French tax authority says break-in exposed data of 600K, including some private messages
Security
Stolen details range from contact information to household finances and withholding rates
France's tax authority says attackers may have stolen the contents of messages exchanged with hundreds of taxpayers during the data raid it confirmed last week.
In an update published this week, the General Directorate of Public Finances (DGFiP) said lists of messages exchanged with the authority were exposed. For around 250 people, the compromised information also included the messages themselves.
Slightly more than 350,000 individuals were affected. The other exposed data included tax identification numbers, marital status, email and postal addresses, and phone numbers.
Tax records also exposed details such as household composition, number of dependents, family quotient, reference tax income, and withholding rates.
Beyond the personal and tax information, DGFiP said the other affected datasets contained information that was already publicly available.
For approximately 250,000 businesses and professionals, the affected data was limited to company names and SIREN numbers, the unique nine-digit identifiers assigned to French businesses.
The compromised cadastral data was limited to property addresses and dimensions, which DGFiP said were already publicly available.
DGFiP said it was notifying affected taxpayers by email or post this week.
DGFiP's latest FAQ pegs the total number of affected parties at roughly 600,000. That appears lower than the 678,000 "individuals and professionals" DGFiP said were affected last week, shortly after the alleged cybercriminal behind the attack, "ZeroBytes," claimed to have stolen data belonging to more than 2 million. The authority did not explain the discrepancy.
The notifications warn that criminals could use the stolen details to make phishing attempts appear more convincing.
DGFiP highlighted impersonation attempts, CEO fraud, and scams involving bogus bank advisers as possible follow-on attacks. The authority said it would never ask taxpayers to provide sensitive information such as PINs or identity documents by phone, text message, or email, and would request such material only through its secure portal.
Separately, the tax authority disclosed a "technical vulnerability" in the government's Vacant Successions Portal (PSV), which is used to search for estates without known heirs.
DGFiP suspended the service after discovering the flaw. It said there was no evidence so far that personal data had leaked, although its investigation into possible exposure of applicants' details continues.
The incident adds to a torrid year for cybersecurity across France's public sector.
In February, the finance ministry, which oversees DGFiP, 'fessed up to an intrusion into a database containing citizens' bank details that affected 1.2 million people.
The Health Ministry confirmed in March that 15.8 million administrative files, 165,000 of which contained doctors' notes, were stolen during an attack on healthtech company Cegedim Santé.
A month later, a 15-year-old allegedly carried out an attack on France Titres, which handles the country's identity documents. The attacker claimed the breach affected between 18 million and 19 million people.
In June, France also began probing an alleged breach of Tchap, the government's encrypted messaging platform, after attackers claimed to have accessed 73,000 user accounts, 643,000 messages, and nearly 60,000 media files. ®
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0
Comments (0)