Threat Intelligence

Stolen Staff Passwords Let Attacker Raid French Tax Data for Seven Weeks Undetected

The Hacker News · 30 Sept 2026
Key Takeaway Enable multi-factor authentication on all business logins and ensure staff devices used for work are properly secured and monitored, since stolen passwords alone are often enough to breach systems that rely on single-factor login.

France's national cybersecurity agency, ANSSI, has confirmed that a data theft from the tax administration (DGFIP) went unnoticed for seven weeks in June and July. The attacker gained access using stolen staff passwords, probably harvested by infostealer malware from personal devices not managed by the tax agency, and used them to log into internal portals that required only a password with no additional verification.

The stolen data affected a little over 350,000 individuals and 250,000 businesses, taken from a messaging tool called E-Contact. Exposed information included tax IDs, contact details, income references and message summaries, with the full content of messages accessed for a smaller subset of victims. Taxpayers' own online accounts and passwords were not compromised. The breach was only discovered on 12 August when the attacker publicised it on an online forum, prompting an official audit that found the intrusion was not especially sophisticated but succeeded due to weak login protections, poor network separation and monitoring gaps.

ANSSI's findings show that even government-grade systems can be undone by basic weaknesses such as single-factor logins and unmanaged devices. For small businesses, the case is a reminder that stolen credentials, often taken quietly by malware on personal or poorly secured machines, can lead to serious breaches that go unnoticed for a long time.

data breach credential theft infostealer malware government security multi-factor authentication

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.