Mastodon Skip to content
live markets
S&P 5007,707.98▲ 3.36%NASDAQ26,331.09▲ 3.18%DOW53,463.05▲ 2.52%GOLD4,558.30▲ 13.66%WTI84.66▲ 1.72%BRENT92.03▲ 3.15%EUR/USD1.1684▲ 2.24%USD/JPY158.39▼ 2.54%DXY98.82▼ 2.15%BTC$69,566▲ 7.40%ETH$2,263▲ 18.20%SOL$84.97▲ 10.40%TOTAL CRYPTO$2.46T▲ 7.85%
pulseofnations.
UTC --:--NYC --:--LON --:--WAW --:-- bluesky ↗ Join the wire

France Tax Authority Breach Hits 678,000 Accounts

Hackers compromised 678,000 accounts at France’s DGFiP tax agency, exposing citizen names, addresses, and tax reference codes.

Partner Surfshark VPN

France’s national tax authority, the Direction Generale des Finances Publiques (DGFiP), has confirmed a cyberattack that compromised 678,000 user accounts, exposing citizen names, physical addresses, and tax reference codes.

The breach, disclosed on August 19, marks one of the largest compromises of a Western European public financial institution in recent months. Security analysts said the attackers gained access through stolen employee credentials combined with an authorized third-party account, a technique that continues to defeat defenses at government agencies across the continent despite years of investment in perimeter security.

Stolen Credentials Behind the Attack

According to initial findings reported by TechRound, the breach stemmed from compromised employee login credentials used alongside a legitimate third-party account. The attack did not require advanced tools or zero-day exploits. Security experts said the scenario highlights how credential theft remains the most persistent and cost-effective vector for breaching institutional systems.

“This is a stolen credential attack – an employee login plus an authorized third party,” said Viktor Bulanek, founder of penetration testing firm Penetrify. “No AI was required for it. The real lesson is duller and more useful.”

Automated Credential Attacks Surge Across Europe

The DGFiP incident fits a pattern of escalating attacks against Western government institutions, health networks, and financial bodies over the past 18 months. A 2025 Verizon Data Breach Investigations Report documented a 30% annual increase in credential-based attacks, driven by automated phishing tools and AI-powered credential stuffing at industrial scale.

IBM’s 2025 Cost of a Data Breach report placed average incident costs at $4.88 million, up 10% year-on-year. Security researchers at Penetrify noted that fully automated penetration tests now cost as little as $1.72 per run, making it cheaper than ever to probe targets for weaknesses. Attackers can now iterate fresh phishing variants before corporate governance workflows approve a single security patch.

Taxpayer Data Exposed to Fraud

Tax reference codes combined with names and physical addresses give attackers sufficient information to file fraudulent tax returns or open credit accounts in victims’ names. French authorities have urged affected taxpayers to monitor their accounts and report suspicious activity to the DGFiP. The agency said it has revoked compromised credentials and is working with French cybersecurity agency ANSSI on a full forensic investigation.

The breach comes at a sensitive time for European data security. The EU’s e-Evidence regulation, enabling cross-border digital searches by law enforcement, took effect on August 18, just one day before the DGFiP incident was disclosed. The proximity of the two events raises fresh questions about whether member states can adequately protect the sensitive data their tax and public service systems hold.

Sources: TechRound; SecurityWeek; Verizon 2025 Data Breach Investigations Report; IBM 2025 Cost of a Data Breach Report

React to this dispatch
Share this dispatch X WhatsApp Report an error

discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Next dispatch CareCloud Breach Hits 3.7 Million, Ten Times Initial Estimate Read →