Illustration of a digital lock with French flag colors, symbolizing a cybersecurity breach on French government data.

French Tax Data Heist: Seven Weeks of Undetected Intrusion Exposes Critical Vulnerabilities

Share
Share
Pinterest Hidden

In a significant blow to France’s digital security, the nation’s tax administration, the DGFIP, fell victim to a sophisticated data theft that saw sensitive tax information belonging to hundreds of thousands of citizens and businesses siphoned off over a period of seven weeks. Alarmingly, neither the DGFIP nor France’s national cybersecurity agency, ANSSI, detected the exfiltration of this critical data as it occurred throughout June and July.

A Breach Unveiled: Scale and Scope of the Compromise

The incident, detailed in a recent ANSSI report, highlights glaring weaknesses in login protection, network segmentation, and monitoring protocols. The attacker leveraged stolen staff passwords to access E-Contact, the DGFIP’s taxpayer communication tool, compromising data for over 350,000 individuals and 250,000 businesses. While taxpayers’ personal online accounts remained secure, the stolen information is deeply personal and financially sensitive.

Individual Data Exposed:

  • Tax ID and contact details
  • Family situation
  • Reference taxable income
  • Tax withholding rate
  • A comprehensive list of messages exchanged with the DGFIP

For a smaller subset of fewer than 250 individuals, the actual content of these messages was also compromised.

Business Data Exposed:

  • Company name and SIREN registration number
  • Business address
  • Basic details of their communications with the DGFIP

Similarly, for under 2,076 businesses, the full content of their messages was also accessed.

The breach only came to light on August 12, when the attacker publicly claimed responsibility on an online forum, a staggering seven weeks after the initial data extraction began. This revelation prompted Prime Minister Sébastien Lecornu to mandate an in-depth audit by ANSSI, contrasting sharply with an earlier, less accurate explanation from the DGFIP’s overseeing ministry, which had attributed the undetected theft to the “sophistication of the attack.”

How the Attack Unfolded: Two Routes to Sensitive Data

ANSSI’s investigation revealed two distinct vectors of attack, both exploiting fundamental security shortcomings.

Route One: Exploiting Stolen Staff Credentials

The primary intrusion began in early May, targeting the E-Contact system. Dozens of DGFIP staff passwords, likely pilfered over three months by “infostealer” malware from unmanaged personal devices, were the key. The attacker exploited two portals, PIGP (used for email and HR) and ADER (providing access to DGFIP applications via the RIE, the government’s inter-ministerial network), both requiring only a single password for entry.

Crucially, the attacker gained access to the RIE through compromised systems within the Ministry of Education. Once inside, the lack of proper network segmentation meant sensitive DGFIP applications were accessible from parts of the RIE with no legitimate need, allowing the attacker to traverse the network and even attempt to breach other government bodies. Despite the compromised accounts having no special privileges, they yielded access to vast amounts of data, a point ANSSI noted without delving into user rights management in this report.

Route Two: Bypassing Partner Portal Security for Land Registry Data

A second, separate breach targeted land-registry data via APEX, a portal for external partners like notaries and land surveyors. This portal required both a password and a one-time email code. Investigators believe a land surveyor’s computer at a private firm had possibly been compromised, enabling the attacker to bypass the multi-factor authentication. This second phase of data theft occurred between July 27 and August 8, affecting nearly 435,000 households, as reported by the Senate finance committee.

A Failure in Detection: Why the Theft Went Unseen

Despite having a routine for managing stolen staff logins, the DGFIP’s Security Operations Center (SOC) repeatedly failed to identify the ongoing data exfiltration.

  • Missed Escalation: On June 7, suspicious activity led to a password reset, but the SOC missed the attacker’s pivot from PIGP to ADER.
  • Delayed Response & Persistent Access: On June 23, another compromised account triggered an alert. While a SOC ticket was opened, the attacker began automated data scraping from E-Contact via ADER hours before the account’s password was reset. Critically, this reset only addressed the PIGP alert and failed to terminate the attacker’s active session on ADER, allowing data to flow for another 16 hours.
  • Blind Spot: The ANSSI report explicitly states that the DGFIP’s SOC was not monitoring ADER at all, leaving a gaping hole in their defenses. Furthermore, there was no comprehensive system to link disparate warning signs, such as unusual login times (at night), connections from VPNs, or IP addresses originating from high-risk locations like India.

This prolonged and undetected breach underscores a critical need for enhanced cybersecurity vigilance, robust network architecture, and comprehensive monitoring within French government institutions to protect sensitive citizen and business data from future threats.


For more details, visit our website.

Source: Link

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *