Analysis of the ANSSI report on the DGFiP cyberattack

DGFiP cyberattack: Expert analysis of the ANSSI report on an undetected intrusion

October 2, 2026 Off by Password Revelator

A month after the first revelations, the long-awaited report from the National Information Systems Security Agency (ANSSI), dated September 23, 2026, lifts the veil on the massive hacking of the General Directorate of Public Finances (DGFiP). Far from the image of a sophisticated cyberattack, the analysis reveals a more worrying reality: a series of systemic failures that allowed attackers to navigate under the radar for almost three months.

This article will also interest you: How software created in Loiret 20 years ago is exported throughout the world

Between May and August 2026, state infrastructure was compromised, exposing the data of hundreds of thousands of citizens. A look back at a chronology of the failure and the critical recommendations of ANSSI.

Timeline of a silent intrusion (May - August 2026)

The public alert was not raised until August 12, 2026, when a malicious actor operating under the pseudonym “Zerobytes” claimed data theft on a specialized forum. However, ANSSI confirms that the intrusion began much earlier.

Investigations, cross-referencing DGFiP technical logs and OSINT sources (including FrenchBreaches publications), establish that the first major exfiltration took place seven weeks before the public claim. The attackers thus had a window of several weeks to explore the information system before taking action.

The scale of data theft

The human and technical toll is heavy:

  • 353,000 individuals affected.
  • 252,000 professionals affected.
  • Data source: the “E-Contact” user relationship management tool.
  • Volume exfiltrated: around 11 GB of data between June 22 and 25, followed by almost 3 GB in July.

The root causes: outdated security in the face of opportunistic attackers

One of the key takeaways from the report is that the attack did not require a zero-day (unknown flaw) or cutting-edge technique. Hackers exploited gaping flaws in identity management and network architecture.

1. Credential compromise

The attackers used several dozen legitimate credentials belonging to DGFiP staff. These credentials were reportedly stolen by infostealer malware that infected personal computers not administered by the DGFiP.

The point of failure: The lack of multi-factor authentication (MFA) on some portals allowed hackers to simply reuse these stolen credentials to log into state services.

2. The supervisory blind spot (SOC)

The report points to a critical inability to detect exfiltration in real time.

  • 11 GB of data passed without triggering a major alert.
  • The ADER portal, used for access to data, was not adequately supervised by the SOC (Security Operations Center) of the DGFiP.
  • Weak signals existed: nighttime connections, geolocated IP addresses in India, VPN use and abnormal volume of requests (scraping). ANSSI emphasizes that the correlation of these events should have triggered an alert.

3. The persistent session flaw

A technical detail illustrates the seriousness of the situation: on June 24, following an alert, the password of a compromised account was reset. However, this action did not terminate the active session. The exfiltration continued until June 25 at 2:31 a.m.

The second wave: hacking of cadastral data

The incident was not limited to tax data. On August 13, a second claim targeted cadastral data, this time concerning 2 million French people (names, dates of birth, plots of land).

The investigation here reveals a different attack vector: the compromise of the computer station of a surveyor working in a private practice. The hacker used this partner account to access the APEX portal. Disturbing fact: the attacker managed to bypass the second factor authentication (2FA) sent by email, highlighting the need to move to more robust authentication solutions, such as FIDO2.

ANSSI in the sights of its own criticism

In a rare move, the report does not merely audit the DGFiP. ANSSI recognizes that its own supervision was unable to detect the attack. The Agency explains that it does not have application supervision on the perimeter concerned and notes that the use of legitimate accounts has made the distinction between normal and malicious activity particularly complex.

Recommendations: towards an overhaul of state cyber defense

To prevent such a scenario from happening again, ANSSI issues a series of strict recommendations for administrations:

  • Generalization of MFA: mandatory deployment of multi-factor authentication on all sensitive access.
  • Principle of least privilege: drastic limitation of rights associated with user accounts.
  • Network segmentation: isolation of critical environments to limit lateral movements.
  • BYOD ban: end to the use of personal devices to access work resources.
  • Application supervision: setting up limits on the volumes of data consulted and behavioral analysis (UEBA).
  • IP filtering: taking into account the reputation and geolocation of IP addresses.

Conclusion

The hacking of the DGFiP will remain a textbook case. Not for the sophistication of the attack, but for the banality of its execution. As ANSSI summarizes, the compromise results from “the chain of several weaknesses”: poorly protected identities, non-segmented architecture and, above all, a chronic inability to detect anomalies in the data flow.

For cybersecurity experts, the lesson is clear: perimeter defense is no longer enough. Faced with attackers using valid credentials, only advanced behavioral monitoring and strict digital hygiene will protect citizen data.

Sources

  • ANSSI analysis report dated September 23, 2026 on the DGFiP incident.
  • OSINT and CTI data: FrenchBreaches publications and Zerobytes claim.
  • Recorded Future notifications and network logs from the Ministry of National Education.