News / Cybersecurity
Massive Data Breach in France: How Vulnerabilities Enabled a Seven-Week Hack Published on 30 September 2026 by Christ-loisele (3 min read)
Between June and August 2026, an attacker exploited stolen passwords and network vulnerabilities to gain access to tax and cadastral data on hundreds of thousands of individuals and businesses. The ANSSI and DGFIP reveal critical gaps in their monitoring and network segmentation.
Video: What is the DGFiP, the General Directorate of Public Finances? | The Apprentices of Bercy (Ministry of Economy and Finance, YouTube)
A Data Breach That Went Unnoticed for Seven Weeks
An attacker successfully stole tax and cadastral data between June and August 2026 by exploiting the passwords of employees at the General Directorate of Public Finances (DGFIP) , according to reports from the ANSSI and analyses by FrenchBreaches . The data involves over 350,000 individuals and 250,000 businesses through the E-Contact portal, as well as cadastral information for nearly 435,000 households, exfiltrated between July 27 and August 8, 2026.
The attack began as early as May 2026, with massive exfiltrations detected between June 22 and 25, 2026, totaling 11 GB of data transferred without triggering any alerts. Despite a password reset on June 24, access persisted until June 25 at 2:31 AM, thanks to open sessions that were not closed. The DGFIP’s Incident Response Service (SOC) did note suspicious connections but failed to link them to the ongoing breach.
The hackers used legitimate accounts, making their activity harder to distinguish from normal usage according to the ANSSI.
Illustrative photo: surveillance camera (Lukys1, CC BY-SA 4.0)
Structural Vulnerabilities Exploited by the Attacker
In its report dated September 23, 2026, the ANSSI highlights that the attack was possible due to major weaknesses : insufficient credential protection, flawed network segmentation, and a lack of proactive monitoring. The hackers used two main vectors: first, stolen passwords to access the PIGP and ADER portals, then compromised the workstation of a surveyor to infiltrate the APEX system, dedicated to cadastral data.
The attacker also exploited legitimate accounts, making their activity difficult to distinguish from normal usage. For example, the SOC did not monitor the ADER portal, missing signals such as abnormal data volumes or automated scraping patterns. The ANSSI notes that the cumulative volume of requests during the exfiltrations should have triggered alerts, but no mechanism was in place to detect them.
What This Means Here
For the administrations and businesses of Benin and West Africa, this incident highlights the risks associated with insufficient network segmentation and passive monitoring of privileged access. If similar vulnerabilities existed in local systems, such as shared passwords or unmonitored connections between services, attackers could exfiltrate sensitive data without being detected for weeks. Tax authorities, like the Directorate General of Taxes of Benin, should strengthen their anomaly detection protocols, particularly through real-time monitoring tools and strict segmentation of critical networks.
Furthermore, reliance on external portals, such as those used for tax filings, exposes data to increased risks if these interfaces are not secured to the same standards as internal systems. Strengthened collaboration with agencies like the CERT-Benin or regional counterparts would help anticipate such threats before they materialize.
A timeline revealed by OSINT and official reports
The reconstruction of the attack relies on cross-referenced data: reports from the ANSSI, analyses by FrenchBreaches (specialized in OSINT/CTI), and technical logs. For example, massive data exfiltration began as early as June 22, 2026, with peaks in activity on June 24 and 25, despite a password reset. The attacker claimed responsibility for the operation on August 12, 2026, on an online forum, following seven weeks of apparent inactivity.
The ANSSI confirms that hackers used dozens of compromised accounts, likely obtained through infostealers , and exploited flaws in network separation to access sensitive systems, such as the RIE (Tax Network). There is no evidence that personal accounts of taxpayers or their passwords were directly compromised, but data accessible via E-Contact (such as exchanges with the DGFIP) were exposed.
Sources