Skip to content

Build1 publisher3 min readPublished

ANSSI traces the DGFIP tax breach to stolen passwords on password-only staff portals

ANSSI says an attacker used dozens of stolen DGFIP staff passwords on password-only portals to take data on over 600,000 French taxpayers and businesses. For other operators, the fixes are login checks on devices they do not manage and a password reset that also ends live sessions.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying ANSSI traces the DGFIP tax breach to stolen passwords on password-only staff portals
Generated illustration

What happened

  • A June 23 alert led to a password reset the next morning, but the attacker's ADER session stayed open and data kept flowing until 2:31 a.m. on June 25.
  • A second route through APEX, a partner portal guarded by a password and an emailed code, yielded land-registry data on nearly 435,000 households between July 27 and August 8.
  • Neither the DGFIP nor ANSSI saw the data leave, and the theft surfaced on August 12 when the attacker claimed it on an online forum.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure Any organization whose staff can reach internal portals with a password alone from unmanaged devices is open to the same route, and it needs no exploit.
  • decision SOC playbooks that answer a stolen credential with a password reset alone leave issued sessions running; at the DGFIP that allowed about 16 hours of scraping after the reset.
  • constraint An emailed one-time code does not close the gap by itself: APEX's code was bypassed from a compromised partner computer, so device trust has to be part of the control.
  • contradiction ANSSI's verdict of an unsophisticated attack undercuts the ministry's August explanation and places the cause in controls the DGFIP chose and operated.

The June 23 incident is where the DGFIP's routine for stolen logins broke. The timeline comes from a dev.to account of ANSSI's report, which cites The Hacker News [17].

1. 8:50 p.m., June 23: a threat intelligence provider flags an account and the SOC opens a ticket [17]. 2. 4:26 a.m. the next morning: the attacker starts scraping E-Contact through ADER [17]. 3. 10:40 a.m.: the SOC resets the password. That clears the PIGP alert but does not end the attacker's ADER session [18]. 4. 2:31 a.m., June 25: the data stops flowing, almost 16 hours after the reset [18].

The ticket sat for 13 hours and 50 minutes before the SOC acted [2]. The ADER scrape ran for about 22 hours, and about six of those came before the reset [3].

A password reset changes what the next login needs. It does nothing to a session an application has already issued, and ADER's session outlived the password that opened it [18]. The DGFIP's answer to a compromised account was a reset, and that routine fired several times [19]. On June 7, an alert on searches from a stolen account got a same-day reset, but the SOC missed the attacker's move onward from PIGP [19]. According to the same account, the SOC never watched ADER [20].

The way in was ordinary. Several dozen staff passwords were stolen over three months, probably by infostealers on computers the DGFIP did not manage, most likely staff's own devices [12]. PIGP, used for email and HR, and ADER, which reaches DGFIP applications over the RIE, asked for a password and nothing else [13]. The attacker got onto the RIE, the network linking French ministries, through compromised Education ministry systems [14]. Sensitive DGFIP applications were reachable from parts of that network with no apparent need for them [15]. None of the accounts held special privileges, yet they could reach a large amount of data. ANSSI did not examine how user rights were managed [16].

The second route complicates the obvious fix. APEX, the portal for notaries and land surveyors, asked for a password plus a one-time code sent by email [11]. The DGFIP found that a land surveyor's computer at a private firm had possibly been compromised, and that let the attacker bypass the code [11]. A code on PIGP and ADER would have stopped a password lifted from a home laptop from working by itself [13]. APEX shows the code gave way once the machine using it was compromised [11]. For a portal in front of tax records, I would keep unmanaged machines off it entirely.

The E-Contact haul covers over 600,000 individuals and businesses [1]. For individuals it includes tax ID, contact details, family situation, reference taxable income, withholding rate and a list of messages exchanged with the DGFIP [8]. Message contents may have gone for fewer than 250 people and fewer than 2,076 businesses [9]. Taxpayers' own online accounts and passwords were not compromised [10].

In August, the ministry overseeing the DGFIP said access checks had not revealed the theft "because of the sophistication of the attack" [6]. ANSSI's verdict is that the attack was not sophisticated [5]. On ANSSI's account, the clever part was that the passwords worked. The agency, which Prime Minister Sebastien Lecornu asked for an in-depth audit, puts the breach down to weak login protection, poorly separated networks and gaps in monitoring [7].

What to watch

  • Whether ANSSI follows up on how DGFIP user rights were managed, given that unprivileged accounts could reach large amounts of data.
  • Whether the traces of attempts to move from the RIE into other government bodies turn into confirmed breaches elsewhere.
  • Whether the DGFIP ends password-only access to PIGP and ADER and adds session revocation to its reset routine.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories