Security1 publisher3 min readPublished Updated
ANSSI traces theft of data on 600,000 French taxpayers and firms to stolen staff passwords
ANSSI says stolen staff passwords let an attacker take data on about 600,000 French taxpayers and firms, and the theft went undetected for seven weeks. Its report blames password-only portals, a flat government network and a reset that left the attacker's session open.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Individuals' records came from E-Contact and include tax ID, contact details, family situation, reference taxable income and withholding rate; message text may have been taken for fewer than 250 people.
- For businesses, the data covers company name, SIREN number, address and basic message details, with message content possibly seen for fewer than 2,076 firms.
- Taxpayers' own online accounts and passwords were not compromised, according to the DGFIP.
- The theft became public on August 12, when the attacker claimed it on an online forum.
- A second route through the APEX partner portal took land-registry data on nearly 435,000 households, according to a Senate finance committee note dated September 4.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- contradiction ANSSI's verdict overturns the ministry's August explanation, so responsibility for the breach moves to the DGFIP's own login, segmentation and monitoring choices and away from the attacker's skill.
- decision A SOC that answers a flagged account with a password reset alone leaves established sessions working, so revoking sessions on every connected portal has to be part of the same response step.
- constraint Email one-time codes fell to one compromised partner computer on APEX, so adding the same factor to PIGP and ADER would do little against an attacker already on a user's device.
- exposure Other ministries on the RIE carry the same exposure, because a foothold in Education ministry systems was enough to reach DGFIP applications and the attacker kept probing other government bodies.
Several dozen DGFIP staff passwords were stolen over three months, probably by infostealers on computers the DGFIP did not manage, most likely staff's own devices, according to ANSSI's report [13]. Suspicious logins began in early May [12]. PIGP, the staff web portal for email and HR, and ADER, which opens certain DGFIP applications over the inter-ministry network known as the RIE, both asked only for a password [14]. A stolen one worked at once [14].
Using ADER meant being on the RIE. The attacker got onto that network through compromised Education ministry systems connected to it [15]. Sensitive DGFIP applications were not separated from the rest of the RIE and could be reached from parts of it with no apparent need [16]. Investigators found traces of many attempts to move into other government bodies on the network [17]. The accounts in use had no special privileges and still reached a large amount of data. ANSSI did not examine how user rights were managed [18].
The security operations center had a routine for stolen staff logins: reset the password when it detected a compromised account or a threat intelligence provider flagged one [22]. It caught some of the attacker's activity, but not the theft [26]. On June 7, searches from a stolen account raised an alert and got a same-day reset, but the SOC missed that the attacker had moved from PIGP to ADER [23]. On June 23 the provider flagged another account, and searches with it opened a ticket at 8:50 p.m. Paris time [24]. At 4:26 a.m. the attacker started pulling E-Contact data through ADER with automated tools that copy it page by page, 7 hours 36 minutes after the ticket opened [24][3]. The SOC handled the ticket at 10:40 a.m. with a password reset, about six hours into the scrape [25][4]. That reset cleared the alert on PIGP. It did not end the attacker's open session on ADER [25].
Counting back seven weeks from the forum claim lands on June 24, the morning the scraping began [2]. In August, the ministry overseeing the DGFIP said its access checks had not revealed the theft "because of the sophistication of the attack" (translated from French) [11]. Prime Minister Sébastien Lecornu asked ANSSI for an in-depth audit after the claim [10]. The agency's report, published Tuesday, says the attack was not sophisticated [3].
A second factor did not stop the attacker on the other route. APEX, the portal for partners such as notaries and land surveyors, asked for a password and a one-time code sent by email [19]. The DGFIP's investigation found that a land surveyor's computer at a private firm had possibly been compromised, and that this let the attacker bypass the code [20]. Land-registry data left between July 27 and August 8 [20].
On both routes, the weak point identified was a machine outside DGFIP control: most likely staff's own devices on the first, possibly a private firm's computer on the second [13][20].
What to watch
- Whether ANSSI or the DGFIP examine how accounts with no special privileges could reach bulk E-Contact data, since the report left user-rights management out of scope.
- Whether the traces of attempted moves into other government bodies on the RIE turn into confirmed intrusions outside the DGFIP.
- Whether the attacker behind the August 12 forum claim is publicly identified or tied to other thefts of government data.