ANSSI has published its investigation into this summer’s data thefts at the French tax administration. Its conclusion: no sophisticated attack, but stolen passwords, missing multi-factor authentication and no detection. Three weaknesses most companies share.
What happened
On 12 August 2026 a group calling itself Zerobytes claimed the theft of data from impots.gouv.fr — about 353,000 individuals and 252,000 businesses, taken from a citizen-relationship tool. A day later it claimed a second batch: land-registry data held by the DGFiP. ANSSI, France’s national cybersecurity agency, was asked by the Prime Minister to investigate and has now published its report.
The findings are sobering. The first exfiltration had taken place seven weeks before the claim, after weeks of exploration. Neither the DGFiP’s monitoring nor ANSSI’s own sensors noticed anything: 11 GB downloaded over three days in June and 3 GB in July raised no alert.
How the attackers got in
- Stolen passwords: dozens of genuine staff credentials, collected over three months, most likely by info-stealing malware on personal computers the administration did not manage.
- No strong authentication on two portals, one of which gave access to sensitive resources.
- A weak second factor: for the land-registry data, the computer of a surveyor in a private firm was compromised, and the one-time code sent by email did not stop the attacker.
- A flat network: sensitive applications were reachable from the government’s shared network, which the attacker entered through another compromised ministry.
ANSSI sums it up plainly: this was not a sophisticated attack, but the exploitation of weaknesses in identity, architecture and detection.
Lessons for your company
- Put strong MFA on everything exposed — VPN, webmail, admin panels, business portals — using an authenticator app or a hardware key rather than codes sent by email or SMS.
- Treat unmanaged devices as compromised: a password typed on a personal or partner computer can end up on sale. Watch for leaked credentials, but do not rely on that alone.
- Partition: partners and subcontractors should reach only what they need, with per-account limits on how much data can be read.
- Monitor every application, not just the network edge, and alert on the obvious signals the report lists: unusual volumes, bursts of requests, night-time logins, VPN or blacklisted IP addresses.
Our take
The same pattern — a stolen password, no second factor, nobody watching the logs — is what we find in most incidents at small and mid-sized companies. The good news is that the fixes are known and affordable; what they need is someone to put them in place and keep them running.
Sources
- ANSSI — L’ANSSI publie le rapport d’incident sur les cyberattaques ayant touché la DGFiP
- ANSSI — Rapport d’incident DGFiP (PDF, TLP:CLEAR)
- The Hacker News — French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
Worried your servers are exposed? Our team audits, patches and monitors Linux and cloud infrastructure 24/7.
Talk to an expert