France's Tax Authority Confirms Data Breach After Hacker Hawks 2 Million Taxpayer Records Online
France's General Directorate of Public Finances (DGFiP) has confirmed a data breach after someone going by the alias "ZeroBytes" turned up on a cybercrime forum this week advertising what they claimed was a database of over 2 million French taxpayers.
According to the seller, the intrusion happened by way of stolen credentials combined with an MFA bypass technique. They also claimed to still have active access to DGFiP systems, helpfully offering to throw that in alongside the database purchase.
DGFiP pushed back on the persistent access claim. In a statement issued Thursday, the directorate said the breach occurred at the end of June and that access had already been cut as part of a routine audit before ZeroBytes made their forum debut. So either the attacker is bluffing about still being inside, or the audit missed something. Neither option is particularly reassuring.
The directorate confirmed that during the intrusion, data relating to both individuals and businesses was browsed and extracted. It says it has filed a complaint, imposed additional access restrictions, and will notify France's data protection authority CNIL once it has a clearer picture of exactly who and how many people were affected.
This would be easy to dismiss as an isolated incident if France's public sector hadn't been haemorrhaging data all year.
In February, the Ministry of Finance admitted attackers had walked off with 1.2 million records containing French citizens' bank details, again via stolen credentials. The ministry said access was revoked quickly, which presumably still counts as a win in the current climate.
A few weeks after that, the Health Ministry confirmed a cyberattack on healthtech provider Cegedim Santé. Around 15.8 million administrative files were taken, with roughly 165,000 containing doctors' notes that in some cases revealed patients' medical histories.
April brought news of a breach at France Titres, the agency that handles passports and driving licences. The alleged perpetrator, reportedly aged 15, posted the stolen data online and claimed it covered somewhere between 18 and 19 million people. That is more than a quarter of metropolitan France's population, lifted apparently by a teenager.
At this rate, France's public sector isn't so much experiencing a cybersecurity problem as conducting an extended stress test of its citizens' tolerance for data exposure.