An extensive data breach within France’s tax administration, involving the unauthorized access to sensitive data of hundreds of thousands of taxpayers and businesses, remained undetected for a prolonged period during June and July. The breach, which exploited stolen staff passwords, was not identified by the tax administration or France’s national cybersecurity agency, ANSSI, until much later.
The Breach Details and Initial Response
The breach targeted E-Contact, a messaging tool used by taxpayers to communicate with France’s tax website, impots.gouv.fr. The compromised information includes data from over 350,000 individuals and 250,000 businesses. Notably, personal taxpayer accounts and their passwords remained secure, with only administrative data being accessed.
Information for individuals included tax IDs, contact information, and other personal financial data, while business data involved company names and registration details. Alarmingly, the theft was only discovered on August 12, following an online claim by the attacker. This prompted Prime Minister Sébastien Lecornu to request a comprehensive audit by ANSSI.
Understanding the Attack Methodology
The attack was initiated via two main avenues. The first involved unauthorized logins starting in early May, which led to the exploitation of the E-Contact system. Attackers utilized several stolen passwords of DGFIP staff, likely obtained through malware from unmanaged personal devices, to infiltrate internal portals like PIGP and ADER.
The breach exploited weaknesses in network separation, allowing access to sensitive applications without proper authorization. Attackers also navigated through compromised systems connected via France’s government network, RIE, accessing and extracting data without special account privileges.
Failures in Detection and Security Recommendations
The DGFIP had a routine in place for dealing with compromised staff logins, yet failed to detect the full scope of the data theft. ANSSI’s report noted the absence of comprehensive monitoring and adequate alerts, which allowed the attacker to continue extracting data undetected.
Post-incident, several security measures were proposed, including enhanced monitoring of all business applications, implementation of strong authentication protocols, and setting data access limits. ANSSI further recommended adopting multi-factor authentication and prohibiting access from personal devices to prevent future breaches.
Looking Ahead: Strengthening Cybersecurity
In response to the breach, significant disruptions occurred as the DGFIP restricted access to compromised systems and portals. An action plan is underway to bolster cybersecurity measures, focusing on improved login security and comprehensive monitoring strategies.
ANSSI’s recommendations emphasize the importance of revoking active sessions during password resets, conducting thorough investigations into compromised accounts, and deploying more robust authentication methods. These steps aim to fortify the DGFIP’s defenses and prevent similar incidents in the future.
The incident underscores the critical need for continuous vigilance and proactive cybersecurity measures within government agencies to protect sensitive data and maintain public trust.
