGFiP) disclosed that roughly 680,000 individuals had their personal and property-related data exposed in a breach that involved compromised employee and third-party credentials.

What Was Taken

According to DGFiP, the attackers accessed systems in June and July, and the unauthorized access was immediately suspended upon detection. At the time, the public tax authority found no evidence of data exfiltration. But last week, officials confirmed that the intruders used compromised credentials for an employee and a third-party account to access systems and steal the information of 678,000 users.

The compromised data includes reference tax income, withholding tax rate, company names and unique identifiers, and cadastral data on real estate addresses and surfaces. DGFiP emphasized that no other information, including usernames and passwords, was compromised in the attack.

Discovery and Response

The incident came to light after a threat actor boasted on a hacking forum about accessing DGFiP’s internal systems and exfiltrating data. The attack was immediately reported to France’s data protection authority CNIL.

DGFiP says it continues to investigate the nature and scope of the data breach, as well as the exact number of potentially affected individuals. The tax authority says it will contact each affected individual directly.

Credential-Based Intrusion

The breach underscores the risk of compromised credentials, a common vector in attacks on government agencies. In this case, the attackers leveraged credentials belonging to an employee and a third-party account, allowing them to move through DGFiP’s systems undetected for an extended period.

The specific details of how the credentials were obtained—whether through phishing, malware, or another method—have not been disclosed.

European Precedent

The incident came to light roughly one month after another European government agency, Romania’s National Agency for Cadastre and Property Registration (ANCPI), fell victim to a disruptive cyberattack.

ANCPI was reportedly hacked by a threat actor known as ByteToBreach, who stole information including employee credentials and internal documents and attempted to extort the agency. When the extortion attempt failed, the hacker reportedly wiped the encrypted data, disrupting official applications, sites, and email services, and bringing Romania’s real estate market to a standstill.

Impact on Affected Individuals

For the 678,000 individuals affected, the exposure of tax income and property data could have long-term implications. Such information can be used for identity theft, financial fraud, or targeted social engineering attacks. The lack of compromised passwords offers some relief, but the data is still sensitive.

DGFiP has not specified what steps affected individuals should take, other than to expect direct contact from the agency. The investigation into the full scope of the breach is ongoing.

Why It Matters

The breach at DGFiP, following the ANCPI incident, highlights a worrying trend: government agencies are increasingly targeted by attackers using stolen credentials to access sensitive systems and data. The fact that DGFiP initially found no evidence of exfiltration, only to later confirm data theft, suggests that detection gaps can allow attackers to operate for weeks or months before the full extent of a breach is known. For individuals, this means that even if authorities respond promptly, the damage may already be done. As investigations continue, affected taxpayers should remain vigilant and consider monitoring for any suspicious activity related to their financial or property records.

#data breach#dgfip#france#cyberattack#credentials

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories