
France's tax authority has confirmed a major data breach affecting 678,000 individuals and professionals after cybercriminals gained access to systems of the Direction générale des Finances publiques (DGFiP).
The disclosure came after a threat actor publicly claimed responsibility for the attack and advertised allegedly stolen DGFiP information on a cybercrime forum.
According to the French government, the attacker gained access to DGFiP information systems in June and July using compromised credentials.
DGFiP says it terminated access for the accounts involved after detecting the intrusions. However, initial access checks did not reveal that data had also been stolen, which authorities attributed to the attack's sophistication.
Following claims made by the attacker on August 12 and 13, investigators conducted a deeper analysis and determined that the unauthorized access had been used to view and extract information belonging to 678,000 people and professionals.
The incident is now being investigated by France's national cybersecurity agency, ANSSI. DGFiP has also notified the French data protection authority, CNIL, and said it will file a criminal complaint.
The confirmed compromised information includes some sensitive financial and tax-related details.
For individuals, the exposed data includes reference taxable income, family quotient and withholding tax rates. Cadastral information was also accessed, including property addresses and property sizes.
For businesses, the stolen information may include company names and SIREN numbers.
Importantly, DGFiP says personal and professional accounts available through its online services were not compromised and users' usernames and passwords were not stolen.
DGFiP says it will contact each affected individual and professional directly by email or postal mail. Those notifications should explain which information may have been stolen and provide recommendations on precautions users should take.
Even without exposed passwords, however, the stolen information could create opportunities for highly convincing fraud.
Tax information, property details and other data can give scammers valuable context when impersonating tax authorities, banks or other organizations. Affected users should therefore be particularly cautious about unexpected messages claiming to come from DGFiP or another government service, especially those asking them to verify an account, provide additional information, follow a link or make a payment.
If you receive a notification from DGFiP, don’t panic. Read it carefully and check what information was affected. Keep in mind that scammers may also try to take advantage of news about the breach by sending fake notifications of their own.
Here are a few precautions you can take:
Also, remember that information stolen in a data breach can remain useful to criminals long after the initial incident. Tax, financial and property information could also be combined with data obtained from other breaches to build a more complete profile of a potential victim, making future phishing, impersonation and social engineering attempts harder to spot.
tags
Alina is a history buff passionate about cybersecurity and anything sci-fi, advocating Bitdefender technologies and solutions. She spends most of her time between her two feline friends and traveling.
View all posts