deniz.in

Markets

Weather

Loading weather

· via Hacker News – Front Page (native)

French tax agency breach exposed 678,000 records; second hack may affect millions

France's DGFiP confirmed a breach exposing tax data on 678,000 people, detected only after the data was offered for sale. A second claimed attack may affect more than two million.

French tax agency breach exposed 678,000 records; second hack may affect millions

France's public finance administration, the DGFiP, has confirmed a major intrusion that leaked a file of 678,000 entries covering both individuals and professionals. According to Cybernetica, a French security newsletter that published a detailed account of the incident, the director general of public finances, Amélie Verdier, confirmed the figures and the affected data categories on the evening of Friday, 14 August.

What was exposed

The administration confirmed that the leaked file contains names, family quotient, reference tax income and withholding tax rate. An analysis of the attacker's claimed dataset by FrenchBreaches, cited by Cybernetica, found additional fields: postal address, phone number, email address and the number of dependents per household. That combination gives anyone who buys the data a rich profile of each victim.

A breach detected weeks late

The timeline may matter more than the intrusion itself. According to Cybernetica, the attacker's access was cut off at the end of June, but the exfiltration that had already taken place was not detected at that point. The breach surfaced only on 12 August, once the stolen data was put up for sale — roughly six weeks after the attacker lost access, and long after the data had left the system.

A second attack, a criminal probe and political fallout

The same attacker has claimed a second intrusion, carried out at the end of July against the server used by professionals for cadastral data. Cybernetica reports that the administration confirmed this second attack took place, although the figure of more than two million people affected comes from the attacker's own claim and awaits verification.

The attacker said his initial foothold came through a VPN used by tax officials, and mocked the state's security in public messages, remarking that people should wake up to the fact that "France is a sketch".

The Paris prosecutor's office opened an investigation on Saturday, 15 August, handing it to the Office anticybercriminalité, and affected individuals were to be notified one by one starting the following week — nearly two months after the intrusion. MEP Aurore Lalucq, co-president of Place publique, has publicly called for the resignation of David Amiel, the minister for public accounts, arguing that the attacker "went in and came out with the till".

A wider pattern of state breaches

As Cybernetica notes, the tax authority is not an isolated case. On the night of 25–26 July, an intruder entered the information system used for training staff at the national education ministry, using the same technique as at the DGFiP: takeover of a professional account. The data involved covers all staff who have worked in the academies since 2001 — identity, status and functions, plus postal address, phone number and social security number for some — and the ministry has published no figure for the scale. The 31 July announcement went largely unnoticed; it was the education system's third breach since January. The finance ministry, meanwhile, had already suffered another cyberattack a few weeks earlier.

Legal exposure under the GDPR

Cybernetica also points to a precedent that may shape the aftermath. After the July 2019 breach of Bulgaria's national revenue agency, which put the tax and social data of six million people online, the Court of Justice of the EU ruled in December 2023 that fear of future misuse of one's data is itself compensable harm, that the burden of proof lies with the administration to show its security measures were appropriate, and that criminal third parties being responsible does not automatically exonerate the state. The ruling interprets the GDPR and therefore applies in France as well.

Why it matters

Cybernetica's core argument is that the real failure is not that an attacker got in — intrusions are inevitable — but that the compromise went undetected for weeks, that a single set of hijacked credentials appears to have yielded entire databases, and that citizens learn their data is gone only once it is offered for sale. With the French state simultaneously pushing cloud adoption and, more recently, AI across its systems, the episode puts detection capability, privileged access design and institutional accountability under scrutiny — by prosecutors, by the public, and by politicians now demanding resignations.

  • #cybersecurity
  • #data-breach
  • #france
  • #gdpr
  • #government

Related posts