Piratage DGFiP: ANSSI reveals how stolen passwords led to catastrophe
ANSSI has released its incident report on the recent DGFiP hack. Stolen agent credentials, absent two-factor authentication, and unnoticed data exfiltrations are detailed in the document, explaining how the data of hundreds of thousands of users was leaked this summer.
To steal a vast amount of data from the Directorate General of Public Finance (DGFiP), no unprecedented vulnerability or shadowy genius was required. The data theft that hit impots.gouv.fr this summer was less a thriller and more an accumulation of basic failures. For weeks, a cybercriminal navigated the tax authority's applications using the credentials of real agents, passing through another ministry, without their data extractions being detected. ANSSI, the French cyber agency, reconstructs the timeline, dissects detection failures, and details the necessary work—some of it urgent.
The public learned of the incident on August 12. On that day, a hacker named Zerobytes claimed responsibility on a forum for the data theft from impots.gouv.fr. At 4:32 PM, ANSSI alerted the DGFiP, and by the next morning, the hacker displayed the details of their haul. The files originated from E-Contact, the internal messaging system used by tax agents to communicate with taxpayers. Two figures circulated: ANSSI reported nearly 353,000 individuals and 252,000 professionals affected, while the hacker claimed around 678,000 records. Crucially, the theft was not recent; data was siphoned off at the end of June, seven weeks before the claim.
Gaining access didn't require picking locks; the attacker had the keys. Over three months, they obtained the usernames and passwords of several dozen tax agents, likely stolen by information-stealing malware, possibly from devices not controlled by the DGFiP, such as agents' personal computers. To access ADER and PIGP, two portals leading to tax applications, an agent only needed their username and password—no multi-factor authentication, like a code sent to a phone, was required. This practice was common at high levels of government. The DGFiP did have a safety net: a contractor monitoring sites where credentials were sold and flagging compromised accounts for password changes. ANSSI found this useful, but it wasn't foolproof and sometimes reacted slowly. One account flagged on June 3rd had its password changed nine days later.
Reaching the right level was the next step. The attacker first connected to PIGP, an internet-accessible tax portal. They then moved to ADER, another entry point exclusively for the Interministerial State Network (RIE), a network connecting government departments. To connect to RIE, they used compromised infrastructure from the Ministry of National Education. Once on this shared network, a lack of segmentation meant nothing separated them from sensitive tax applications. An alert had been issued on June 9th; the Ministry of Education had sent security teams from other ministries 17 technical indicators of the attack, including a list of IP addresses to monitor, one of which the hacker was using. They then scraped E-Contact, a program that copies data record by record, between June 24th and 25th, and again on July 22nd.
Unfortunately, none of these data exfiltrations were detected by the DGFiP or ANSSI. The agency's probes monitor network traffic, not activity within applications. Since the hacker used legitimate accounts, they appeared as any other agent. Still, indicators were present. A total of 11 GB of data was transferred between June 22nd and 25th, followed by 3 GB at the end of July. Some connections occurred late at night, via VPNs, from India, or from IP addresses known for malicious activity. Scraping, which requires a query for each accessed record, must have generated an unusually high volume of requests, unhindered by any limits. Simple agent accounts, without special privileges, granted access to large amounts of data. Individually, these signals might seem trivial and risk overwhelming security teams with false alarms. Collectively, they could have betrayed the intruder.
The timeline is, frustratingly, revealing. On June 23rd at 8:50 PM, suspicious searches on PIGP triggered a ticket at the DGFiP's Security Operations Center (SOC), which reset the account's password the next day at 10:40 AM. However, ADER was not monitored, and the reset did not terminate the open session. The scraping, initiated at 4:26 AM, continued until June 25th at 2:31 AM. In July, the account used was reset only two days after the exfiltration resumed. The report also notes that a report of compromised accounts, sent on June 15th, received no response from the DGFiP, nor was there a follow-up from ANSSI. These accounts had, however, already been reset.
On August 13th, Zerobytes claimed responsibility for data from the Professional Cadastral Data Server. According to the hacker, the names, birth dates, parcels, and properties of 2 million French citizens were involved. The entry point, again, was not extraordinary. The likely compromised workstation of a private surveying firm allowed bypassing the two-factor authentication for APEX, the portal reserved for partners like notaries and surveyors. The second factor, a simple code received by email, proved insufficient. According to the DGFiP, access and exfiltration occurred between July 27th and August 8th.
In August, the DGFiP took decisive action. On the 6th, before any public claim, ANSSI alerted them to two suspicious IP addresses; upon reviewing its probe logs retrospectively, it detected suspicious traffic to two tax portals. On the 11th, the DGFiP confirmed abnormal connections, reset five accounts, and blocked these two IP addresses. Access restrictions followed. On August 13th, agents lost access to the ADER portal, followed by PIGP on the 18th. For PIGP, only external partners, such as local government accountants, retained access. Neither of these access points is expected to be reopened to agents. Regarding the cadastral data, the surveyor's account was deactivated on August 14th, the APEX portal was locked, and all accounts from their firm were suspended on the 18th. ANSSI acknowledges that these drastic measures significantly disrupted the work of the DGFiP and its partners.
For the future, ANSSI has drafted comprehensive recommendations. Firstly, it proposes prohibiting personal computers for accessing tax tools and restricting internal applications to DGFiP-managed and secured workstations. Secondly, it suggests mandating multi-factor authentication everywhere, with a second factor distinct from the password. An email code is useless if the email account is accessed with the same credentials; a physical key or a dedicated app, ideally on a separate device, is preferable. All applications should be monitored by a SIEM, a central control system that collects and analyzes connection logs. Quotas for data access, blocking of suspicious IP addresses based on origin or reputation, and session termination upon password changes are also recommended. ANSSI finally calls for agents to have access only to data necessary for their duties, for better segmentation of the Interministerial State Network (RIE) between ministries, and for much faster circulation of attack indicators.
The report, at least, is commendably frank. It states that this compromise "is not the consequence of a sophisticated attack." Instead, it resulted from weaknesses in identity verification (how connections are validated), architecture (network and application organization), and anomaly detection. A full audit is already planned to uncover all exploitable vulnerabilities. The ongoing projects could shape the state's digital security roadmap. ANSSI conditions this on obtaining support from the teams managing these applications daily, the hierarchy of the Ministry of Action and Public Accounts, and other administrations. In other words, the security of the tax authority will not be determined solely within its security center.
Fresh materials — Tech News

LDLC Confirms Data Breach: Customer Personal Information Accessed
French online retailer LDLC has reported a cybersecurity incident. Unauthorized access to one of its systems allowed cybercriminals to view customer personal data. This includes names, addresses, phone numbers, and account details. LDLC assures that banking information and passwords were not c

Google: Space Data Centers Need 1,800 Starship Launches
Google is developing orbital data centers. To make this project viable, the tech giant is awaiting significant progress from SpaceX and its Starship rocket. On October 1st, Google sent its first space-bound data center into orbit aboard a SpaceX Falcon 9 rocket. This mission wi

Ryzen 5 9600X Hits €142.36 on AliExpress for AM5 Builds
Our review highlighted the Ryzen 5 9600X not just for its raw performance, but for its remarkable efficiency and cool operation under load. Now, with a price cut to less than half its launch cost during AliExpress's Local Day, it presents a much more compelling option for an AM5 platfo

Marshall Bromley 150: Compact Speaker with Lights and Karaoke Features
The Marshall Bromley 150, a more compact party speaker, now includes music-synced lights. It retains two inputs for microphones or instruments and a removable battery offering around 40 hours of playback. The controls have moved to the left side to maximize the front panel for light effects, wh

Ecoflow Delta 3 Classic: 130€ Off Before Prime Day
The Ecoflow Delta 3 Classic stands out for its compact design and, more importantly, its versatility. It can simultaneously charge an electric car and a smartphone, all at a 15% reduced price on Amazon. Get the Ecoflow Delta 3 Classic for 718 euros instead of 848 euros at Amazon. To tak

Saily's Unlimited eSIM for the US Drops to €36.89 Before the All Saints' Day Holidays
Saily, the travel eSIM from Nord Security (the company behind NordVPN), sells data plans by destination via its website or app. For the United States, their unlimited plan is priced daily for 1 to 30 days. The 15-day version currently costs €40.99. Using the code CLUBIC offers a 10% discoun