France’s Directorate General of Public Finances (DGFiP) has suffered a major security breach, exposing the tax and property data of nearly 680,000 users after hackers exploited compromised credentials.
- Approximately 678,000 users' tax-related data was exfiltrated.
- Attackers used compromised employee and third-party credentials for access.
- Leaked data includes tax income, withholding rates, and real estate cadastral records.
France’s Directorate General of Public Finances (DGFiP) has officially disclosed a significant data breach impacting roughly 680,000 individuals. The breach came to light after a threat actor boasted on a specialized hacking forum about gaining unauthorized access to the agency's internal systems.
According to official reports, the unauthorized access occurred during June and July. While the DGFiP suspended the access immediately upon detection, they initially found no evidence of data exfiltration. However, further investigations revealed that the attackers had successfully stolen information using compromised credentials from an employee and a third-party account.
Nature of the Compromised Data
The stolen dataset is comprehensive, including reference tax income, withholding tax rates, company names, unique identifiers, and cadastral data—which pertains to real estate addresses and land surface areas. Fortunately, the agency confirmed that usernames and passwords were not part of the exfiltrated data.
BozokMedia analysis shows that this incident highlights a systemic vulnerability in government identity and access management (IAM). The fact that a single set of compromised credentials could grant access to such a massive volume of sensitive data suggests a lack of granular access controls. In an era of escalating state-sponsored cyber warfare, such vulnerabilities in financial infrastructure can be weaponized for large-scale social engineering or financial fraud.
"The transition to digital governance must be matched by an equal investment in Zero-Trust security frameworks to prevent single-point-of-failure breaches."
This breach follows a troubling trend across Europe. Just a month prior, Romania’s National Agency for Cadastre and Property Registration (ANCPI) was targeted by the group 'ByteToBreach'. Unlike the French incident, the Romanian attack involved extortion and data wiping, which effectively paralyzed the country's real estate market for several weeks.
| Feature | France (DGFiP) Breach | Romania (ANCPI) Attack |
|---|---|---|
| Scale of Impact | ~680,000 Individuals | Agency-wide Disruption |
| Attack Vector | Compromised Credentials | Extortion & Data Wiping |
| Data Type | Tax & Real Estate Records | Internal Docs & Credentials |
Frequently Asked Questions
1. Were my login passwords stolen?
No, the DGFiP has stated that usernames and passwords were not compromised in this specific attack.
2. How will affected individuals be notified?
The tax authority has committed to contacting every affected individual directly.