DGFiP breach: stolen logins, no MFA, no detection (29/09/2026)
On 29 September 2026 France's cyber agency ANSSI published its incident report on the cyberattacks against the tax administration. No rare technique: passwords stolen from personal computers, a second factor sent by email, sensitive applications reachable without segmentation, and a portal nobody was watching. All four links exist in most SMEs.
The short version
On 29 September 2026 ANSSI published its incident report on the cyberattacks against the Direction generale des finances publiques, dated 23 September 2026 and referenced 3033/ANSSI/SDO/NP[1][2]. The ANSSI DGFiP report covers malicious activity spread from May to August 2026, with two automated exfiltration waves - 11 GB on 24 and 25 June, 3 GB on 21 and 22 July - then access to cadastral data between 27 July and 8 August[1]. For an SME the value of the document is not the size of the leak: the attack chain it describes needs no rare skill and works the same way in a ten-person company.
Four links, all of them ordinary
The first link is identity. The report describes the theft, over a three-month period, of several dozen credentials belonging to legitimate staff, probably compromised by infostealer malware on computers not managed by the administration, as a consequence of personal device use[1].
The second link is authentication. Two portals did not enforce strong authentication, and where a second factor did exist, ANSSI calls it insufficient because it was a one-time code sent by email[1]. A code delivered to a mailbox the attacker already controls is not a second factor; it is the same factor twice.
The third link is architecture. Sensitive applications were reachable from the French interministerial network without segmentation, which increased their exposure and opened a lateral movement risk from third-party resources[1]. The attacker reached that network through the compromise of another ministry, the ministry of education[1]. In plain terms: a neighbour's perimeter became the front door.
The fourth link is detection. During the incident the DGFiP security operations centre was not monitoring the ADER portal - the very portal used to exfiltrate - and no mechanism correlated the suspicious signals: night-time logins, abnormal volumes, malicious IP addresses, industrial-scale page scraping[1].
What it changes for an SME
Each of the four links has an equivalent in a small company, and none of them is expensive to fix.
- The personal laptop. A salesperson opening the CRM on a family machine exposes your access to everything running on it. ANSSI explicitly recommends banning personal devices and hardening company ones[1].
- The email second factor. If your invoicing tool, your online banking or your payroll portal sends its code by email, move to an authenticator app or a hardware key. The report argues for authentication resistant to the compromise of the first factor[1].
- The legitimate account behaving badly. Nobody was looking for an intrusion: the access was valid. What should have raised a flag was volume and timing. An SME can switch on unusual-sign-in alerts in Microsoft 365 or Google Workspace in an hour.
- The connected third party. Your accountant, your IT provider and your industry software vendor all hold access to your systems. The lateral movement ANSSI describes is exactly that scenario, at state scale.
Accounting firms, fiduciaries and software vendors are first in line
The report puts the E-Contact portion at close to 353,000 individuals and 252,000 professionals[1]. Firms that file electronically on behalf of clients, and vendors connected to tax portals, concentrate the data of dozens of companies inside a single account: the value of one stolen credential there has nothing to do with the size of the firm. The CNIL, which received the breach notification, states that individual and professional usernames and passwords are understood not to be affected, but warns about phishing built from the extracted tax and address data[3]. The actor separately claimed two million French people for the cadastral part - that is an attacker's claim, not a figure confirmed by ANSSI[1]. If this is your business, re-read our analysis of NIS2 scope for accounting firms and fiduciaries in France.
And if the leak starts with you?
The four countries CyberNovaLabs.io works in apply the same GDPR, with different authorities and the same 72-hour deadline to notify a breach likely to result in a risk.
| Country | Data protection authority | Lead cyber authority |
|---|---|---|
| France | CNIL | ANSSI / CERT-FR |
| Belgium | APD / GBA | CCB |
| Netherlands | Autoriteit Persoonsgegevens | NCSC-NL / RDI |
| Luxembourg | CNPD | ILR |
If your company falls within the scope of NIS2, the directive adds a report to the competent CSIRT on top of the GDPR notification: an early warning within 24 hours, then an incident notification within 72 hours. Check your scope before the incident, not during it. Our article on breach notification duties after the Jims leak sets out the procedure and the expected content.
Do this week
- List every business portal (banking, tax, payroll, CRM, invoicing) and note, for each one, which second factor is actually active.
- Replace every email one-time code with an authenticator app or a hardware key.
- Ban in writing any access to company tools from an unmanaged personal computer, and provide the alternative.
- Turn on unusual-sign-in and mass-download alerts on mail and file storage.
- List the providers holding access to your systems and remove the ones you no longer use.
- Confirm that a password leaked elsewhere opens nothing of yours: no credential reused across two services.
- Write on one page who calls whom, in what order, the day a leak is confirmed - and which authority to notify within 72 hours.
At CyberNovaLabs.io
We audit this exact perimeter for SMEs in the Netherlands, Belgium, France and Luxembourg: access inventory, the real state of multi-factor authentication, application exposure, and a minimum set of detection alerts. The method is described on our cybersecurity page, and our B2B teams also run appointment setting from Brussels. If you want to know in thirty minutes which of the four links is open in your company, let us talk it through in a first call.
Sources
- ANSSI - Rapport d'incident n° 3033/ANSSI/SDO/NP sur les cyberattaques ayant touche la DGFiP (date du 23/09/2026, publie le 29/09/2026)
- ANSSI - L'ANSSI publie le rapport d'incident sur les cyberattaques ayant touche la DGFiP (29/09/2026)
- CNIL - Piratage du systeme d'information des impots : les verifications sont en cours (18/08/2026)
Qualified meetings, no lock-in.
Criteria in writing before launch, pay per meeting or monthly, stop with a simple email.
Read next
Data breach at FWB: three weeks before it was confirmed (05/10)
Flagged from outside in mid-September, confirmed on 5 October 2026: the EAD-online.be data breach shows where the GDPR's 72 hours are really lost, and why the weak link is so often a supplier.
Read the article →October 7, 2026 · 7 min readNIS2 France: are hotels and tourism in scope?
Tourist accommodation is absent from the NIS2 annexes, and France's transposition was still in parliament on 7 October 2026. Yet in May 2026 three French tourism operators lost their reservation databases within 72 hours. Here is what actually applies to you.
Read the article →October 6, 2026 · 8 min readB2B appointment setting: phone, LinkedIn or email?
Channel choice is not a matter of taste. It is set first by what the law of each country allows for the contact you target, then by the buyer's role. Here are the four national regimes, the channel table by buyer profile, and the formula that tells you how many contacts you need to work.
Read the article →