preloader

· · digital-security digital-privacy gdpr cve data-breach identity-access-management europe france

France’s Tax Authority Just Confirmed a Breach That Started With One Set of Stolen Login Credentials

Source: BleepingComputer

Two months. That is how long an attacker sat inside France’s national tax authority using credentials that were never supposed to leave the hands of the employee and third party they belonged to, before anyone noticed.

A breach with no exploit chain to patch

The Direction Generale des Finances Publiques (DGFiP) confirmed on August 14 that unauthorised access to its systems ran through June and July 2026, using stolen or impersonated login credentials tied to a DGFiP staff member and an authorised third party. There is no CVE here, no zero-day, no patch Tuesday entry to point to. The attacker simply had working credentials for a system that trusted them, and used that access to pull reference tax income, family quotient data and withholding tax rates for individuals, along with company names, SIREN numbers and cadastral property data for businesses. In total, 678,000 people and organisations had data taken.

The forum listing forced the disclosure

DGFiP did not find this on its own timeline. A threat actor using the handle ZeroBytes listed a database, initially touted as roughly two million records, for sale on the PwnForums hacking forum on August 12. That is what triggered public confirmation two days later. DGFiP has since disabled every account tied to the identified unauthorised logins and notified the Commission Nationale de l’Informatique et des Libertes, France’s GDPR supervisory authority, as required. The gap between an attacker having usable access and a forum listing forcing an organisation’s hand is a familiar pattern, and it is rarely a short gap.

Why credential-based intrusions are the harder problem

A vulnerability in a piece of software has a fix: a patch, a version bump, a configuration change. A stolen credential that behaves exactly like the legitimate account it was taken from does not announce itself the same way, and it will not show up on a CVE feed. Catching it depends on things many organisations underinvest in relative to patch management: anomalous access pattern detection, session monitoring for privileged and third-party accounts, and short credential lifetimes that limit how long a theft stays useful. A national tax authority is a government institution with real security resources, and this still ran for two months. That should recalibrate how confident any organisation is that its own third-party and staff access controls would catch the same thing faster.

What this means under GDPR, beyond the French case

DGFiP’s notification to CNIL is the correct move and the legally required one, but it also puts the incident on the public record as a GDPR case study: financial and property data on 678,000 data subjects, a breach window measured in months, and a root cause of credential compromise rather than a software flaw. Any organisation handling comparable personal or financial data, tax advisers, property firms, financial services providers, anywhere in the EU, is processing the kind of data this incident exposed and carries the same notification obligations if something similar happens on their own systems.

If your organisation cannot say with confidence how quickly it would detect a staff or third-party account behaving abnormally, or how long a compromised credential would stay valid before it was noticed, contact Excello Digital. We help European businesses build identity and access controls that catch credential misuse long before it reaches a hacking forum.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!