A Senate report has outlined how hackers infiltrated the Direction générale des finances publiques (DGFiP), France's tax authority, to steal personal data from over 600,000 individuals and professionals. The report, authored by Senate Finance Committee President Claude Raynal (PS) and rapporteur Jean-François Husson (LR), was shared with committee members on September 4. The findings follow a September 1 meeting in which senators questioned the director general of public finances, Amélie Verdier, about the breach.
The attack occurred in three phases. The first took place between June 23 and 25, and again from July 21 to 23. According to the report, the attackers likely gained initial access using credentials from the National Education system to enter the interministerial network of the French government (RIE), which connects various state agencies. Once inside, the hackers used stolen login details—likely obtained through "infostealers," a type of malicious software that captures sensitive information—to access DGFiP systems. They then accessed a portal used by partner administrations and targeted the "e-contact" application, from which they stole data on nearly 350,000 individuals and 250,000 professionals.
A second breach occurred from July 27 to August 8, during which the attackers accessed the "professional server for cadastral data (SPDC)" through a portal used by external partners. This allowed them to extract cadastral data—information related to property records—for 434,564 households. A third breach, detected on August 17, involved exploiting a technical vulnerability in a statistical processing device developed by the DGFiP, which gave the attackers access to data on "vacant inheritances."
The senators highlighted "structural weaknesses" in the DGFiP’s cybersecurity, particularly in managing access controls and detecting unusual activity. Although the DGFiP had disabled the compromised accounts, the data theft went unnoticed. The rise of remote work since the start of the pandemic and increased data sharing between government agencies have created more entry points for potential cyberattacks, according to Raynal and Husson.
In response, the DGFiP has taken steps to secure its systems, including restricting access for certain administrations and banning the use of personal computers to connect to DGFiP tools. The minister for Public Action and Public Accounts, David Amiel, has pledged to expand two-factor authentication and speed up the deployment of tools that can detect unusual data access patterns. The investigation into the breach is ongoing, and a 18-year-old suspect has been placed under investigation.
French Senate Reveals Details of Cyberattacks on Tax Authority's Systems
AI-rewritten from original reportingHow it works
cyberattackdgfipdata-breachhackingsecurity-vulnerabilityfrance



