
French Tax Breach Exposes 600k Records via Infostealer-Stolen Passwords and Flat Government Networks
Stolen staff passwords enabled seven-week undetected access to French tax data on over 600,000 entities due to missing MFA and poor network segmentation. Official claims of sophistication contradict ANSSI evidence of basic credential abuse. The breach reveals systemic gaps in monitoring unmanaged endpoints and lateral movement controls across government networks.
The attacker leveraged dozens of passwords harvested by infostealers over three months, bypassing single-factor portals PIGP and ADER on the RIE network. Lateral movement from compromised Education ministry systems succeeded because DGFIP applications lacked isolation from partner-connected segments. A second vector via APEX exploited a land surveyor's compromised endpoint to bypass email OTP, exfiltrating land-registry details on 435k households between 27 July and 8 August. ANSSI's post-incident review confirms no sophisticated tooling was required.
Ministry statements initially attributed the undetected exfiltration to attack sophistication, yet ANSSI documented routine weak login controls, absent MFA on internal portals, and SOC alerts that triggered password resets without tracing data movement. This mirrors prior French government incidents where infostealer campaigns against contractor devices enabled RIE traversal. The pattern shows credential reuse across managed and personal endpoints remains the dominant vector, not novel exploits.
DGFIP's existing stolen-login routine caught isolated activity on 7 June but missed the broader campaign until the actor's forum claim on 12 August. Senate finance committee documentation and ANSSI findings together indicate prolonged exposure stemmed from insufficient logging correlation and rights review rather than technical complexity. Expect mandated MFA enforcement and RIE segmentation audits within six months.
Next steps include Prime Minister-directed ANSSI expansion of the audit to other ministries and likely procurement of endpoint detection for all staff devices. Without device management mandates, similar credential theft will recur across interconnected French government networks.
DGFIP: Mandatory MFA and endpoint detection on all staff devices within 9 months or repeat credential incidents exceed 2025 baseline by 30%.
Sources (3)
- [1]ANSSI Rapport d'audit DGFIP(https://www.ssi.gouv.fr/rapport-dgfip-2026)
- [2]Note Commission des finances Sénat 4 septembre(https://www.senat.fr/commission/finances/note-dgfip-2026)
- [3]DGFIP communiqué 12 août(https://www.impots.gouv.fr/actualites/breach-econtact)