Stolen Passwords, No Alarms: How France's Tax Agency Lost Data on 600,000 Taxpayers and Businesses
TL;DR what: An attacker used several dozen DGFIP staff passwords, probably stolen by infostealers, to scrape France's E-Contact taxpayer messaging tool in June and July without detection. impact: Tax and contact dat
TL;DR
- what: An attacker used several dozen DGFIP staff passwords, probably stolen by infostealers, to scrape France's E-Contact taxpayer messaging tool in June and July without detection.
- impact: Tax and contact data on a little over 350,000 individuals and 250,000 businesses was exposed, plus land-registry data on nearly 435,000 households through a second route.
- fix: ANSSI's audit points to weak login protection, poor network separation and monitoring gaps, including password-only portals and a SOC that never watched ADER.
- who: French taxpayers and businesses that used E-Contact, and any organization whose staff can reach internal portals with a password alone from devices it does not manage.
Several dozen stolen staff passwords, two portals that asked for nothing more, and a security operations center that reset the wrong door. That is how an attacker walked out of France's tax administration with data on a little over 350,000 individuals and a little over 250,000 businesses in June and July. Neither the DGFIP nor ANSSI, France's national cybersecurity agency, saw the data leave. The theft became known on August 12, when the attacker claimed it on an online forum, seven weeks after the first batch was taken.
The key line in ANSSI's report, published Tuesday, is its verdict: the attack was not sophisticated. That contradicts the ministry overseeing the DGFIP, which said in August that access checks had not revealed the theft "because of the sophistication of the attack." ANSSI, which Prime Minister SΓ©bastien Lecornu asked for an in-depth audit, puts it down to weak login protection, poorly separated networks and gaps in monitoring. (Source: The Hacker News, reporting on the ANSSI report.)
What was taken
The data came from E-Contact, the tool taxpayers use to message the tax administration behind impots.gouv.fr. For individuals, the data that may have been viewed or copied includes tax ID, contact details, family situation, reference taxable income, tax withholding rate and a list of messages exchanged with the DGFIP. For fewer than 250 people, the messages themselves may also have been taken. For businesses it covers company name, SIREN registration number, address and basic message details. For fewer than 2,076 businesses, message content may have been seen. Taxpayers' own online accounts and passwords were not compromised.
A second route reached land-registry data through APEX, a portal for partners such as notaries and land surveyors that required a password and a one-time code sent by email. The DGFIP found that a land surveyor's computer at a private firm had possibly been compromised, which let the attacker bypass that code. That data was taken between July 27 and August 8 and concerns nearly 435,000 households, according to a September 4 Senate finance committee note reported by Public SΓ©nat.
How the attacker got in
- Credentials: several dozen DGFIP staff passwords, stolen over three months, probably by infostealers on computers the DGFIP did not manage, most likely staff's own devices.
- Password-only portals: PIGP, used for email and HR services, and ADER, which provides access to DGFIP applications via the RIE, asked only for a password. A stolen one worked immediately.
- Borrowed network access: the attacker reached the RIE, the network connecting French government ministries, through compromised Education ministry systems.
- Flat segmentation: sensitive DGFIP applications could be reached from parts of the RIE that had no apparent need for them. Investigators found traces of many attempts to move into other government bodies.
- Ordinary accounts: none of the accounts had special privileges, yet they could reach a large amount of data. ANSSI did not examine how user rights were managed in this report.
β οΈ The reset that left the session open β On June 23 a threat intelligence provider flagged an account, and a SOC ticket opened at 8:50 p.m. Paris time. At 4:26 a.m. the attacker began scraping E-Contact through ADER. The SOC handled the ticket at 10:40 a.m. by resetting the password. That resolved the PIGP alert but did not end the attacker's open ADER session. Data kept flowing for almost 16 more hours, until 2:31 a.m. on June 25.
Why no one saw it
The DGFIP already had a routine for stolen logins: when the SOC detected a compromised account or a provider flagged one, it reset the password. That routine fired several times. On June 7, searches from a stolen account triggered an alert and a same-day reset, but the SOC missed the attacker's move from PIGP to ADER. In July it happened again. The attacker restarted automated extraction on July 22 with another stolen account. The SOC spotted suspicious searches the next day and reset the account on July 24.
The SOC was not monitoring ADER at all. Nothing linked the warning signs: night logins, VPN connections, addresses in India, addresses known to be malicious. The 11 GB exchanged between June 22 and 25 raised no alert. Per-user request counts were not checked, even though scraping takes one request per page. ANSSI acknowledges that each signal alone usually produces many false alarms, but says that together they could have raised an alert.
ANSSI's own monitoring missed the theft too. Its sensors sit only at the entry and exit points of the RIE and the internet, and it has no access to application logs. Because the traffic came from real staff accounts, it looked legitimate. The agency still says the total request volume should have raised alerts. On June 9, the Education ministry's security team sent 17 indicators of compromise to all ministries. The attacker had already used one of those addresses and used it again in late June.
The RedEye take
The DGFIP did not have a detection problem. It had a response problem. Its alerts fired at least three times across June and July, and each time the result was a password ticket instead of an intrusion investigation. A password reset is account housekeeping. It does not contain an intrusion. When nearly 14 hours pass between a ticket and a reset, and the reset leaves the live session running, the attacker decides how long the incident lasts.
The second lesson is about who controls the perimeter. Here it was set by machines the DGFIP did not own: staff personal devices carrying infostealers, a private surveyor's laptop, another ministry's network. The August claim of sophistication did not hold up against the audit. Public bodies that explain a breach before it has been investigated put their credibility at risk. The open question is the one ANSSI left out of scope: why accounts with no special privileges could reach this much data.
What defenders should learn
- A credential alert is an intrusion until proven otherwise. The response has to cover every application the account can reach, including sessions that are already open. In this case, one reset left ADER pulling data for almost 16 hours.
- Coverage gaps matter more than detection rules. The SOC watched PIGP and did not watch ADER at all. A current map of which authentication points feed the SOC is worth more than another alert.
- Correlate weak signals for each identity. Night logins, VPN egress, unusual geography and request volume are noisy alone. Together, according to ANSSI, they should have caught an 11 GB scrape.
- Password-only portals assume every device holding the password is clean. Infostealers on unmanaged personal machines supplied several dozen working credentials, and the emailed code on APEX did not survive a compromised partner endpoint.
- Indicators shared by peers lose value quickly. The 17 indicators arrived June 9, and the attacker reused one of the listed addresses weeks later. How fast a SOC takes in and acts on peer intelligence is something it can measure and improve.
Originally published on RedEye Threat Intelligence.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.