France’s national cybersecurity agency ANSSI has published its investigation into cyberattacks affecting the country’s tax administration, the DGFiP. The agency found that attackers used legitimate staff credentials and exploited weaknesses in authentication, network architecture and monitoring to reach sensitive systems and remove data.
Valid accounts reduced the attacker’s visibility
ANSSI traced unauthorized activity between May and August 2026 across the tax portal and a separate land-registry environment. Credentials had been exposed after use on unmanaged personal devices, while some access portals lacked strong authentication. Sensitive applications were also reachable through government network paths without sufficient segmentation.
The report says neither DGFiP monitoring nor ANSSI’s network sensors detected the two data-exfiltration waves. One portal used by the attacker was not monitored, application logs were unavailable to ANSSI and suspicious signals were not correlated across systems.
Session control and application telemetry are central
The case shows why password resets must revoke active sessions across every connected portal. Public-sector operators should combine phishing-resistant authentication, application-level logging, data-volume alerts and segmentation between agencies. Retrospective searches should also connect identity, application and network evidence across administrative boundaries. SectechMedia follows related controls in its cyber-physical security coverage.

Leave a Reply