# France's Tax Collector Lost Data on 680,000 People — and Learned About It From a Hacking Forum


France's Directorate General of Public Finances found out it had been breached roughly the same way most people learn their password is compromised: someone posted about it online.


The DGFiP, which manages tax collection for the French government, disclosed this week that attackers accessed its systems in June and July using stolen credentials — one belonging to an employee, one to a third-party account. At the time, the agency saw no evidence of data exfiltration. It took a threat actor bragging on a hacking forum for investigators to confirm that the financial data of approximately 678,000 French residents had, in fact, walked out the door.


That gap between intrusion and discovery is where most of the damage gets done.


## Two Stolen Keys, One Very Large Vault


The entry vector here is straightforward, which is precisely what makes it embarrassing. No zero-day exploitation. No elaborate phishing infrastructure. Just compromised credentials — for an employee account and a third-party contractor account — that apparently weren't flagged as anomalous long enough to stop months of access.


What those credentials unlocked is the part worth paying attention to. The stolen data includes reference tax income, withholding tax rates, company names and unique identifiers, and cadastral data covering real estate addresses and property surfaces. DGFiP confirmed that usernames, passwords, and payment details were not compromised. Cold comfort for people whose financial profile is now packaged somewhere on a forum.


Reference tax income and withholding rate data is exactly the kind of information that makes social engineering convincing. An attacker armed with someone's tax bracket, their employer name, and a real property address can construct a highly credible impersonation — of a tax official, a bank officer, or a fraud investigator. This isn't data that enables direct account takeover. It's data that enables the more dangerous second-order attack where the victim does the work themselves, trusting the caller because the caller already knows too much.


## The Third-Party Problem Nobody Wants to Talk About


The employee credential compromise is the headline, but the third-party account compromise deserves equal scrutiny. Government agencies routinely extend system access to contractors, auditors, software vendors, and consultants. Each of those accounts is a potential entry point with access calibrated for convenience rather than least-privilege security principles.


France is not unique in this. The 2020 SolarWinds breach demonstrated at scale how trusted third-party relationships become the path of least resistance. The 2023 MOVEit campaign exploited managed file transfer software used by thousands of organizations simultaneously. The consistent thread: attackers don't need to breach your perimeter when they can walk in through a door you propped open for a vendor.


DGFiP has not disclosed which third-party held the compromised account, how long that account had been active, or whether its permissions were scoped appropriately. Those answers matter for understanding whether this was a credential compromise of a well-designed system or an access review failure that had been waiting to become an incident.


## A Pattern Across European Government Infrastructure


The timing lands in a particularly rough stretch for European public-sector systems. Roughly a month before the DGFiP disclosure, Romania's National Agency for Cadastre and Property Registration — also, notably, a property records authority — was hit by a threat actor going by ByteToBreach. That attack was considerably more destructive: when the extortion attempt failed, the attacker reportedly wiped the encrypted data, taking Romania's real estate market offline for approximately three weeks while the agency rebuilt from scratch.


Two national property and tax records systems in two EU member states, both targeted within the same summer. That's not coincidence — that's targeting. Cadastral and tax databases are attractive because they're authoritative, they're rich with financial and identity data, and they're often operated by agencies that prioritize availability over security hardening. The records they hold have to be accurate and accessible to function; that operational mandate creates pressure against the kind of restrictive controls that might have caught credential misuse sooner.


It also raises a harder question for the European government security posture broadly: how many other national registries and tax authorities are running on legacy infrastructure with credential management practices that haven't kept pace with threat actor sophistication?


## What Defenders — and Affected Citizens — Should Actually Do


For the 678,000 people whose data is now confirmed compromised: the immediate risk isn't someone emptying a bank account. It's the scaffolding for social engineering attacks — calls, emails, or letters that reference specific, accurate financial details to establish false credibility. The DGFiP says it will contact affected individuals directly. Anyone receiving that notification should verify the contact through official channels before providing any additional information.


For defenders working in government or critical infrastructure: the credential audit this breach demands isn't exotic. Inventory every active third-party account, confirm current need, enforce MFA without exception, and build anomaly detection around access patterns rather than just access events. The attacker's access spanned two months. Something was moving, being read, or being exported for two months. That's a detection problem as much as a prevention problem.


---


## HackWire Analysis


The DGFiP breach lands in a familiar category: organizations that can tell you *what* was taken but struggle to tell you *how long* the attacker had access before it was noticed. That's an instrumentation failure, not just a credential failure.


What's being underreported in initial coverage is the cadastral data dimension. Property records — addresses, parcel identifiers, surface area — paired with tax income data creates a remarkably complete dossier for real estate fraud, mortgage fraud, and impersonation of property owners in transactions. France has a reasonably robust identity verification system for property transfers, but fraudsters armed with this combination of data have demonstrated, repeatedly in other jurisdictions, that they can work around it.


The Romanian ANCPI attack from last month provides a useful contrast. ByteToBreach escalated to destructive wiping when extortion failed — a playbook we've seen in healthcare and energy contexts, now showing up in property registry authorities. The DGFiP attacker appears to have been more interested in quiet exfiltration than leverage. Different threat actor profiles targeting the same class of data suggest this category of government database is drawing broad criminal attention, not just opportunistic scanning.


The EU's NIS2 directive, which expanded mandatory cybersecurity requirements for public sector entities, came into force in member states in late 2024. Both France and Romania were obligated to implement those requirements. Whether either agency met the directive's incident response and security baseline requirements will be a question for regulators — and probably for parliamentary committees — in the months ahead.


For organizations watching this from outside Europe: the attack vector is a solved problem. Credential hygiene, MFA enforcement, third-party access reviews, and behavioral monitoring for data access anomalies aren't expensive or exotic. They're table stakes. The gap between knowing that and executing it at scale inside a government bureaucracy is where the real problem lives.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)