ANSSI, France's cybersecurity agency, published its incident report on the attack against the Direction générale des Finances publiques on 29 September 2026. The report is dated 23 September and went to the prime minister on the 24th. Its finding about the method is one line, and it is the least comfortable one available: the intrusion "n'est pas la conséquence d'une attaque sophistiquée" — it is not the consequence of a sophisticated attack.

The data covers roughly 353,000 individuals and 252,000 businesses by ANSSI's count.

Passwords that were already for sale

The attacker did not break the authentication. They logged in.

ANSSI found no brute force and no credential stuffing. What it describes is several dozen agents' usernames and passwords, most likely collected by infostealer malware from machines the DGFiP does not administer — agents' own computers, where a work password had been typed into a browser and kept there.

That is the ordinary shape of credential theft in 2026. The infostealer economy sells logs by the thousand, filtered by the domains they contain. An administration's own perimeter is irrelevant to it, because the capture happens somewhere the administration has no visibility and no authority.

Against that, the single control that would have mattered is multi-factor authentication, and ANSSI's finding is that sensitive portals did not require it.

Three days of scraping

The exfiltration itself was not subtle either. The files came from E-Contact, the messaging system agents use to correspond with taxpayers, and were taken by a scraper opening records one by one: 24 and 25 June, then again on 22 July.

For individuals, the exposed fields include the tax identifier, contact details, family situation, reference taxable income, withholding rate, and the history of messages exchanged with the administration. Taxpayers' own accounts and passwords were not compromised.

A program paging through a case-handling tool for two days is not a stealth technique. It is a volume of reads that no human account produces, and it ran twice, four weeks apart, without stopping anything.

The alarm came from the attacker

The theft became known on 12 August, when the attacker claimed it on a forum. ANSSI alerted the DGFiP at 16:32 that day.

That is roughly seven weeks after the first extraction. Between the two dates, the published account records no internal detection: no alert on the volume of records read, no alert on logins from unexpected places, nothing from the application itself.

ANSSI's structural findings follow from that gap rather than from the intrusion: no multi-factor authentication on sensitive portals, application-level monitoring absent, and compartmentalisation between ministries weaker than it should be. Each of those is an ordinary recommendation. Together they are the reason a login with a valid password could be used for three months without raising anything.

What this particular data is good for

The fields taken are worth separating from the usual phrase about personal data, because of what they allow in combination.

A tax identifier and a reference taxable income establish who somebody is and what they earn. A withholding rate and a family situation fill in the rest of a household. And the message history with the tax administration gives the attacker the one thing that ordinary fraud lacks: a real, verifiable shared context. Someone calling a taxpayer about a case they actually opened, quoting what they actually wrote, is not a cold call. It is a conversation that is already in progress.

That is why a tax-agency breach is worse than its field list suggests. Nobody can reissue a tax identifier or change their income history, and the state is the one correspondent almost everyone is predisposed to answer.

Seven weeks is the finding

Of everything in the report, the interval is the number to keep. The first extraction was in late June. The agency learned of it on 12 August, from a forum post.

In that period the attacker had working credentials, a working route and no reason to hurry. The second scraping run, four weeks after the first, is the proof: they came back because nothing had changed, and nothing had changed because nobody knew.

Prevention failed once, in a way that is cheap to fix with multi-factor authentication. Detection failed continuously, which is the more expensive problem and the one the report spends its recommendations on.

What to do

  • Require multi-factor authentication on anything holding citizen or customer records, before anything else on this list.
  • Treat work credentials typed into unmanaged machines as already compromised, and plan for that rather than forbidding it in a policy nobody can enforce.
  • Alert on read volume, not only on write and login events. A scraper looks like a very fast, very patient employee.
  • Watch the criminal forums where your own domains appear. In this case, that channel was faster than every internal control combined.

What is not established

  • Who the attacker is. ANSSI does not attribute the intrusion.
  • Whether the data has been sold or published since the claim of 12 August.
  • The exact count. ANSSI's figures are lower than the attacker's own claim, and lower than some early reporting.
  • What has changed since. The report makes recommendations; it does not record which have been implemented.