threat_intelligence434 wordsRead on Huntaegis

ANSSI Discloses Tax Data Theft After Stolen Staff Passwords Enabled Undetected Access for Seven Weeks

539/69 Thursday, October 1, 2026 France’s national cybersecurity agency, ANSSI, has published a report on a cyberattack targeting the Direction générale des Finances publiques (DGFIP), the French tax administration responsible for the impots.gouv.fr website. Attackers used stolen staff passwords to gain access to systems and exfiltrate tax-related data belonging to individuals and businesses between June and July 2026. The incident affected information associated with more than 350,000 individuals and over 250,000 businesses. The exposed data came from E-Contact, a system used by taxpayers to communicate with DGFIP. Taxpayers’ online accounts and passwords were not directly compromised. For individuals, the data that may have been accessed or copied included tax identification numbers, contact information, family status, net taxable income, withholding tax rates, and records of messages exchanged with DGFIP. In fewer than 250 cases, the contents of messages may also have been accessed. Business-related data included company names, SIREN registration numbers, addresses, and basic message details, while the contents of messages may have been accessed in fewer than 2,076 business cases. The report stated that the attack was not technically sophisticated but succeeded because of weak login protections, insufficient network segmentation, and monitoring gaps. The attackers used dozens of staff passwords believed to have been stolen by infostealer malware from devices not managed by DGFIP, such as personal devices, and used them to access password-only portals including PIGP and ADER before reaching E-Contact. Another access path involved APEX, a portal used by partners such as notaries and land surveyors for land registry-related services. The incident was detected on August 12 after the attackers claimed responsibility on an online forum, approximately seven weeks after the first data theft occurred. Before then, DGFIP’s SOC had detected some suspicious activity and reset passwords for affected accounts, but failed to identify that the attackers had moved from PIGP to ADER and still maintained active sessions. As a result, data extraction from E-Contact continued for nearly another 16 hours. DGFIP’s SOC was also not monitoring ADER and had no alerts for abnormal data volumes or request activity, including 11 GB of data exchanged between June 22 and 25. ANSSI’s network sensors also failed to detect the activity because the attackers were using legitimate staff accounts, while the agency did not have access to application logs. ANSSI recommended that DGFIP invalidate all active sessions whenever passwords are reset, conduct retrospective investigations when accounts are identified as compromised, enforce MFA across all applications without relying solely on one-time codes sent by email, monitor all business applications through SIEM, establish data access quotas, and prevent personal devices from accessing agency resources. Source: https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.