France’s tax administration lost data on roughly 678,000 people and businesses this summer, and stolen staff passwords were the way in. Nobody at the agency spotted the theft. The attacker announced it on a criminal forum on 12 August, about seven weeks after the first batch of data left the building.

On 23 September the French national cyber agency ANSSI published its incident report. It reads less like a story about a clever adversary and more like a checklist of things many UK organisations still have not fixed.
Table of Contents
What was taken
The agency is the DGFiP, which runs the impots.gouv.fr tax service. According to The Next Web and Bitdefender, the total was 678,000 affected individuals and businesses. The data included income figures, family status, withholding rates, addresses and property sizes for people, plus company names and SIREN registration numbers for businesses.
Online account passwords were not part of the haul. That is small comfort. Income plus address is exactly what a scammer needs to sound convincing on the phone, and officials warned of impersonation scams and identity fraud.
How stolen staff passwords opened the door
The first route hit E-Contact, the messaging tool taxpayers use to write to the tax office. The Hacker News, summarising the ANSSI report, says the attacker used several dozen staff passwords collected over about three months. They were most likely lifted by infostealer malware from devices the agency did not manage, probably staff members’ own. Our piece on Operation Endgame shows how that ecosystem keeps running.
Two internal portals, called PIGP and ADER, asked for a password and nothing else. So a stolen password worked straight away, and so, because of that, did the next one. From there the attacker reached the inter-ministry network and ran automated tools that pulled records page by page.
Reports differ on multi-factor authentication. The Next Web says the attacker bypassed it. The Hacker News reads the ANSSI findings as saying the two portals had no second factor at all. Either way, the login protection did not stop anyone.
A second route through a supplier
Stolen staff passwords were only half the story.
The land registry data came a different way. The attacker compromised the computer of a land surveyor at a private firm, then got past the one-time email code on the APEX portal. That took place between 27 July and 8 August, according to The Hacker News.
This is the third-party problem in miniature. The agency’s own controls were only as strong as the laptop of a contractor it did not run.
The monitoring failures
The detail that should worry security managers is in the ANSSI wording. In the report’s words, as quoted by The Hacker News, the security operations centre was “not monitoring ADER at all”. No system linked warning signs such as night-time logins and VPN connections from addresses in India.
When alerts did fire, the team reset passwords. It did not end the active sessions. The attacker kept extracting data for at least 16 more hours.
Resetting a password does not log anyone out. Session tokens survive it. This is a common gap, and a good incident response drill would catch it in an afternoon.
Why this matters for smaller firms
It is tempting to read a story about a national tax service and move on. Don’t. The attack needed no exploit and no budget. It needed a list of working logins and a page that asked for nothing more. Small firms have plenty of those pages, and far fewer people watching them.
What to test in your own business
None of this needs a nation-state budget to repeat. A criminal with a list of infostealer logs and a login page that wants only a password can do the same to a UK firm. Here is where to look.
- Every login page that reaches staff data. List the internal portals, webmail, HR tools and remote access gateways. Check that each one demands a second factor.
- Personal devices. If staff can sign in from home laptops, an infostealer on that laptop is your problem. Require managed devices or phishing-resistant sign-in (our guide to what multi-factor authentication stops covers the trade-offs) for sensitive systems.
- Monitoring coverage. Make a list of systems and confirm each one feeds your alerts. The gap is often a whole system nobody connected.
- Session revocation. During an incident, kill sessions and tokens as well as resetting passwords. Practise it before you need it.
- Suppliers. Ask which contractors can reach your data and how their machines are protected.
An internal penetration test that starts from leaked credentials shows quickly how far one staff password gets an attacker in your environment. It is a more honest measure than a policy document.
The lesson from France
The attacker did not need an exploit. The agency did not learn of the theft until the attacker said so, and the government convened a crisis meeting on 19 August. Passwords alone, thin monitoring and a slow response made an ordinary attack expensive. Stolen staff passwords will keep working until someone checks for them.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.