Product1 publisher3 min readPublished
France's tax agency lost 678,000 records through logins it had issued itself
DGFiP says the intruder used a stolen employee identifier and an authorised third party's credentials, and claimed to bypass MFA. No zero-day was involved.
The Product Desk · Product desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The French tax agency (DGFiP) says an attacker took data belonging to 678,000 individuals and businesses.
- The intrusions at DGFiP happened in June and July.
- The agency did not establish that anything had left its systems until the attacker said so in August.
- In a statement on 14 August, DGFiP said that for individuals the attacker reached reference tax income, family quotient and withholding tax rate, and for companies the registered name and SIREN number.
- The attacker also consulted cadastral records covering the addresses and floor areas of properties.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
France's Direction generale des Finances publiques says an attacker reached data on 678,000 individuals and businesses, and that the way in was not a software flaw but the stolen identifiers of a DGFiP employee and of an authorised third party [1][7]. For anyone running an enterprise estate, that is the load-bearing detail: the perimeter that failed was a set of valid logins the agency had issued to parties it trusted [9].
The intrusions happened in June and July, and the agency did not establish that anything had left its systems until the attacker said so in August [2][3]. On 12 and 13 August, someone using the alias ZeroBytes claimed the access on a cybercrime forum and offered a database for sale; DGFiP opened in-depth investigations the same day, and those produced the 678,000 figure [12]. That is a gap of one to two months between the intrusions and the moment the state learned from a criminal advertisement that data had gone [26].
DGFiP says it cut off every account involved as soon as it detected the intrusions, and that the access checks it ran at that point showed no sign of exfiltration, a failure the agency attributes to the sophistication of the attack [11]. The forum post read, in the version reported by Help Net Security, "I'm still logged into the panel, so if you want, you can buy it along with the database" [13]. The attacker also described bypassing multi-factor authentication, again according to Help Net Security [8]. Nobody outside the agency can test either claim.
The two sides do not agree on scale. ZeroBytes said the portal held records on roughly 20 million French citizens, that they had pulled 252,149 records covering more than two million people, and that scraping the rest would have taken months [15]. The government's number is 678,000, about a third of the attacker's people count and around 3.4 percent of the claimed 20 million [24][25]. DGFiP says its investigations continue and that it has not yet fixed the precise volume extracted or the final number of users concerned [16].
In a statement on 14 August the agency set out what was reachable: for individuals, reference tax income, family quotient and withholding tax rate; for companies, registered name and SIREN number [4]. The attacker also consulted cadastral records covering property addresses and floor areas [5]. What held: accounts on impots.gouv.fr were not compromised, and no taxpayer usernames or passwords were taken [6].
An authorised third party here means an outside body granted a route into the agency's systems, a category that includes notaries, bailiffs and local authorities, each of which widens the set of logins that will open the door [9]. The pattern repeats. INCYBER notes that fraudulent access to FICOBA, the national bank account register, was obtained a few months earlier, also with stolen credentials [22]. Help Net Security counts a third incident, at France Titres, in April [23]. Attackers reached 75,000 Fortinet firewalls in June using old passwords rather than a zero-day [10].
Prime Minister Sebastien Lecornu chaired an interministerial crisis cell on Monday, with a judicial investigation already running, Bloomberg reported [17]. Watch the two audits: ANSSI has been asked to establish the causes, and a separate review of DGFiP system security is due to produce operational conclusions in September, according to INCYBER [18]. The Paris prosecutor's investigation covers fraudulent extraction of data and criminal conspiracy [19]. Notifications to affected people started by email that evening and run through the week, and DGFiP has referred the matter to CNIL and says it will lodge a criminal complaint [20]. The government's April cybersecurity plan carries 200mn euros in additional investment and a target that from 2027 every ministry spends 5 percent of its digital budget on security [21]; whether any of that reaches third-party credential governance is the question the September conclusions will answer or dodge.