< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

3 clusters · 20 sources · 12 days · First seen · Last updated

Data breaches in French public organizations

Overview

Multiple French organizations have reported significant data breaches involving the theft of personal information.

In mid-September, the French National Agency for Adult Training (Afpa) reported a breach potentially affecting 1.7 million people. Officials stated the extraction was linked to a vulnerability in a third-party hosting management tool. While personal details like names and addresses were likely compromised, sensitive data such as banking information was reportedly not available on the affected application.

Following this, the French National Cybersecurity Agency (ANSSI) released an incident report regarding a breach at the Directorate General of Public Finances (DGFiP). The breach, which occurred in late June, involved the theft of data from the ‘E-Contact’ internal messaging system used by agents to communicate with taxpayers. While a hacker known as Zerobytes claimed to have stolen approximately 678,000 records, ANSSI identified roughly 353,000 individuals and 252,000 professionals as being affected.

An audit requested by the Prime Minister revealed that the breach was facilitated by weaknesses in credential protection, system architecture, and attack detection. Hackers utilized agent credentials compromised through use on personal devices. The report also highlighted a lack of network segmentation, noting that attackers were able to move laterally from systems belonging to the Ministry of National Education to access applications via the State Interministerial Network (RIE). The unauthorized access and subsequent data exfiltration went undetected throughout July and August.

Cybersecurity experts have noted that these incidents highlight a ‘blind spot’ regarding the exploitation of satellite applications—third-party tools used alongside primary systems that are often poorly mapped or undocumented.

Entities

ANSSI · DGFiP · InterCert France · Pierre Prady · Afpa

Timeline

  1. [TECHNOLOGY] 7 sources
    ANSSI audit reveals critical vulnerabilities in DGFiP cybersecurity

    An ANSSI audit reveals that the DGFiP data breach was caused by weak credential protection, poor system architecture, and a lack of detection mechanisms, allowing lateral movement from other state networks.

  2. [TECHNOLOGY] 8 sources
    DGFiP data breach caused by stolen credentials, ANSSI reports

    ANSSI reports that stolen credentials and lack of multi-factor authentication led to a major DGFiP data breach in France, highlighting risks from undocumented satellite applications.

  3. [TECHNOLOGY] 8 sources
    Afpa reports data breach potentially affecting 1.7 million people

    Afpa, France's national adult training agency, reports a data breach potentially affecting 1.7 million people via a third-party hosting tool vulnerability.

Sources

cegepoutaouais.qc.ca · cert.ssi.gouv.fr · clubic.com · comarketing-news.fr · contrepoints.org · emarketerz.fr · entrevue.fr · estrepublicain.fr · generation-nt.com · it-connect.fr · journalducoin.com · lapauseinfo.fr · ledauphine.com · lejdd.fr · midilibre.fr · notretemps.com · sudouest.fr · vosgesmatin.fr · zataz.com · zdnet.fr

This summary has been updated 1 time: see revision history