France's national cybersecurity agency has published a candid post-mortem of the summer 2026 breaches at the Direction générale des Finances publiques (DGFiP), the authority behind impots.gouv.fr and the national land registry. ANSSI's conclusion is uncomfortable for every large public administration: the compromise "is not the consequence of a sophisticated attack." The attackers logged in with stolen credentials of legitimate staff and partners. They reached a sensitive internal portal over the shared interministerial network from another ministry that had already been compromised. They then scraped data for weeks without tripping a single alert, either at the DGFiP or at ANSSI. Security leaders should read this report as a checklist of their own exposures.

What ANSSI published and when

At the Prime Minister's request, ANSSI investigated the timeline of illegitimate activity observed on DGFiP information systems between May 2026 and August 2026, along with the measures that could have prevented or detected it. The resulting 20-page report (No. 3033/ANSSI/SDO/NP, dated 23 September 2026 and marked TLP:CLEAR) was delivered to the Prime Minister on Thursday 24 September and published on 29 September. The public version is anonymised: account names are pseudonymised, and some technical details and IP addresses are redacted.

The investigation covers two exfiltration perimeters:

  • impots.gouv.fr / E-Contact. On 12 August 2026 at 13:50, an actor calling itself Zerobytes claimed on an online forum to have stolen data belonging to the impots.gouv.fr platform. ANSSI notified the DGFiP at 16:32 the same day. On the morning of 13 August, Zerobytes published details of the stolen data, which ANSSI says concerns nearly 353,000 private individuals and 252,000 professionals, taken from a DGFiP tool for managing exchanges with users. The report's timeline also records the claim as announcing 678,437 records (392,867 individuals and 285,570 professionals), based on OSINT/CTI. These figures come from the attacker's claims and publication as recorded by ANSSI, and the report does not reconcile them.
  • Cadastral data (SPDC). On 13 August at 18:44, ANSSI was alerted to a claim covering data from the DGFiP's professional cadastral data server. The claim mentions 2 million French people and an exfiltration on 29 July. According to the attacker, the data includes names, dates of birth, property identifiers, cadastral parcels and information on property owned. ANSSI reports these as the attacker's statements, not as verified figures.

Attack mechanics: credentials, the RIE pivot and industrial scraping

Stolen credentials from unmanaged devices

Over a three-month period, the attacker obtained several dozen credentials belonging to legitimate DGFiP agents. ANSSI says these were "probably compromised via spyware (infostealers) on computers not administered by the DGFiP." Investigators found no brute-force or credential-stuffing attempts, which means the attacker already held working username and password pairs. ANSSI also points to the use of personal devices to reach business resources, including personal devices used with ADER portal credentials and third-party devices used with APEX credentials.

Two portals lacked multi-factor authentication. The PIGP (Portail internet de la gestion publique, which also gave DGFiP agents webmail and HR access) and ADER (a portal for reaching certain DGFiP applications over the RIE) both allowed immediate reuse of stolen credentials.

Lateral movement through the interministerial network

The attacker first validated stolen accounts on the internet-facing PIGP. Minutes later, the same accounts were used on the ADER portal from IP addresses inside the Réseau interministériel de l'État (RIE). The attacker had RIE access because infrastructure belonging to the Ministry of National Education, which is connected to the RIE, had been compromised. ANSSI found that sensitive DGFiP applications were "accessible from the RIE without segmentation." Several illegitimate accesses came from RIE locations with no apparent need to reach DGFiP infrastructure.

Scraping E-Contact

On 23 June, using a newly compromised account, the attacker focused on E-Contact, the DGFiP's messaging application for exchanges with users, and began iteratively developing scraping tools against it. Automated exfiltration began at 04:26 on 24 June and ran until 02:31 on 25 June. The DGFiP SOC had a ticket for suspicious searches by the account. It reset the password at 10:40 on 24 June, but ANSSI notes that the reset "does not interrupt the session and the ongoing exfiltration, which continue." A second wave followed on 22 July, from 07:28 to 11:33 and again from 16:20 to 17:16, using other freshly compromised accounts.

The cadastre: bypassing email OTP via a surveyor's PC

The land-registry theft took a different route. The DGFiP's investigation found that a compromised workstation belonging to a géomètre-expert (land surveyor) at a private firm was used to get around the second factor on the APEX partner portal. On APEX, that second factor is a one-time password sent by email. Data was accessed and exfiltrated between 27 July and 8 August 2026. ANSSI's conclusion is that the MFA implemented on APEX "is insufficient" if the attacker can reach the mailbox that receives the code.

Why nothing was detected

ANSSI's findings on detection are the most significant part of the report. Neither exfiltration wave was detected by DGFiP or ANSSI monitoring. The report lists signals that were present but never correlated:

  • Volume: 11 GB exchanged between 22 and 25 June and 3 GB between 21 and 23 July raised no alert.
  • Request rates: requests per user over time were not tracked, even though scraping requires one request per page retrieved.
  • Source IP: connections came from VPN addresses, addresses geolocated in India and addresses categorised as malicious. Some IPs were reused across accounts already known to be compromised, weeks apart.
  • Time of day: night-time connections were not interpreted as a risk signal.
  • Coverage: the DGFiP SOC was not monitoring ADER, the portal used to exfiltrate E-Contact data.

ANSSI is equally frank about its own blind spots. It had no application-level monitoring on this perimeter. Its network sensors could not distinguish attackers using legitimate accounts, and it had no relevant network indicators or threat-specific detection rules. Even so, it says the cumulative volume of requests "should have triggered alerts." The report also notes that the exfiltration ran from non-privileged accounts that nevertheless had access to large volumes of data. User rights management is left to a second-phase organisational audit.

Missed interministerial signals

On 9 June, the Ministry of National Education's security operations centre (COSSIM) told all ministerial CSIRTs about an incident on its perimeter. It shared 17 indicators, asked for heightened vigilance on traffic from its IP ranges across the RIE, and listed one of the addresses the attacker later used against ADER. More indicators followed on 11 June and 4 July. ANSSI says the time taken to analyse and share such indicators across RIE-connected bodies "should have been reduced to a minimum." It adds that blocking flows at RIE level could have limited exfiltration, but only once legitimate RIE flows have been mapped in more detail.

Timeline of key events

Date (2026, UTC+2)Event (per ANSSI report)
2–8 MaySuspicious PIGP logins with one account from three locations (malicious IPs in France and India). On 7 May, the account authenticates to E-Contact via ADER and its password is reset.
13–17 MayThree more accounts compromised. Suspicious PIGP logins follow from 22 May to 3 June.
7 JuneA new account logs into PIGP, then ADER from RIE addresses. An alert on mailbox searches triggers a same-day reset that misses the PIGP-to-ADER pivot.
9 JuneCOSSIM (National Education) shares 17 indicators with all ministerial CSIRTs.
21–23 JuneReconnaissance on ADER, then iterative development of scraping tools against E-Contact.
24 June 04:26 – 25 June 02:31First automated exfiltration from E-Contact. The password reset at 10:40 on 24 June does not end the session.
21–22 JulyFive credential pairs validated. Second exfiltration wave on 22 July. Account reset and IP blocked on 24 July.
27 July – 8 AugustCadastral data accessed and exfiltrated via APEX using a surveyor's compromised account.
6 AugustANSSI flags two malicious IPs to the DGFiP after a retro-hunt on its sensors. On 11 August, the DGFiP reports resetting five accounts and blocking both IPs.
12 AugustZerobytes claims the impots.gouv.fr theft. ANSSI notifies the DGFiP and informs CSIRT Finances.
13 AugustCadastral claim. The DGFiP disables ADER access for DGFiP agent accounts, a measure the report says should remain permanent.
14 AugustSurveyor's account identified as the cadastral source. Account disabled and portal access locked.
18 AugustPIGP access cut for agent accounts. All accounts of the surveying firm disabled.

ANSSI notes that the containment measures, especially cutting agent and partner access to the portals used for exfiltration, had significant operational impact on DGFiP services and partner organisations.

Remediation: ANSSI's recommendations, translated into a playbook

The action plan agreed with the DGFiP has three main strands: expand monitoring to all business applications, limit credential exposure and implement strong authentication, and reduce the attack surface exposed to third-party networks, including application-level thresholds on the data that can be accessed. The detailed recommendations apply to any organisation that exposes line-of-business applications to partners or shared networks.

  1. Tier application access by audience. Make internal-use applications reachable only from managed devices, with no direct internet access except through a dedicated agent VPN. Put limited-external applications behind site-to-site or point-to-site VPNs, or source-IP allowlists combined with MFA and strict business limits. For public applications, apply geo-filtering and IP-reputation blocking, or at least alert on them.
  2. Ban personal devices for professional access and harden managed endpoints with monthly patching, EDR, antivirus and an always-on VPN.
  3. Deploy MFA on every application, with a second factor that survives compromise of the first. ANSSI specifically rejects email OTP when the mailbox can be opened with a single username and password. It recommends hardware tokens or authenticator apps, ideally on a different device from the one used for the first factor.
  4. Put every application in the SIEM and apply quotas on records accessed, request counts and data volume per period, along with injection-pattern detection and GeoIP and reputation blocking.
  5. Enforce least privilege and consultation caps so that one non-privileged account cannot bulk-read hundreds of thousands of records.
  6. Fix the reset process. A password reset after a compromise notification must revoke active sessions on all applications and portals. It must be followed by a review of the account's activity since the presumed compromise date, and repeated compromises of the same account must lead to a root-cause investigation. ANSSI also suggests studying automatic account blocking on suspicious searches.
  7. Shorten indicator sharing across shared networks and map legitimate flows so that partner-to-partner traffic can be blocked quickly when one member is compromised.

ANSSI also notes that the DGFiP's credential-leak monitoring service, which flagged several compromised accounts, "demonstrated its value" as a safety net. However, it cannot cover every resale platform and leaves a window between account compromise and reset that is long enough for an attacker to start exfiltrating. Threat-intelligence monitoring of stolen credentials supports strong authentication but cannot replace it.