ANSSI Report on French Tax Authority Breach: Key Lessons from the DGFiP Cyberattack
Signal Watch | French tax authority (DGFiP) breach: ANSSI's post-mortem >> @channel Good luck with ECSM tomorrow, and because it always helps to have a recent story about cyber risk...
What happened: ANSSI (France's national cybersecurity agency) published its incident report on 29 Sept 2026 analysing the breach at the French Tax Authority earlier in the year. Over three months, the attacker collected the logins and passwords of several dozen tax agents, probably stolen by infostealers. ANSSI suspects that was via devices the DGFiP doesn't control, notably agents' personal computers.
Impact: Data from the E-Contact application covering nearly 353,000 individuals and 252,000 businesses, plus land registry data, was taken. Around 14 GB left over three months without the tax office or ANSSI raising the alarm.
Interesting detail: A session stayed open roughly sixteen hours after the password was reset. Also, in 2026, two tax portals with access to sensitive data still relied on just a username and password.
Lessons:
BYOD and personal-device hygiene is your risk to manage, even though itβs outside your perimeter. This is where awareness and education can make the difference.
IT Service desks need to remember to revoke sessions as well as resetting passwords.
Least privilege matters: ordinary agent accounts with no special rights gave access to large volumes of sensitive data.
