France DGFiP tax admin: ANSSI incident report — ~353k individuals + ~252k businesses via stolen staff passwords; undetected ~7 weeks
ANSSI (published 29 September 2026; report remitted to the Prime Minister 24 Sep, document dated 23 Sep, TLP:CLEAR PDF) details malicious activity on Direction générale des Finances publiques (DGFiP) systems between May and August 2026. Actor Zerobytes claimed theft from impots.gouv.fr / E-Contact taxpayer messaging on 12 August; ANSSI notified DGFiP the same day. Claimed scope: nearly 353,000 individuals and 252,000 professionals (tax ID/contact/family/income/withholding and message metadata; taxpayer online accounts/passwords not compromised). Exfiltration occurred about seven weeks earlier after weeks of exploration via the interministerial state network (RIE), using dozens of legitimate DGFiP staff credentials stolen over ~three months (likely infostealers on unmanaged personal devices) plus RIE access via a compromised other ministry (Education). Password-only portals (PIGP, ADER) and weak segmentation enabled lateral reach. A second Zerobytes claim (13 Aug) covered cadastral data after compromise of a private land-surveyor workstation bypassed email OTP on the APEX partner portal (exfil ~27 Jul–8 Aug). Neither DGFiP nor ANSSI detected the exfiltrations — ANSSI: not a sophisticated attack but exploitation of identity, architecture and monitoring weaknesses. Containment (cutting agent/partner portal access) disrupted services. Wire: The Hacker News 29 Sep. Primary: ANSSI actualité + incident PDF.
- Product
- DGFiP / impots.gouv.fr E-Contact + partner APEX cadastral portals (French tax administration)
- Versions
- n/a — credential/portal and network-architecture incident (not a named product CVE); ANSSI/DGFiP remediation: MFA on portals, stop personal-device access to sensitive apps, extend monitoring/quotas, fuller audit ordered by PM
- Exploited in Australia?
- unknown
- Patch to
- No CVE patch path. Defenders (esp. gov/tax/shared ministerial networks): enforce phishing-resistant MFA on staff and partner portals; ban unmanaged personal devices for privileged/tax apps; segment sensitive apps off shared inter-agency networks; correlate volume/anomaly alerts on messaging and partner portals; hunt infostealer-exposed staff credentials. AU orgs with FR tax/partner exposure: watch DGFiP/impôts FAQs for affected-taxpayer notices.
Primary: ANSSI — Rapport d’incident cyberattaques DGFiP (actualité 29 Sep 2026) · Vendor: ANSSI — Rapport d’incident DGFiP PDF (23 Sep 2026; TLP:CLEAR) · The Hacker News — French tax data theft via stolen staff passwords (29 Sep 2026)
