680,000 Affected by French Tax Authority Data Breach

www.news4hackers.com-680-000-affected-by-french-tax-authority-data-breach-680-000-affected-by-french-tax-authority-data-breach

France’s Directorate General of Public Finances (DGFiP) experienced a significant data breach impacting 680,000 individuals, highlighting vulnerabilities in public institution cybersecurity.

Data Breach Overview

France’s Directorate General of Public Finances (DGFiP) reported a data breach affecting approximately 680,000 individuals. The incident was revealed after a malicious actor claimed to have accessed DGFiP’s internal networks and extracted sensitive information.

Timeline and Investigation

According to the tax authority, the unauthorized intrusion occurred between June and July, with access terminated immediately upon detection. At the time, no evidence of data exfiltration was identified. However, a subsequent investigation confirmed that attackers utilized compromised credentials from an employee and a third-party account to infiltrate systems, resulting in the exposure of data for 678,000 users.

Compromised Information

The compromised information included reference tax income figures, withholding tax rates, company names and identifiers, and cadastral details such as real estate addresses and property sizes. No usernames, passwords, or additional personal identifiers were disclosed.

Response and Reporting

The breach was promptly reported to France’s data protection authority, the CNIL. DGFiP is conducting ongoing analysis to determine the full scope of the incident and the precise number of affected individuals. The agency plans to notify each impacted person directly.

Similar Incident in Romania

This breach follows a similar incident involving Romania’s National Agency for Cadastre and Property Registration (ANCPI), which suffered a disruptive cyberattack one month prior. The Romanian agency was targeted by a threat actor known as ByteToBreach, who stole employee credentials and internal documents before attempting to extort the organization.

Impact of the Romanian Breach

When the extortion demand was rejected, the attacker deleted encrypted data, causing widespread disruption to real estate services and halting operations for three weeks. The central cadastral database remained unaffected, but ANCPI required significant time to restore critical systems.

Cybersecurity Lessons

The DGFiP breach highlights the growing risk of credential-based attacks against public institutions, with threat actors leveraging compromised access to extract sensitive financial and property information. The incident underscores the importance of continuous monitoring, timely incident response, and robust access control measures to mitigate the impact of such breaches.

“The DGFiP breach highlights the growing risk of credential-based attacks against public institutions, with threat actors leveraging compromised access to extract sensitive financial and property information.”



About Author

en_USEnglish