Stolen Staff Passwords Let Attacker Raid French Tax Data for Seven Weeks Undetected
France's national cybersecurity agency, ANSSI, has confirmed that a data theft from the tax administration (DGFIP) went unnoticed for seven weeks in June and July. The attacker gained access using stolen staff passwords, probably harvested by infostealer malware from personal devices not managed by the tax agency, and used them to log into internal portals that required only a password with no additional verification.
The stolen data affected a little over 350,000 individuals and 250,000 businesses, taken from a messaging tool called E-Contact. Exposed information included tax IDs, contact details, income references and message summaries, with the full content of messages accessed for a smaller subset of victims. Taxpayers' own online accounts and passwords were not compromised. The breach was only discovered on 12 August when the attacker publicised it on an online forum, prompting an official audit that found the intrusion was not especially sophisticated but succeeded due to weak login protections, poor network separation and monitoring gaps.
ANSSI's findings show that even government-grade systems can be undone by basic weaknesses such as single-factor logins and unmanaged devices. For small businesses, the case is a reminder that stolen credentials, often taken quietly by malware on personal or poorly secured machines, can lead to serious breaches that go unnoticed for a long time.