government security3 articles
French Tax Authority Breach Exposes Financial Data on 680,000 Citizens
France's tax authority (DGFiP) has disclosed a data breach affecting approximately 680,000 individuals, after a threat actor used compromised employee and third-party credentials to access its systems in June and July. Stolen data includes reference tax income, withholding tax rates, company identifiers, and real estate cadastral data, though no passwords or usernames were compromised. The breach was reported to France's data protection authority CNIL, and DGFiP is contacting all affected individuals while continuing to investigate the full scope of the incident.
France's Tax Authority Confirms Data Breach After Hacker Hawks 2 Million Taxpayer Records Online
France's tax authority (DGFiP) has confirmed a data breach that occurred in late June 2026, in which an attacker using stolen credentials and an MFA bypass technique accessed and extracted data on approximately 2 million taxpayers. The alleged criminal, known as "ZeroBytes," advertised the stolen database on a cybercrime forum and claimed to still have access to DGFiP's systems, though the agency disputes this and says access was severed during a routine audit. The incident is one of several significant cyberattacks targeting French public sector organisations in 2026, following earlier breaches affecting the Finance Ministry, Health Ministry, and the passport and driver's licence agency France Titres.
CISA Left Its Passwords in a Public GitHub Repo Called 'Private-CISA'
CISA, the US cybersecurity agency, had a trove of sensitive credentials — including plaintext passwords, SSH private keys, and tokens — exposed in a public GitHub repository called "Private-CISA" since at least November 2025, with GitHub's default secret-protection features deliberately disabled. Security testing confirmed the leaked credentials provided high-privilege access to multiple AWS GovCloud accounts, and the repo appears to have been managed by CISA contractor Nightwing. The incident marks yet another security embarrassment for CISA, following a separate January 2026 incident in which the acting director uploaded sensitive government documents to ChatGPT.