French tax authority data breach stemmed from simple security flaws, not advanced hacking
The ANSSI reported that the summer theft of personal data from the DGFiP resulted from exploiting weak system controls rather than a sophisticated cyber-attack.
The ANSSI’s incident report concluded that the recent summer data thefts from the French tax authority were not the product of a highly sophisticated intrusion but rather the result of basic security gaps. Hackers, identified as the group ZeroBytes, leveraged legitimate login details obtained from DGFiP staff to infiltrate the system and extract personal data belonging to close to 700,000 citizens and companies. Neither the tax agency’s internal supervision nor ANSSI’s monitoring detected the exfiltrations.
In response, Prime Minister Sébastien Lecornu mandated a comprehensive audit of the DGFiP’s IT environment, which will assess all vulnerabilities. The agency also advised the adoption of multi-factor authentication, prohibition of professional service access from personal devices, and the use of passwords that follow security best practices. Earlier this month, two suspects were arrested, with an 18-year-old placed in pre-trial detention.
Why it matters
The breach exposes systemic cybersecurity weaknesses in a key government agency handling sensitive financial data.
In this story
