On Tuesday, September 29, 2026, the National Agency for the Security of Information Systems (ANSSI) released a report detailing a significant data breach at the Direction générale des Finances publiques (DGFiP), France's tax administration. The breach occurred between June and July 2026 and exposed the data of hundreds of thousands of French citizens. According to the report, the attack did not exploit a highly complex technical vulnerability but instead took advantage of insufficient security measures, such as the absence of multi-factor authentication on several services and the exposure of business applications. The breach involved two major datasets: one from the E-Contact user contact tool and the other from cadastral data accessed through a firm of expert surveyors. The attacker obtained numerous identifiers and passwords from DGFiP agents or external users through infostealers, a type of spyware installed on personal or partner devices. The attack required some preparation but could have been easily avoided if certain services had not been accessible with just a single password. ANSSI highlighted the lack of multi-factor authentication on several services and the insufficient protection when it was in place. For example, the APEX portal used a code sent by email as a second factor, which was bypassed when an expert surveyor's workstation was compromised. The report also noted that the ADER portal, used to access E-Contact and extract data, was not monitored by the DGFiP's SOC, the team responsible for monitoring systems and detecting suspicious behavior. Numerous signals indicated the breach, including unusual data transfers, connections made at night or from foreign IP addresses, and automated data scraping. ANSSI noted that 11 GB of data was transferred between June 22 and 25, and then 3 GB between July 21 and 23, without any alerts being triggered. Some accounts were reset after alerts, but this was not enough to stop the attacker. The hacker also used the compromised infrastructure of the Ministry of National Education to access the Interministerial Network of the State and reach the DGFiP. The breach had been ongoing for weeks before being publicly exposed. On August 12, a hacker named Zerobytes claimed to have stolen data from impots.gouv.fr on an online forum. The ANSSI alerted the DGFiP that same day, and the hacker detailed the extent of the breach the following morning. The data came from E-Contact, an internal messaging system used by tax authority agents to communicate with taxpayers. While the ANSSI reported that nearly 353,000 individuals and 252,000 professionals were affected, the hacker claimed to have stolen some 678,000 records. To prevent such incidents in the future, ANSSI recommends implementing strong authentication methods, such as physical keys or dedicated applications, instead of relying on email codes. The agency also suggests reducing the exposure of business applications through managed workstations, limited access, and the use of virtual private networks (VPNs). The report notes that even ordinary accounts were sufficient to extract large amounts of data, and existing defenses failed to stop the operation in time. France has not yet implemented the European Union's NIS 2 directive on cybersecurity, which would require member states to strengthen protection measures and clarify responsibilities. The delay in transposing the directive into French law has allowed recent cyberattacks to occur. The European Commission has requested financial sanctions against France for this delay, and the issue of "backdoors" in encrypted messaging apps has been a point of contention. Meanwhile, the ANSSI has reported 99 suspected data breaches since August 1, 2026, with 67 confirmed and 32 still under investigation, affecting various government services and potentially exposing the data of millions of citizens.