· via dev.to (home feed)
ANSSI finds stolen staff passwords, not sophistication, behind France's breach of 600,000 records
ANSSI's audit says stolen staff passwords, portals secured by passwords alone and monitoring gaps let an attacker take data on some 600,000 French taxpayers and businesses, plus land records on 435,000 households.

The breach
An attacker extracted data on a little over 350,000 individuals and 250,000 businesses from France's tax administration, the DGFIP, after logging in with several dozen stolen staff passwords, and the theft went undetected by both the agency and ANSSI, France's national cybersecurity agency. It became known on August 12, when the attacker claimed it on an online forum, about seven weeks after the first batch was taken. The account comes from a RedEye Threat Intelligence analysis published on dev.to, based on an ANSSI audit requested by Prime Minister Sébastien Lecornu and on reporting by The Hacker News.
The audit's central conclusion is that the intrusion was not sophisticated. That contradicts the ministry overseeing the DGFIP, which said in August that access checks had missed the theft because of the attack's sophistication. ANSSI instead points to weak login protection, poorly separated networks and gaps in monitoring.
What was taken
Most of the data came from E-Contact, the tool taxpayers use to message the administration behind impots.gouv.fr. For individuals, exposed fields include tax identifiers, contact details, family situation, reference taxable income, withholding rates and lists of messages exchanged with the DGFIP; for fewer than 250 people, the message contents themselves may have been copied. For roughly 250,000 businesses, the data covers company names, SIREN registration numbers, addresses and basic message details, with message content potentially exposed for fewer than 2,076 firms. Taxpayers' own online accounts and passwords were not compromised.
A second route reached land-registry data through APEX, a portal for partners such as notaries and land surveyors that required a password plus a one-time code sent by email. The DGFIP found that a land surveyor's computer at a private firm had likely been compromised, letting the attacker bypass that code. The data was taken between July 27 and August 8 and concerns nearly 435,000 households, according to a September 4 Senate finance committee note reported by Public Sénat.
How the attacker got in
The credentials, several dozen DGFIP staff passwords collected over three months, were probably harvested by infostealer malware on computers the agency did not manage, most likely employees' personal devices. Two portals, PIGP for email and HR services and ADER for access to DGFIP applications, asked for nothing more than a password, which meant a single stolen credential granted access. The attacker reached the RIE, the network linking French ministries, through compromised Education ministry systems, and weak network segmentation meant sensitive tax applications were reachable from parts of that network that had no obvious reason to reach them. Investigators also saw signs of repeated attempts to pivot into other government bodies. None of the accounts used carried special privileges, yet they could reach large volumes of data, a question the audit did not examine.
Detection and response gaps
The agency's standard answer to a compromised account was a password reset, and that routine fired repeatedly without containing the intrusion. On the evening of June 23 a threat-intelligence provider flagged an account and a SOC ticket opened at 8:50 p.m. Paris time. At 4:26 a.m. the attacker began scraping E-Contact through ADER; at 10:40 a.m. the SOC reset the password, which silenced the PIGP warning but left the attacker's ADER session open and authenticated. The exfiltration continued for nearly 16 further hours, until 2:31 a.m. on June 25, and about 11 GB of traffic crossed between June 22 and 25 without prompting any alert. Similar cycles played out on June 7 and again in July, when extraction resumed on July 22 with another stolen account and was met with a reset on July 24.
The SOC was not monitoring ADER at all, and nobody correlated the weak signals that, per ANSSI, should have added up: logins at night, VPN use, IP addresses in India and other addresses already flagged as malicious. Nobody tracked how many requests each account made, even though scraping requires one request per page. ANSSI's own monitoring covers only the points where the RIE meets the internet, and it has no visibility into application logs, so activity from genuine employee accounts raised no suspicion. On June 9 the Education ministry circulated 17 indicators of compromise to every ministry; the attacker had already used one of the listed addresses and reused it weeks later.
Why it matters
RedEye argues the DGFIP could detect but could not respond: warnings appeared at least three times across June and July, and each was answered with a password reset rather than an effort to determine what the account was still doing. A reset does not terminate a live session, and until credential alerts are handled as intrusions spanning every application the account can reach, the attacker chooses when the incident ends. The breach also shows that a portal protected by a password alone assumes every device holding that password is clean, and that the real perimeter now includes devices outside the organization's control: staff laptops, a private surveyor's machine, another ministry's network. Finally, blaming a breach on sophistication before the audit is done risks credibility when the audit concludes the opposite.
- #data-breach
- #security
- #france
- #credential-theft
- #government-it