Cyber & AI intelligence
Wasteland.
Briefs indexed2948
Issues30
Published Mondays07:30 CT
▣ Breach FRENCH-TAX-ADMINIS 2026-09-30

DGFiP: Stolen Staff and Contractor Credentials Fuel Seven-Week Tax Data Theft

"An attacker used stolen login credentials belonging to staff at France's General Directorate of Public Finances (DGFiP) and to an authorised outside party to take tax data on hundreds of thousands of taxpayers and…"

An attacker used stolen login credentials belonging to staff at France's General Directorate of Public Finances (DGFiP) and to an authorised outside party to take tax data on hundreds of thousands of taxpayers and businesses in June and July 2026. Nobody noticed the theft until the actor, using the alias "ZeroBytes", advertised the data on a cybercrime forum on 12 August, about seven weeks after the first batch left DGFiP systems. Accounts of the scale differ. DGFiP first put the total at 678,000 individuals and professionals (Help Net Security, The Next Web). Its later FAQ gives roughly 600,000 (The Register). The breakdown cited in the ANSSI incident report and in DGFiP's updated figures is about 353,000 individuals and 252,000 businesses (The Hacker News, Mac4Ever). ZeroBytes claimed data on more than 2 million people. That claim has not been verified. A 20-page report from France's national cybersecurity agency ANSSI, published on 29 September, found the intrusion "was not the consequence of a sophisticated attack". That contradicts the ministry's explanation in August.

This incident is separate from the FICOBA bank-account registry breach covered earlier. DGFiP runs both systems, but none of the reporting here links the two. The systems affected here are the E-Contact messaging tool on impots.gouv.fr and cadastral (land registry) records. The timeframe is June to August 2026, and the actor claiming the theft is ZeroBytes.

What Happened

According to reporting on the ANSSI report, the investigation covered malicious activity on DGFiP systems between May and August 2026. It centred on two data thefts that ZeroBytes claimed on 12 and 13 August (Mac4Ever).

The ANSSI findings directly contradict the ministry's August account. The agency concluded that the compromise came from "the exploitation of weaknesses in three areas": identity, architecture and detection (01net).

What Was Taken

The figures have changed over time, and DGFiP has not explained why.

Source Figure
DGFiP, 14 August statement (via Help Net Security, The Next Web) 678,000 individuals and professionals
FrenchBreaches monitoring platform (via TechRepublic) ~678,000 records: ~393,000 individuals, ~286,000 professionals (Reuters noted the ministry had not confirmed these)
DGFiP FAQ, later in August (via The Register) ~600,000 total
DGFiP and ANSSI report (via The Hacker News, Mac4Ever) ~353,000 individuals and ~252,000 businesses
ZeroBytes claim (via Help Net Security) 252,149 records covering "more than 2 million people", taken from a portal the actor said held ~20 million citizens

Individuals: tax ID number, email and postal addresses, phone numbers, marital status, household composition and number of dependents, family quotient, reference taxable income, withholding tax rate, and a list of messages exchanged with DGFiP. For fewer than about 250 people, the content of those messages may also have been taken (The Hacker News, The Register). TechRepublic, citing Brussels Signal, also lists dates of birth. Other sources do not confirm that.

Businesses: company name, SIREN number, address and basic message metadata. For fewer than 2,076 businesses, message content may have been seen (The Hacker News).

Cadastral data: property addresses and floor areas. DGFiP says this information was already public (The Register, The Next Web).

Not affected: DGFiP says taxpayers' personal and professional impots.gouv.fr accounts were not compromised, and no taxpayer usernames or passwords were taken (The Hacker News, The Next Web).

Why It Matters

The Attack Technique

Initial access: ANSSI says the credentials were "probably" stolen by infostealer malware on computers DGFiP did not manage, including agents' personal devices (01net). The Senate note, as reported by bdor.fr, also points to an infostealer as the likely source for the credentials used to enter the RIE.

MFA weaknesses: Mac4Ever reports that ANSSI found no strong authentication on some access paths. In the cadastral theft, the compromised surveyor's workstation allowed the attacker to get around two-factor authentication delivered by email. ZeroBytes separately claimed an "MFA bypass technique" (Help Net Security). That fits a scenario in which an infostealer on the endpoint captures both the password and the email-delivered code, or the session itself.

Lateral movement: ANSSI criticised weak separation between networks and applications (The Hacker News, Mac4Ever). Once in, the attacker could explore DGFiP systems for weeks before reaching E-Contact.

Exfiltration: The data was pulled through legitimate application interfaces using valid accounts. ZeroBytes complained that the portal was "horrible to scrape" and that a full extraction would have taken months (Help Net Security). That suggests slow, application-level harvesting rather than bulk database dumps, and this kind of activity blends in with normal agent use unless query volume is being monitored.

Detection: ANSSI says suspicious signals went unnoticed (Mac4Ever). DGFiP's own access review after the accounts were suspended failed to show that data had been taken.

What Organizations Should Do

  1. Require phishing-resistant MFA for every staff and third-party account that reaches sensitive data. Email and SMS codes do not protect you if the endpoint is compromised. Use FIDO2 or certificate-based authentication, especially for external partners.
  2. Block sensitive applications from unmanaged devices. Use device posture checks or conditional access so that a password taken from an agent's home PC cannot open citizen or customer records.
  3. Monitor infostealer log markets for your domains. Check stealer-log feeds for staff and contractor credentials, and rotate credentials and revoke sessions as soon as a hit appears.
  4. Separate networks and applications. Access to a shared government or corporate network should not give a path to high-value applications. Put identity-aware controls in front of each sensitive system.
  5. Alert on how much data an account pulls, not just on logins. Set baselines for each user's record lookups and exports in applications like E-Contact. Flag sustained high-volume lookups and access to many unrelated taxpayers or customers.
  6. Treat account suspension as the start of an investigation. When you cut off suspicious access, reconstruct everything the accounts did from application logs before you conclude that no data was taken.

Sources: French Tax Data Theft Using Stolen Staff Passwords Went Undetected... | France’s tax authority admits hackers made off with data on 678,000... | French tax authority says break-in exposed data of 600K, including... | Piratage des impôts : l'ANSSI révèle ce qu'il s'est vraiment passé... | France’s tax agency lost data on 678,000 people to a stolen login | Piratage des impôts : l’ANSSI détaille les failles qui ont permis l... | French Tax Authority Breach Exposes Sensitive Taxpayer Data | Piratage du fisc : le Sénat révèle comment les données des Français...