France's tax authority learned of the theft 49 days after it began, from the thief's own claim
ANSSI's incident report dates the first extraction to 24 June and the first knowledge to the attacker's claim on 12 August. Stolen staff passwords opened two portals with no second factor, and one password reset left the attacker's session open.
By Parminder Kumar Sharma · · 19 min read

49 days from first extraction to the thief's post
By the timestamps in ANSSI's incident report, the first extraction of tax data began at 04:26 on 24 June 2026, and the French tax administration first learned of the theft when the attacker claimed it on an online forum at 13:50 on 12 August. That is 49 days and 9 hours (our arithmetic, in UTC+2 as the report uses). ANSSI, France's national cybersecurity agency, calls it seven weeks in its own executive summary, so the figure is the agency's and not a reporter's sum. The tax administration is the DGFiP, the Direction générale des Finances publiques.
That fact does not establish much of what the headlines around it suggest. It does not say who the attacker was: the report names only a pseudonym, and one suspect has been placed under formal investigation (mis en examen) and held, and is presumed innocent. It does not prove how the passwords were stolen: infostealer malware is ANSSI's probable explanation, which is an inference. It does not show a second factor being defeated on the main route, because the two portals used for the main theft had none. Where a second factor did exist, on a partner portal, it was a one-time code sent by email, and it was bypassed. And the 49 days belongs to one of three extractions: the second was 21 days before the claim, and the land-registry theft about 5 to 17 days.
Nor does it mean nothing was detected. Four times, on 7 June, 23 June, 6 July and 23 July, an alert fired on the attacker's searches and the DGFiP's security operations centre reset a password. What it missed was the theft. On 24 June one of those resets left the attacker's session open, and data kept flowing for another 15 hours 51 minutes.
Two routes, and both began with a password
ANSSI describes two routes. On the first, an attacker used several dozen logins belonging to DGFiP staff, stolen over three months. ANSSI's view is that they were probably taken by infostealers, malware that quietly copies saved logins, running on computers the DGFiP did not manage. It supposes they came notably from personal devices, for the ADER logins, and from third-party organisations' computers, for the APEX logins. It found no brute-force or credential-stuffing attempts, which means the attacker already held the passwords, and it adds that they could have been valid or expired.
Two portals asked for nothing more. PIGP, a public-finance portal that also gave DGFiP staff webmail and HR services, and ADER, a gateway to DGFiP applications reached over the State's inter-ministry network (the RIE), had no multi-factor authentication, ANSSI says. The attacker reached the RIE through compromised Education ministry systems joined to it, and sensitive DGFiP applications were open to parts of that network with no apparent need. The accounts had no special privileges, yet they could reach a large volume of data. ANSSI did not examine how user rights were managed.
The data came from E-Contact, the messaging tool taxpayers use to write to the tax administration. The Senate finance committee's note of 4 September, as reported by Public Sénat, says E-Contact had no second login step either.
The second route ran through APEX, a portal for partners such as notaries and land surveyors. It did have a second factor, a one-time code sent by email. A possible compromise of a land surveyor's computer at a private firm, the DGFiP's investigation found, is what let the attacker get past the code. The land-registry data was taken between 27 July and 8 August and concerns nearly 435,000 households, according to the same Senate note.
ANSSI's verdict is that the compromise "n'est pas la conséquence d'une attaque sophistiquée", in our translation not the consequence of a sophisticated attack, but of weaknesses in three areas. Identity: leaked logins from personal devices, with no strong authentication on two portals. Architecture: sensitive applications reachable from the RIE without segmentation, which is how a compromise at the Education ministry reached the tax administration. Detection: the SOC did not monitor ADER, and nothing correlated the warning signs.
Alerts, resets, and a session that stayed open
The DGFiP was not blind. It had a routine for stolen staff logins: when its SOC detected a compromised account, or its threat-intelligence provider flagged one, it reset the password and looked for related activity. ANSSI says the routine showed its worth but cannot cut the risk enough on its own. The timeline shows it working on the login and failing on the theft.
- 7 June. Searches from a stolen account raised an alert and the password was reset the same day. The SOC missed that the attacker had already moved from PIGP to ADER.
- 23 June. The intelligence provider flagged another account, and its searches opened a SOC ticket at 20:50. At 04:26 on 24 June the attacker began pulling E-Contact records with automated scraping tools, which copy data page by page. The SOC reset the password at 10:40, 13 hours 50 minutes after the ticket. The reset dealt with the PIGP alert and did not end the open ADER session. Data kept flowing for 15 hours 51 minutes more, until 02:31 on 25 June.
- 22 to 24 July. The attacker restarted the extraction on 22 July at 07:28 with another stolen account. The SOC spotted suspicious searches the next day and reset the account on 24 July.
Then there were the signals nobody added up. ANSSI lists night-time logins, connections from VPN addresses and from addresses in India, several addresses categorised as malicious, addresses reused weeks apart on accounts already known to be compromised, and data volumes of 11 GB between 22 and 25 June and 3 GB in July. Scraping needs one request per page, and nobody was counting requests per user. ANSSI's point is that each signal alone throws up false positives, but together they could have raised an alert.
ANSSI's own monitoring missed the theft as well. It says its network monitoring could not see activity by real staff accounts, though the cumulative number of requests should have triggered alerts. Warnings did arrive:
- On 9 June the Education ministry's security team told every ministry's team about an incident, with 17 indicators of compromise. The attacker had used one of those addresses two days earlier and used it again in late June. ANSSI says the delay in analysing and sharing such markers should have been kept to a minimum.
- On 15 June a partner told ANSSI that two DGFiP accounts were compromised. The DGFiP did not reply and ANSSI did not chase, though the DGFiP had already reset both.
- On 29 June a partner told ANSSI that the account used for the 24 June extraction was compromised. The DGFiP replied that it already knew and had reset it.
- On 6 August ANSSI searched its past sensor data and passed the DGFiP two suspicious addresses. The DGFiP replied on 11 August that it had blocked them and reset five accounts. The theft was identified only when the attacker claimed it on 12 August.
Three extractions, three clocks
Time from each extraction to the moment the theft was known, derived from ANSSI's annex 1 and executive summary. The land-registry window is given in whole dates, so its gap is a range.
| Extraction | Window, UTC+2 | Time to the claim (derived) |
|---|---|---|
| E-Contact, first wave | 24 June 04:26 to 25 June 02:31 | 49 days 9 hours, to 12 August 13:50 |
| E-Contact, second wave | From 22 July 07:28, in sessions to 11:33 and 16:20 to 17:16 | 21 days 6 hours, to 12 August 13:50 |
| Land registry, via APEX | 27 July to 8 August, per the DGFiP's investigation | About 5 to 17 days, to the claim reaching ANSSI on 13 August at 18:44 |
ANSSI ties the attacker's 12 August claim to the 24 June session, which is why the first row is the headline. The 102 days on the timeline are something different: the span from the earliest suspicious logins the report records, on 2 May, to the claim. The report does not say the theft began then, and it says the exploration of DGFiP applications preceded the extraction by several weeks.
Three totals for one theft
The counts moved as well. The attacker's claim on 12 August, as recorded by ANSSI, was 678,437 records: 392,867 individuals and 285,570 businesses, which do add up. The ministry's press release of 14 August said the investigation had established a total of 678,000 individuals and businesses, the claimed figure to the nearest thousand, while also saying the nature and volume of the data and the number of users were still being determined. The DGFiP's FAQs of 24 August then said a little over 350,000 individuals and a little over 250,000 businesses. ANSSI's report says nearly 353,000 and 252,000, and that the attacker published the detail of the stolen data on 13 August.
Four counts for the E-Contact theft, each as its source states it.
| Source and date | Individuals | Businesses |
|---|---|---|
| Attacker's claim, 12 August, recorded by ANSSI | 392,867 | 285,570 (total 678,437) |
| Ministry press release, 14 August | 678,000 in total | not split |
| DGFiP FAQs, 24 August | a little over 350,000 | a little over 250,000 |
| ANSSI report, 23 September | nearly 353,000 | 252,000 |
Adding ANSSI's two figures gives about 605,000, which is 73,437 fewer than the claimed total, or 10.8 per cent (derived, from rounded figures). Nothing public says why. The sources do not say whether the claim counted records rather than people, or overstated the haul.
On what was taken, the FAQs are specific. For individuals: tax ID, civil status, postal, phone and email contact details, family situation, number of dependants and tax shares, reference taxable income, the withholding rate, and the list of messages exchanged with the DGFiP. For fewer than 250 taxpayers the messages themselves may have been taken, though not the attachments. For businesses: SIREN registration number, name, address and generic message information (request identifier, date, service in charge, form type and status), with message contents possibly accessed for fewer than 2,076 businesses. On the land registry the DGFiP says property addresses and surfaces were consulted. The attacker's own claim, recorded by ANSSI, was broader: two million people, with names, dates of birth, land identifiers, parcels and holdings. We found nothing public that confirms it.
Six comforting phrases, and what the record shows
The friendly-name fallacy is the habit of mistaking a comforting label for a control or a fact. This record has several. Each phrase below is accurate as far as it goes; the point is what it leaves out.
Comforting phrases in the official statements and what the ANSSI report and the DGFiP's own documents show.
| Comforting phrase, and who used it | What the record shows |
|---|---|
| "Because of the sophistication of the attack" (ministry press release, 14 August, on why access checks missed the thefts) | ANSSI, 23 September: not a sophisticated attack. Stolen passwords on portals with no second factor, and no brute force. The ministry wrote two days into the investigation; the later, fuller record disagrees. |
| "Detected and closed at the time" (DGFiP FAQs, 24 August) | Logins and searches were detected. The theft was not, and the FAQs say so in the next sentence. On 24 June the reset did not end the ADER session, and data flowed for another 15 hours 51 minutes. |
| "Your taxpayer account was not compromised" (FAQs and ministry) | Accurate, and beside the point: the attacker did not need the account. What was taken, tax ID, contact details, family situation, reference income and the message list, is what makes a scam call credible. The FAQ itself names phishing and fraudulent calls, made more credible by the personal data, as the main consequence. |
| "Declarations and payments were not consulted" (FAQ for professionals) | Also accurate. The same FAQ says message metadata was taken, and message contents for fewer than 2,076 businesses. Payments were never the asset that mattered here. The FAQ for individuals has no equivalent sentence. |
| "Two-factor authentication" (APEX, one-time code by email) | It existed in name. ANSSI says an emailed code is not a reasonable choice where one login can open the mailbox, and here the code was bypassed through a possibly compromised computer. |
| "Non-privileged accounts" (ANSSI, on the accounts used) | No special rights, and still a large volume of data within reach. Privilege is not the same as reach. |
One more shift in the record. On 14 August the ministry put the intrusions down to the stolen credentials of "un agent" of the DGFiP and of "un tiers habilité", one agent and one authorised third party. ANSSI's report, six weeks later, speaks of several dozen credentials stolen over three months. Its annex uses 29 distinct anonymised account labels (our count: 22 internal and 7 external), a mix of accounts that logged in and accounts only tried, so 29 is not a count of stolen credentials. The two statements are not necessarily in conflict, because the ministry wrote on day two of the investigation, but the later record is far wider.
What is stated, and what is not
Questions a reader would ask, checked against the ANSSI report, the DGFiP and ministry statements, and, where marked secondary, press reports of the Senate note and the prosecutor's statement.
| Question | Stated on the record | Not stated |
|---|---|---|
| Who was behind it? | An actor calling itself Zerobytes claimed both thefts (ANSSI). The Paris prosecutor's office told Franceinfo on 4 September that one man, suspected of being one of the authors, was placed under formal investigation (mis en examen) on 20 August and held in provisional detention, that a second suspect was released, and that the inquiry continues under an investigating judge (secondary). | Any finding of guilt. ANSSI names no individual. Whether those held are the whole group, or who holds the data now. |
| How were the passwords stolen? | Probably infostealer malware on devices the DGFiP did not manage (ANSSI). The DGFiP's director told senators the same about personal equipment (Senate note, secondary). | Which malware, which devices, which accounts. The report says it is supposed, and that some passwords may have been expired. |
| Was multi-factor authentication bypassed? | None on PIGP or ADER (ANSSI), or on E-Contact (Senate note, secondary). On APEX an emailed code was bypassed through a possibly compromised computer. | How the code was bypassed. Whether any portal had a phishing-resistant factor. |
| Is seven weeks the official figure? | Yes: ANSSI's summary says the extraction happened seven weeks before the claim. Our sum is 49 days 9 hours. | That it covers everything. The second wave is 21 days, the land registry about 5 to 17. |
| How many people? | Nearly 353,000 individuals and 252,000 businesses (ANSSI). Nearly 435,000 households for the land registry (Senate note, secondary). | Why the claim of 678,437 was higher. The volume of the July wave. The number of credentials beyond "several dozen". |
| Were payments affected? | For professionals, declarations, payments and bank details were not consulted (FAQ). Taxpayers' account passwords were not among the data. | Any equivalent statement for individuals. How the DGFiP established it. |
| Is the account complete? | A 20-page report built from DGFiP logs, provider notices, Education ministry network logs and the attacker's own posts. | Anything under the redactions. User rights, which ANSSI did not study. The second phase of the audit. |
This story is not the whole summer. The DGFiP's news page, updated on 14 September, records a third incident. On 17 August a technical vulnerability was discovered on the portal for vacant estates, which the DGFiP says holds only public data. A third party then claimed fraudulent access, and an extraction was observed. That is a flaw, not a stolen password, and it sits outside every number above.
What a UK reader can act on
Ordinary accounts were the exposure. ANSSI stresses that the accounts had no special privileges and still reached a large volume of data. Programmes for privileged access rightly start with administrators. The French record says the read-and-export reach of ordinary staff roles is the same question.
A reset is not a kill switch. The NCSC's guidance on multi-factor authentication for corporate online services (version 2.0, 26 September 2024) warns that timed re-authentication delays how quickly an attacker's access can be cut off after detection, and says a suspected stolen session credential should trigger a policy that blocks it. In our reading, France's problem on 24 June had a similar shape: the reset changed the password and the open session carried on.
Not all second factors are equal. The same NCSC guidance ranks FIDO2 first and message-based methods, email, SMS and calls, last, as only likely to be appropriate when no other strengthening method is possible. ANSSI reached the same view about the emailed code at APEX.
Unmanaged devices. The NCSC's bring your own device guidance (reviewed 13 May 2025) says that letting personal devices reach corporate data through a browser gives no confidence in the security or configuration of the device, and that a compromised device can expose credentials and security tokens. It describes virtual desktops as reducing the attack surface. ANSSI goes further and recommends banning personal devices for work resources.
Logging the data, not just the login. The NCSC's introduction to logging for security purposes (8 July 2018) asks who has viewed or downloaded a specific document, and points to database and application logs for sensitive assets, including bulk personal data repositories. The DGFiP's gap was an application whose activity its SOC could not see.
The clock starts at awareness. The ICO's guide to personal data breaches says UK GDPR notification is due within 72 hours of becoming aware of a breach, where feasible, and that organisations should have robust breach detection. Here awareness arrived with the thief's post, 49 days after the theft began. Earlier briefings cover the 72 hour clock and the other clocks that run to a regulator, a government portal whose owner was told 84 days later, and a network path to government records.
What to do, in the order worth doing it
Take this with you
Actions, in order
- List every role that can read or export records in bulk, privileged or not, and set per-user quotas on records viewed, requests made and data exchanged in a period, with an alert and a cut-off. ANSSI recommends exactly this for the DGFiP.
- Make a compromised-credential flag do two things at once: reset the password and revoke every active session and token on every application. Then review what the account did from the estimated date of compromise. Time your own version on a real alert, from ticket to dead session.
- Find every application that holds bulk personal data and is not in your central logging. Each one is an ADER. Give it an owner and a date.
- Alert on combinations, not single signals: night-time logins, VPN and hosting addresses, unexpected countries, addresses previously tied to compromised accounts, request rates and data volumes. ANSSI's point is that together they could have raised an alert.
- Retire email and SMS codes as the second factor for sensitive data. Move to FIDO2 keys or passkeys first and authenticator apps second, in the NCSC's order, and put a date on it.
- Decide the unmanaged-device rule in writing: no access to sensitive portals from personal devices, or only through managed browsers or virtual desktops.
- Check that your credential-exposure feed covers infostealer logs, and that a hit is handled as an incident with a look-back and not as a password ticket.
- List the partner portals and shared networks that can reach your applications, restrict them by source address or VPN, and segment them. Ask which of them a compromise elsewhere could reach.
- Work out how you would learn of a theft that no alert caught. In France it was the thief's post, and that post also started the regulator's clock.
Method and interest
The ANSSI report is a public authority's account, written at the Prime Minister's request, of failures at another agency and at itself: its own sensors missed the theft, and the report says so plainly. The DGFiP's FAQs and the ministry release are communications from the body that suffered the breach, aimed at telling affected people what to do. They are accurate as far as we can check on what they state, and they say little about why the theft went unnoticed. The timeline was assembled from DGFiP logs and analyses, the threat-intelligence provider's notices, Education ministry network logs and the attacker's own posts, so times can differ between sources, as the report warns. The public version is redacted.
The Hacker News was used as a pointer and matches the report on every point we checked except one: it says ANSSI's sensors sit only at the entry and exit points of the RIE and the internet, and that the agency has no access to application logs. We could not find that wording in the public text, so we left it out. The prosecutor's statement and the Senate note reach us through Franceinfo and Public Sénat, and are labelled as such. We have no commercial interest in the story. We name no individual; the group name is the one ANSSI and the prosecutor's office use.
The question that exposes the gap
When your team resets a stolen password, which sessions does that reset end, on which applications, and who would notice if one of them kept pulling data for another sixteen hours?
Key facts
Sources
- PrimaryIncident report N° 3033/ANSSI/SDO/NP, 23 September 2026, 20 pages in French, read in full: the source of the timeline, the times, the weaknesses and the recommendationsANSSI (Agence nationale de la sécurité des systèmes d'information)accessed 2026-09-30
- PrimaryNews item of 29 September 2026 publishing the report: used for the publication date, the hand-over to the Prime Minister on 24 September and ANSSI's own summary of why it could not detect the theftANSSIaccessed 2026-09-30
- PrimaryPress release no. 953 of 14 August 2026: used for the first official account, the sophistication explanation and the 678,000 totalMinistry of the Economy and Finance (Bercy press office)accessed 2026-09-30
- PrimaryFAQ for individuals, 24 August 2026, in French: used for the count, the data fields taken and the detected-and-closed wordingDGFiP (impots.gouv.fr)accessed 2026-09-30
- PrimaryFAQ for professionals, 24 August 2026, in French: used for the business count and fields, the declarations-and-payments wording and the 2,076 figureDGFiP (impots.gouv.fr)accessed 2026-09-30
- PrimaryNews page published 14 August 2026 and modified 14 September 2026: used for the third incident, the vacant-estates portal of 17 AugustDGFiP (impots.gouv.fr)accessed 2026-09-30
- PrimaryPage of 18 August 2026 saying the CNIL has been notified and its checks are under way: used for the regulator's statusCNILaccessed 2026-09-30
- PrimaryMulti-factor authentication for your corporate online services, page 6 of 7, version 2.0, 26 September 2024: used for session credentials and timed re-authenticationUK National Cyber Security Centreaccessed 2026-09-30
- PrimaryRecommended types of MFA, page 3 of 7, version 2.0: used for the ranking of FIDO2 first and message-based methods lastUK National Cyber Security Centreaccessed 2026-09-30
- PrimaryBring your own device, Action 4 deployment approaches, reviewed 13 May 2025: used for browser access from personal devices and virtual desktopsUK National Cyber Security Centreaccessed 2026-09-30
- PrimaryIntroduction to logging for security purposes, 8 July 2018: used for application and database logs for bulk personal dataUK National Cyber Security Centreaccessed 2026-09-30
- PrimaryPersonal data breaches: a guide: used for the 72 hours from becoming aware and the expectation of breach detectionInformation Commissioner's Officeaccessed 2026-09-30
- Reported byReport of 7 September 2026 on the Senate finance committee note of 4 September: the only access we had to the note, used for E-Contact having no second step, the 435,000 households and the director's account of personal devicesPublic Sénataccessed 2026-09-30
- Reported byReport of 4 September 2026 quoting the Paris prosecutor's office on the suspects and the inquiry: the prosecutor's own statement was not found, so this is the route to itfranceinfoaccessed 2026-09-30
- Reported byReport of 29 September 2026 that pointed us to the primary sources; not relied on for any figureThe Hacker Newsaccessed 2026-09-30


