France’s cybersecurity agency ANSSI has published its incident report on the summer attacks against the tax administration, DGFiP, and it points to stolen legitimate logins, a flat network and monitoring gaps.

What happened

At the Prime Minister’s request, ANSSI investigated activity on DGFiP systems between May and August 2026 and published its report on September 29. It covers two data thefts, one involving the impots.gouv.fr platform, claimed on August 12, and one involving land-registry data, claimed the next day. ANSSI says the compromise followed weaknesses in three areas. Attackers used valid credentials of DGFiP users, obtained after those users signed in from personal devices, and sensitive portals had no strong authentication. Sensitive applications were exposed to the internet or reachable from the state’s interministerial network without segmentation, which allowed movement from a third-party body, the Education ministry. And neither DGFiP’s monitoring nor ANSSI’s detected either wave of theft.

Why it matters

The report names ordinary controls, not an advanced technique. ANSSI says DGFiP did not supervise one of the portals the attacker used to take data, and that no mechanism correlated the suspicious signals it did have. ANSSI adds that its own sensors could not see the behavior, citing probe placement, missing network indicators and missing detection rules. ANSSI and DGFiP have agreed an action plan, and the report lists improvements to detection and to coordination between ministries.

Our read

Password-only access to a portal that reaches sensitive data is a design decision, and infostealer logins from unmanaged personal devices make that decision fail. Test it in a day: list every portal that accepts a password alone, then check that monitoring covers each one. If a national agency’s sensors missed the theft, a SOC that watches only the systems it already knows about will miss the next one as well. We made a related argument about identity checks that attackers walk around, and covered forgotten accounts as an entry point into Microsoft 365.

Source: ANSSI, incident report on the cyberattacks affecting the DGFiP