Product1 distinct publisher3 min readUpdated
DGFiP says the intruder used a stolen employee identifier and an authorised third party's credentials, and claimed to bypass MFA. No zero-day was involved.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
France's Direction generale des Finances publiques says an attacker reached data on 678,000 individuals and businesses, and that the way in was not a software flaw but the stolen identifiers of a DGFiP employee and of an authorised third party [1][7]. For anyone running an enterprise estate, that is the load-bearing detail: the perimeter that failed was a set of valid logins the agency had issued to parties it trusted [9].
The intrusions happened in June and July, and the agency did not establish that anything had left its systems until the attacker said so in August [2][3]. On 12 and 13 August, someone using the alias ZeroBytes claimed the access on a cybercrime forum and offered a database for sale; DGFiP opened in-depth investigations the same day, and those produced the 678,000 figure [12]. That is a gap of one to two months between the intrusions and the moment the state learned from a criminal advertisement that data had gone [26].
DGFiP says it cut off every account involved as soon as it detected the intrusions, and that the access checks it ran at that point showed no sign of exfiltration, a failure the agency attributes to the sophistication of the attack [11]. The forum post read, in the version reported by Help Net Security, "I'm still logged into the panel, so if you want, you can buy it along with the database" [13]. The attacker also described bypassing multi-factor authentication, again according to Help Net Security [8]. Nobody outside the agency can test either claim.
The two sides do not agree on scale. ZeroBytes said the portal held records on roughly 20 million French citizens, that they had pulled 252,149 records covering more than two million people, and that scraping the rest would have taken months [15]. The government's number is 678,000, about a third of the attacker's people count and around 3.4 percent of the claimed 20 million [24][25]. DGFiP says its investigations continue and that it has not yet fixed the precise volume extracted or the final number of users concerned [16].
In a statement on 14 August the agency set out what was reachable: for individuals, reference tax income, family quotient and withholding tax rate; for companies, registered name and SIREN number [4]. The attacker also consulted cadastral records covering property addresses and floor areas [5]. What held: accounts on impots.gouv.fr were not compromised, and no taxpayer usernames or passwords were taken [6].
An authorised third party here means an outside body granted a route into the agency's systems, a category that includes notaries, bailiffs and local authorities, each of which widens the set of logins that will open the door [9]. The pattern repeats. INCYBER notes that fraudulent access to FICOBA, the national bank account register, was obtained a few months earlier, also with stolen credentials [22]. Help Net Security counts a third incident, at France Titres, in April [23]. Attackers reached 75,000 Fortinet firewalls in June using old passwords rather than a zero-day [10].
Prime Minister Sebastien Lecornu chaired an interministerial crisis cell on Monday, with a judicial investigation already running, Bloomberg reported [17]. Watch the two audits: ANSSI has been asked to establish the causes, and a separate review of DGFiP system security is due to produce operational conclusions in September, according to INCYBER [18]. The Paris prosecutor's investigation covers fraudulent extraction of data and criminal conspiracy [19]. Notifications to affected people started by email that evening and run through the week, and DGFiP has referred the matter to CNIL and says it will lodge a criminal complaint [20]. The government's April cybersecurity plan carries 200mn euros in additional investment and a target that from 2027 every ministry spends 5 percent of its digital budget on security [21]; whether any of that reaches third-party credential governance is the question the September conclusions will answer or dodge.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The agency did not establish that anything had left its systems until the attacker said so in August.
The attacker also described bypassing multi-factor authentication, according to Help Net Security.
DGFiP says it cut off every account involved as soon as it detected the intrusions; the access checks it ran at that point revealed no sign that data had left, and the agency attributes that failure to the sophistication of the attack.
ZeroBytes claimed the portal held records on roughly 20 million French citizens, said they had pulled 252,149 records covering more than two million people, and said scraping the rest would have taken months.
In a statement on 14 August, DGFiP said that for individuals the attacker reached reference tax income, family quotient and withholding tax rate, and for companies the registered name and SIREN number.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Official statements are specific; scope is provisional and single-sourced
The core facts rest on named official attribution - a dated DGFiP statement on 14 August, Bercy on the credential entry route, a prosecutor's investigation, and commissioned ANSSI audits - which is strong evidence for the mechanism and the response. It is held back by two things: the whole cluster is one publisher relaying its own reporting plus Help Net Security, Bloomberg and INCYBER, and the agency itself says the extracted volume and final affected-user count are not fixed. No independent technical verification of the attacker's MFA-bypass or live-session assertions exists in the supplied material.
Incident confirmed and formal state response already executing
Read as real-world materialisation rather than product uptake, the story is well past announcement. There is a dated agency disclosure, a live criminal marketplace listing, an interministerial crisis cell, ANSSI and ministry security-office engagement, precautionary shutdown of sensitive system access, a Paris prosecutor investigation, a CNIL referral and notifications already going out by email. What is not yet materialised is any confirmed downstream harm or a settled count, and the audits that would test either account only report in September.
Mildly overstated by the seller's numbers, which the article flags rather than adopts
The widest figures in circulation - a portal holding roughly 20 million records and extraction covering more than two million people - come from someone trying to sell a database, and are three to thirty times the officially counted 678,000. That is genuine inflation pressure on the story. The gap is small rather than large because the article foregrounds the discrepancy, attributes the big numbers to the seller, and repeats that DGFiP has not fixed the final count; the headline uses the official figure. Some downward pressure also exists from the agency's interest in a low provisional number, which keeps the net gap only modestly positive.
Both narrators have reason to shade the number
The disclosure environment is heavily incentive-loaded and the article says so. DGFiP and Bercy benefit from a bounded count, an enumerated list of what held, and an explanation that blames the attack's sophistication for its own checks missing the exfiltration. The seller benefits from maximal scope claims, a live-access boast and a 20 million record portal to raise the asking price. The government also has a political stake: it announced a 200mn euro state cybersecurity plan in April and was breached in June and July, so the crisis cell and September audits serve accountability optics as well as investigation. No supplied evidence points to vendor or commercial incentive in the coverage itself.
Mechanism solid, magnitude open, one publisher
Confidence is moderate. The intrusion mechanism, timeline, official response steps and regulatory posture are all attributed on the record and internally consistent, so the qualitative core is dependable. Magnitude is not: the count is provisional by the agency's own statement, the competing figures come from an interested seller, and the ANSSI audit that would arbitrate is still pending. With only one supplied publisher, there is no independent corroboration of the secondary attributions to Help Net Security, Bloomberg and INCYBER.
product
Nebius funds $4.5bn of AI capacity on terms that pay lenders mostly in stock2 distinct publishers
build
The $559M-versus-$12.3B quarter matters more than the $65B run rate4 distinct publishers
build
The $5m drought policy that paid nothing: Malawi's index was tuned to a crop nobody planted1 distinct publisher
invest
Nvidia's $500bn GPU pool makes the seller the guarantor of its own demand1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 17, 2026