# A Massive Data Breach at the French Tax Authority: How Stolen Passwords Exposed Hundreds of Thousands
In June and July, a significant data breach struck the national tax administration, exposing sensitive information on hundreds of thousands of taxpayers and businesses. The attack, which went unnoticed for weeks, succeeded not through highly sophisticated hacking techniques, but due to critical security oversights within the government agency’s network infrastructure.
## The Breach and the Data Compromised
The breach involved two distinct attack paths. The first targeted an internal messaging tool used by citizens to communicate with tax officials. The attacker gained access using dozens of stolen employee credentials, ultimately exposing the personal data of over 350,000 individuals and 250,000 businesses.
For individuals, compromised data included tax IDs, contact details, family situations, taxable income, and tax withholding rates, along with a list of their messages; in some cases, the message content itself was taken. Businesses faced exposure of their names, registration numbers, and addresses, with the actual content of fewer than 2,100 businesses also potentially viewed. A second route targeted land-registry data through a partner portal, compromising records for nearly 435,000 households.
## How the Attackers Penetrated the Network
The attackers infiltrated the network using passwords harvested over a three-month period by infostealer malware, likely from staff members’ personal or unmanaged devices. Once inside, the attackers exploited two internal portals that relied solely on passwords for authentication. They moved laterally into the government’s central network through compromised systems in the Education Ministry. Critically, sensitive tax applications were not properly segmented, allowing the attackers to access them from network zones where they should not have had a presence. The accounts the attackers used had no special privileges, yet they could reach a vast amount of data.
## The Failure of Detection
The agency’s security operations center had protocols for compromised logins, but these failed to catch the exfiltration. Alerts were triggered—such as suspicious login times and connections from foreign IP addresses—but were either ignored or mismanaged. When a password was reset to block an intruder, the team failed to terminate the attacker’s active session on the secondary portal, allowing data to continue flowing for nearly 16 hours. Furthermore, the security team was not monitoring the specific portal used for the final data extraction. Automated scraping tools used by the attacker generated an unusually high number of requests and moved massive volumes of data, yet no anomaly detection system flagged these actions. The breach only came to light when the attacker publicly boasted about the theft on an online forum in August.
## Changes Implemented and Security Recommendations
In response, the affected portals have been locked down, and staff are now blocked from accessing sensitive work tools via personal devices. A comprehensive action plan is underway to overhaul monitoring, implement strong authentication across all systems, and enforce strict limits on data access volumes.
Security analysts recommend that organizations revoke all active user sessions immediately upon a password reset, deploy multi-factor authentication using hardware tokens or authenticator apps rather than email codes, and monitor all business applications through centralized security platforms. Setting quotas on data exchange and request frequency is also crucial to spotting scraping attempts before massive data theft occurs.
## Frequently Asked Questions (FAQ)
**Q: What kind of information was stolen in the tax breach?**
A: Stolen data included personal tax IDs, contact details, family situations, income references, and tax withholding rates for individuals. For businesses, it involved company names, registration numbers, and addresses, along with the content of some exchanged messages. Land registry records for nearly half a million households were also compromised.
**Q: How did the hackers get the staff passwords?**
A: The passwords were likely stolen by infostealer malware, which secretly copies saved login credentials. This malware probably infected staff devices that were not managed or secured by the agency, such as personal computers.
**Q: Why wasn’t the breach detected sooner?**
A: The breach went undetected due to severe monitoring gaps. The security team failed to investigate alerts properly, did not check for unauthorized active sessions after resetting passwords, and was not monitoring the specific portal used to extract the data. Additionally, the high volume of automated scraping requests did not trigger automated alarms.
**Q: Were the individual taxpayer login accounts compromised?**
A: No. The attackers used stolen employee credentials to access internal government systems; the public-facing tax portals where individuals log in to file their returns were not breached.
## Conclusion
This breach serves as a stark reminder that even in high-security government environments, fundamental cybersecurity hygiene is essential. The attackers succeeded not by breaking through a sophisticated firewall, but by exploiting weak authentication, poor network segmentation, and inadequate monitoring. As agencies worldwide grapple with protecting sensitive citizen data, this incident underscores the urgent need for robust identity verification, continuous network monitoring, and strict access controls to prevent similarly devastating breaches in the future.
Thank you for reading



