France’s tax authority admits hackers made off with data on 678,000 individuals
Incidents: Hackers breached France’s tax authority, exposing data on 678,000 individuals via stolen credentials and MFA bypass.
Deep Analysis and Expert Commentary
The attack vector involved compromised login credentials combined with an MFA bypass technique, highlighting vulnerabilities in multi-factor authentication implementations. The attacker, 'ZeroBytes,' claimed access to a portal containing data on 20 million French citizens but only extracted 252,149 records due to technical difficulties. DGFiP's delayed detection of data theft underscores the sophistication of the attack, which targeted tax income, family quotient, and business identifiers. Mitigations include immediate account suspension, enhanced access controls, and collaboration with ANSSI. Organizations should review MFA robustness, monitor for credential leaks, and implement behavioral analytics to detect anomalous access patterns.
Action Items
- Review and strengthen MFA implementations to prevent bypass techniques.
- Conduct thorough access control audits to identify and remediate compromised accounts.
- Deploy behavioral analytics to detect and respond to anomalous access patterns.
Original Article Brief Intro
Help Net Security · 2026-08-17 · Incidents: Hackers breached France’s tax authority, exposing data on 678,000 individuals via stolen credentials and MFA bypass.
Related Terms and Notes
Malware Families
- DGFiP — France’s General Directorate of Public Finances, responsible for tax collection and public financial management.
Techniques / TTPs
- credential theft
Context Notes
- cybercrime
- data breach
- data_breach
- MFA bypass — Techniques used to circumvent multi-factor authentication, often exploiting weak implementations or social engineering.
- MFA_bypass
- tax authority
- tax_authority