A report from France's national cybersecurity agency ANSSI reveals that a data breach at the country's tax administration, DGFIP, was far less sophisticated than initially claimed. The attackers used several dozen stolen staff passwords, likely harvested by infostealer malware from personal devices, to access taxpayer and business data through the E-Contact messaging tool. The theft, affecting over 350,000 individuals and 250,000 businesses, went unnoticed for seven weeks until the attacker bragged about it on a forum in August.

The report identifies two attack routes. One went through PIGP and ADER, portals protected only by passwords, while the other abused a land surveyor's compromised computer to bypass a one-time code on the APEX portal. ANSSI says the attack worked because sensitive DGFIP applications were not separated from the broader government network, and because the DGFIP's security operations center was not monitoring ADER at all. Alerts were raised and passwords reset, but open sessions were not terminated, allowing automated scraping tools to keep pulling data for hours.

Notably, ANSSI's own monitoring also missed the theft. Its sensors sit only at the entry and exit points of the government network, and it has no access to application logs. Because the attackers used real staff accounts, the activity looked legitimate. The report contrasts with an earlier statement from the ministry overseeing DGFIP, which attributed the breach to the "sophistication of the attack." ANSSI explicitly says the attack was not sophisticated, pointing to weak login protection, poor network separation, and gaps in monitoring as the real causes.