Skip to content
InYourGeek
visiteur@inyourgeek — shell
↹ compléter↑↓ historique⏎ ouvrirhelp
FR
Security· 3 min read

ANSSI report: DGFiP breach came from stacked failures, not a hack

ANSSI published its report on the DGFiP intrusion on 30 September 2026, a breach that exposed data on 678,000 taxpayers and businesses. Its conclusion: no sophisticated attack, only accumulated weaknesses.

Illustration of a French tax administration data centre, evoking the DGFiP intrusion analysed by ANSSI

No exploit, three areas of weakness

The DGFiP, France’s public finances directorate, acknowledged over the summer an intrusion into its IT systems, with access to data concerning 678,000 taxpayers and businesses. On 30 September 2026, the national cybersecurity agency ANSSI published its incident report, whose contents are detailed by Next. One sentence carries the whole document: “The compromise of the DGFiP’s information systems is not the consequence of a sophisticated attack, but of the exploitation of weaknesses in three areas.” Those three areas are identity, network architecture and signal detection. Nothing in the report describes a technique you would call novel.

The intrusions began as early as May 2026. On volume, the agency states that the stolen data concerns “close to 353,000 individuals and 252,000 professionals, obtained from a DGFiP tool for managing relations with users” — a portion of the total announced in August. Two suspects, aged 16 and 18, were arrested in late August; one has been charged and placed in pre-trial detention.

The attacker already had the passwords

The starting point is not a technical break-in but valid credentials. ANSSI writes that “no brute force or credential stuffing attempt was identified, which means the attacker had passwords for these accounts (which may have been valid or expired).” Accounts are anonymised in the report: internal accounts are numbered up to 22, external ones up to 7, so close to thirty accounts compromised by infostealer. One of the explanations retained for how they were obtained is “the leaking of login credentials, frequent and consequent to the use of personal devices.”

On external access, the report is precise: “the DGFiP’s investigations will show that the compromise of the workstation of a chartered surveyor within a private practice made it possible to bypass two-factor authentication by email, then to access and exfiltrate data between 27 July 2026 and 8 August 2026.” To that is added “the absence of strong authentication on two portals, one of which gives access to sensitive resources.”

A password reset that interrupted nothing

The DGFiP reset the passwords. But a reset is not enough if the machines stay infected and the open sessions are not cut. That is exactly what happened: the reset of 24 June 2026 “does not interrupt the session and the ongoing exfiltration, which continue,” the agency notes in its timeline of events.

Signals available, never escalated

The third strand is detection. “The exfiltration sessions carried out by the attacker were not detected in real time by the control mechanisms implemented on the business applications or on the DGFiP’s security equipment,” ANSSI finds. The indicators did exist, and they were elementary: “the volume of information exchanged during connections (11GB between 22 and 25 June, 3GB between 21 and 23 July),” as well as “the number of requests per user over a time window.” Next also notes, among the signals that went unnoticed, an IP address located in India and night-time connections.

Every link in this chain maps to a control you would expect to find in place: hardening access from unmanaged equipment, strong authentication on sensitive portals, session invalidation, volume thresholds. For the 678,000 individuals and businesses whose data left the building, the distinction between a sophisticated attack and an accumulation of failures changes nothing about the outcome.

Sources (1)

Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.