started · updated
ANSSI audit reveals critical vulnerabilities in DGFiP cybersecurity
The French National Cybersecurity Agency (ANSSI) released an incident report following a summer hack of the General Directorate of Public Finances (DGFiP). The audit, requested by the Prime Minister, identified critical vulnerabilities that allowed hackers to exfiltrate data from the impots.gouv.fr platform and cadastral records.
ANSSI noted that the breach was not the result of a sophisticated attack but rather the exploitation of three main weaknesses: credential protection, system architecture, and attack detection. Hackers utilized credentials belonging to DGFiP agents, which had been compromised through use on personal devices. Additionally, some sensitive applications lacked strong authentication.
The report highlighted a lack of network segmentation, noting that certain applications were accessible via the State Interministerial Network (RIE) without proper isolation. This allowed attackers to move laterally from other administrative infrastructures, specifically progressing from systems belonging to the Ministry of National Education. Furthermore, the data exfiltration went undetected throughout July and August by both DGFiP and ANSSI supervision mechanisms.