# French Tax Administration Breach Exposes Data of Over Half a Million

*Published September 30, 2026*
*Source: [https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html](https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html)*

## Executive Summary

Attackers used compromised staff credentials to access and exfiltrate sensitive tax data from France's tax administration, affecting hundreds of thousands of individuals and businesses. The breach went undetected for seven weeks due to weak login protections and insufficient monitoring, prompting an audit and security overhaul.

## Article

In a significant data breach, attackers exploited stolen staff credentials to access and exfiltrate tax data from France's tax administration, affecting over 350,000 individuals and more than 250,000 businesses. This unauthorized access occurred via the E-Contact tool used by taxpayers to communicate with the tax authority. Despite the breach spanning seven weeks from June to July, it remained undetected until the attackers announced it in an online forum.

The incident, attributed to weak login protections and inadequate network segmentation, was facilitated by the use of infostealing malware. This malware likely compromised the personal devices of tax administration staff, allowing attackers to obtain login credentials for internal portals like PIGP and ADER. These portals did not require multi-factor authentication, which enabled the attackers to access sensitive data without arousing suspicion.

The breach exposed personal details such as tax IDs, contact information, and financial data for individuals. Businesses had their registration numbers and communication details compromised. While most of the affected parties had only metadata exposed, a smaller subset of users experienced a more severe data leak, including the content of their communications.

Following the attack, French authorities have initiated a comprehensive audit to address security lapses and reinforce defenses. Measures include implementing robust authentication methods, limiting data access, and enhancing monitoring systems to detect unusual data transfer volumes. The portals involved in the breach have been shut down, and a review of access protocols and network security is underway to prevent future incidents.

The breach underscores the importance of securing sensitive governmental systems against unauthorized access. It also highlights the need for continuous vigilance and timely sharing of threat indicators among government agencies to mitigate risks before they lead to significant data losses.
