Attackers used credentials stolen from staff at France’s Directorate General of Public Finances (DGFiP) to access tax-administration systems between June and August and exfiltrate taxpayer, business, and land-registry information. The E-Contact exposure affected more than 353,000 individuals and 252,000 businesses, while a separate APEX access path reportedly exposed land-registry data for nearly 435,000 households. ANSSI assessed that several dozen valid staff credentials were likely harvested by infostealer malware from unmanaged personal computers, finding no evidence of brute-force or credential-stuffing attempts.
ANSSI attributed the prolonged, roughly seven-week undetected intrusion to password-only authentication, poor network segmentation, personal-device access, and gaps in application-level monitoring. Password resets did not terminate active ADER sessions, the DGFiP SOC did not monitor ADER, and suspicious indicators—including foreign and malicious IP addresses, nighttime activity, high request volumes, and approximately 11 GB of transfers—were not correlated. DGFiP disabled staff access to PIGP and ADER and locked APEX; planned measures include phishing-resistant MFA, managed-device hardening, session revocation, expanded SIEM coverage, data-access quotas, and a ban on personal devices accessing work systems.

See attribution, scope, and your downstream exposure.
11 events from the most recent confirmed update back to the earliest known activity.
French judicial authorities reportedly suspect that two known French cybercriminals were involved in the DGFiP incident.
ANSSI released a report concluding that password-only access, inadequate segmentation, unmanaged devices, and insufficient application-level monitoring enabled the compromise. It recommended phishing-resistant MFA, session revocation after password resets, SIEM coverage for business applications, transfer and request quotas, and restricting personal-device access.
DGFiP disabled staff access to ADER and PIGP and locked APEX, including disabling the implicated surveyor account and subsequently other accounts from that firm. DGFiP did not expect staff access to ADER or PIGP to resume.
The DGFiP data theft became publicly known after the attacker claimed responsibility on an online forum. Prime Minister Sébastien Lecornu then requested an in-depth ANSSI audit.
A separate intrusion route used a potentially compromised private land-surveying firm's computer to bypass APEX's email-delivered one-time code. The resulting land-registry-data extraction reportedly concerned nearly 435,000 households.
Using compromised low-privilege staff accounts, the attacker extracted E-Contact data affecting more than 350,000 individuals and more than 250,000 businesses. The SOC did not monitor ADER or alert on 11 GB of transfers, while DGFiP and ANSSI did not correlate indicators including malicious IPs, India-based access, nighttime logins, and high request volumes.
DGFiP's SOC opened a ticket for suspicious activity while the attacker was automating E-Contact scraping through ADER. Resetting the affected password did not revoke the active ADER session, allowing extraction to continue for nearly 16 more hours.
The French Education Ministry shared 17 indicators of compromise with other ministries. The attacker later reused one of the identified ministry IP addresses.
After reaching the interministerial RIE network through compromised Education Ministry systems, investigators found that the attacker attempted to move laterally to other government institutions. The attempt underscored the inadequate segmentation between sensitive DGFiP applications and the wider government network.
The first intrusion route began with suspicious logins using stolen DGFiP staff credentials. The attackers used password-only PIGP and ADER access paths and reached the state RIE network through compromised Education Ministry systems.
Several dozen legitimate DGFiP staff passwords were likely stolen over approximately three months by infostealer malware operating on computers unmanaged by DGFiP, likely including personal devices. ANSSI found no evidence of brute-force or credential-stuffing activity, indicating the attackers used valid credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
mkd-cirt.mk
Open sourcezdnet.fr
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.