France's tax authority lost information on 678,000 individuals due to a compromised login.

France's tax authority lost information on 678,000 individuals due to a compromised login.

      The French tax authority has reported that an attacker accessed data belonging to 678,000 individuals and businesses. These breaches occurred during June and July. The agency only confirmed that data had been extracted after the attacker made an announcement in August.

      In a statement dated August 14, the Direction générale des Finances publiques detailed the information accessed by the attacker. For individuals, this included reference tax income, family quotient, and withholding tax rate. For companies, the information accessed comprised the registered name and SIREN number. The attacker also accessed cadastral records, which include property addresses and size.

      The tax agency clarified what information was not compromised. The breaches did not affect personal or professional accounts on impots.gouv.fr, and no taxpayer usernames or passwords were taken.

      The method of access did not involve a software vulnerability. The attacker exploited the stolen credentials of a DGFiP employee and an authorized third party. According to Help Net Security, the attacker also managed to circumvent multi-factor authentication.

      In this context, an authorized third party refers to an external entity that has been given access to the tax agency's systems, such as notaries, bailiffs, and local authorities, thereby increasing the number of potential logins.

      This trend of breaches using old passwords, rather than exploiting new vulnerabilities, is becoming more common. For instance, attackers accessed 75,000 Fortinet firewalls in June by using outdated passwords. Currently, login credentials are the new perimeter security concern.

      DGFiP confirmed it had disabled every compromised account as soon as the breaches were detected. The access checks conducted at that time showed no evidence that any data had been exfiltrated. The agency attributes this oversight to the sophistication of the attack.

      The breach was uncovered when someone using the alias ZeroBytes claimed responsibility on a cybercrime forum on August 12 and 13, offering a database for sale. In-depth investigations by DGFiP began the same day, leading to the identification of 678,000 affected individuals. One of the forum messages stated, “I’m still logged into the panel, so if you want, you can buy it along with the database,” as reported by Help Net Security.

      However, no one outside the agency can verify this claim, which contradicts DGFiP's assertion that it closed all compromised accounts upon detection. Subsequently, the agency has taken additional measures to restrict access to sensitive systems as a precaution, collaborating with the finance ministry's security office and ANSSI, the national cybersecurity agency.

      There is a discrepancy in the reported numbers; ZeroBytes claimed the portal contained records on approximately 20 million French citizens. They asserted that they had extracted 252,149 records covering over two million individuals, stating that retrieving the remaining data would take months. The government's figure remains at 678,000 individuals and businesses.

      DGFiP has stated that its investigations are ongoing, and it has not yet determined the exact amount of data so far extracted or the final count of affected users. A similar discrepancy in numbers had previously occurred during a breach involving France's sovereign messenger in June, where officials and the hacker disagreed over the severity of the incident.

      A crisis meeting chaired by Prime Minister Sébastien Lecornu took place on Monday, addressing the breach within the tax agency. A judicial investigation was already underway prior to this meeting, according to Bloomberg.

      Lecornu tasked ANSSI with auditing the incident to identify its causes, as reported by INCYBER. He also requested a security audit of DGFiP’s systems, with operational findings expected by September. The Paris prosecutor has initiated an investigation into fraudulent data extraction and criminal conspiracy.

      Notifications regarding the breach began that evening via email and continued throughout the week. Each notification outlined the data the attacker may have accessed or extracted, along with recommended precautions. DGFiP has informed CNIL, the data protection authority, and indicated that it would file a criminal complaint.

      In response to the breaches, the government announced a plan to enhance state cybersecurity at the end of April, involving an investment of €200 million. It also set a goal for each ministry to allocate 5% of its digital budget towards cybersecurity by 2027.

      The intrusions into DGFiP occurred in June and July, and INCYBER noted that fraudulent access to FICOBA, the national bank account registry, had previously occurred a few months prior, which was also achieved using stolen credentials. Help Net Security reported a third incident involving France Titres in April.

      Other European public agencies have experienced similar data breaches. France’s statistics office had its staff directory compromised in June, while attackers in Liechtenstein accessed the registry of shell company owners.

      The exposed data presents unique risks. The combination of reference tax income and withholding rate reveals a household’s earnings, while cadastral data provides information about the household’s residence and property size.

      French authorities have cautioned that this information could be utilized for scams and identity theft. There is a specific threat of callers who are already

Other articles

EY will retain interns for a year prior to extending a job offer to them. EY will retain interns for a year prior to extending a job offer to them. EY will retain assurance interns on a part-time basis for 8 to 12 months following their internship, as AI takes over the junior tasks that new employees used to learn. The DOJ is looking into Andreessen Horowitz regarding rival board positions. The DOJ is looking into Andreessen Horowitz regarding rival board positions. The DOJ investigation into Andreessen Horowitz is questioning if its partners are part of rival AI boards. This was reported by Bloomberg on Monday. The legislation originates from 1914. Greg Brockman stated that OpenAI did not fully recognize the cyber capabilities of its own models. Greg Brockman stated that OpenAI did not fully recognize the cyber capabilities of its own models. Greg Brockman dismissed OpenAI's departures during a television appearance. In a blog post he penned, he mentioned that the company had misjudged the cyber capabilities of its models. The wildfire app that has gained popularity in America is aiming to tackle even larger disasters. The wildfire app that has gained popularity in America is aiming to tackle even larger disasters. Watch Duty has established its reputation by monitoring rapidly spreading wildfires, and the introduction of nationwide flood coverage marks the initial move towards transforming the nonprofit into a more comprehensive disaster-warning service. Tesla Discreetly Activates Power Export Feature on Its Top-Selling Electric Vehicle Tesla Discreetly Activates Power Export Feature on Its Top-Selling Electric Vehicle Tesla has discreetly activated vehicle-to-load capabilities on the Model Y Premium in the US using an $80 adapter, limited to 2.4kW. However, vehicles in Europe and Canada still lack this feature. Forget doomscrolling; Gen Z is now scrolling through bird content on TikTok. Forget doomscrolling; Gen Z is now scrolling through bird content on TikTok. Birdwatching is gaining traction among a younger demographic on TikTok, where millions of views are introducing Gen Z to birds, wildlife, and a growing outdoor pastime.

France's tax authority lost information on 678,000 individuals due to a compromised login.

The breach at the French tax agency revealed 678,000 records. DGFiP managed to terminate the intruder's access but failed to detect the theft and found out about the extent of the breach through a post on a forum.