< Back to all clusters
[TECHNOLOGY] · France · 8 sources

started · updated

DGFiP data breach caused by stolen credentials, ANSSI reports

The French National Cybersecurity Agency (ANSSI) has released an incident report regarding a major data breach at the Directorate General of Public Finances (DGFiP). The breach, which occurred in late June, involved the theft of data from the internal messaging system, E-Contact, used by agents to communicate with taxpayers.

According to ANSSI, the breach was facilitated by basic security failures, including the use of stolen agent credentials and a lack of multi-factor authentication. While a hacker known as Zerobytes claimed to have stolen approximately 678,000 records, ANSSI identified roughly 353,000 individuals and 252,000 professionals as being affected. The unauthorized access went undetected for seven weeks.

In response to these incidents, cybersecurity experts, including Thibaud Binétruy of InterCert France, are highlighting critical vulnerabilities in corporate defense. A significant ‘blind spot’ identified is the exploitation of satellite applications—third-party tools used alongside primary information systems that are often undocumented or poorly mapped, making it difficult for security teams to identify critical compromised access points.

Entities

ANSSI · DGFiP · InterCert France