They Changed the Locks. The Burglar Was Already Inside.
June 24, 2026. Someone at France's tax administration spots something wrong and does exactly what the playbook says: reset the password.
Problem solved? Not even close.
The intruder was already logged in. Changing the password didn't kick them out. For roughly 16 more hours, they kept pulling data out through the same open session.
That's one scene from France's official post-mortem of the breach at the DGFiP, the country's tax administration. ANSSI, France's national cybersecurity agency, published it on September 23. It reads like a checklist of every identity mistake you've been warned about.
The damage: tax records on more than 350,000 people, data on more than 250,000 businesses, and land-registry records tied to roughly 435,000 households.
The tax office didn't catch it. It found out on August 12, when the attacker bragged about it online.
No Zero-Day. No Genius. Just Passwords.
Here's what should make you uncomfortable. ANSSI says this was not a sophisticated attack. No custom exploit. No nation-state wizardry.
The attacker had working passwords for about 30 staff accounts. ANSSI found no sign of guessing or brute force. They didn't need to guess. They already had the passwords.
Where from? Most likely infostealers. (An infostealer is malware that quietly copies every saved password and login from a computer and ships them to criminals.) ANSSI believes they were sitting on personal or unmanaged computers that staff used to reach work systems.
Think of it this way. You lock your office every night, but you keep a spare key in your kitchen drawer at home. Someone breaks into your kitchen. Your office is now open.
From there, the attacker walked through three open doors:
Two portals that asked for a password and nothing else. No second factor. (MFA, or multi-factor authentication, is the code on your phone that proves it's really you. These portals didn't have it.)
A government network that wasn't walled off. The attacker got onto France's inter-ministry network through compromised Education Ministry systems, then reached tax applications from there.
A "second factor" sent by email. A third portal used one-time codes, but delivered them by email. The attacker compromised a land surveyor's computer at a private firm and went straight through. If the thief has your inbox, an email code proves nothing.
The Alarms Were There. Nobody Connected Them.
This is the part that should keep security teams up at night.
The signs were loud:
Logins in the middle of the night
Connections through VPNs and from IP addresses in India, some already flagged as malicious
11 GB of data pulled out between June 22 and 25
Query volumes that looked exactly like what they were: a machine scraping a database
Nobody stitched it together. The portal used for most of the theft wasn't watched by the security operations center at all. And the one alert that did lead somewhere ended with that password reset, which left the live session running.
So the attacker kept going. Another 3 GB in late July. Then the land-registry route, from July 27 to August 8.
Seven weeks after the first big haul, the tax office learned about it the same way everyone else did: from the attacker's own post.
Police Have a Suspect. The Data Is Still Out There.
French police arrested an 18-year-old on August 18. He was charged two days later and jailed pending trial. According to French outlet Next, investigators believe he belongs to ZeroBytes, the group that claimed the breach. A 16-year-old was arrested on August 26 and released after questioning.
French outlet Clubic reports the 18-year-old had already been charged twice before, in 2023 and 2024, over earlier cyberattacks, and was under court supervision when this happened.
Sit with that. A national tax agency. A teenage suspect already known to the courts. And the weapon was a pile of stolen passwords.
Arrests don't put data back. Names, income, family situation, past messages with the tax office: that's exactly what makes a scam believable. "Hello, this is the tax office about your withholding rate…" now comes with your real numbers attached.
Six Things to Do Today
ANSSI's fixes aren't exotic. That's the point.
Kill sessions when you reset a password. A reset that leaves live sessions running is theater. ANSSI calls for revoking active sessions on every reset. Ask your IT team whether yours does.
Put real MFA on every app, not just email. ANSSI recommends methods that survive a stolen password, like authenticator apps or hardware keys. Codes sent by email don't cut it.
Keep personal devices off work systems. ANSSI recommends banning it outright. Infostealers love the family laptop.
Watch every business app, and cap the data. The app nobody monitors is the one attackers use. ANSSI suggests volume limits so mass scraping trips an alarm.
Wall off your network. One compromised department shouldn't open a road into another.
Treat every "tax office" message with suspicion. Don't click links in tax emails or texts. Go to the official site yourself. This one's general advice, not ANSSI's, and it applies wherever you pay taxes.
CLOSING
Have you ever logged into a work system from your personal laptop "just this once"? Be honest: how many times was it actually once?
Identity Decoded publishes every week at identity-decoded.com
