DGFiP Unauthorized Access Exposes 680000 Taxpayer Records
DGFiP breach exposed records of 680000 taxpayers via credential compromise. Evidence points to persistent authentication weaknesses documented in prior ANSSI audits. CNIL investigation underway with potential enforcement actions within 18 months.
The breach occurred through compromised credentials on a DGFiP portal used for taxpayer file management. Attackers extracted names, addresses, tax identification numbers, and income brackets. No bank details or payment information were reported taken. Official notification to affected individuals began in late 2024 via the CNIL-mandated process.
Data volume matches patterns in prior French public sector incidents where legacy authentication lacked multi-factor enforcement. Cross-reference with 2022 ANSSI reports shows repeated findings on weak access controls in tax administration databases. The 680000 figure represents approximately 1.6 percent of French taxpayers, concentrated in specific regional directorates.
Operational impact includes mandatory identity verification resets for exposed accounts and increased fraud monitoring by banks. CNIL opened an investigation under GDPR Article 33 timelines. Similar exposures in Belgium's SPF Finances in 2023 resulted in 2.4 million euro penalties after 18-month reviews.
DGFiP has deployed additional logging and endpoint detection on affected segments. Full remediation audit due by Q2 2025.
CNIL: Administrative fine above 3 million euros issued within 18 months.
Sources (2)
- [1]Primary Source(https://www.cnil.fr/fr/actualite/breche-donnees-dgfip-2024)
- [2]Supporting Source(https://www.ssi.gouv.fr/publication/rapport-annuel-2023-acces-non-autorises)