← All resources

DGFiP breach: stolen logins, no MFA, no detection (29/09/2026)

Published October 6, 2026 · 7 min read · CyberNovaLabs.io

On 29 September 2026 France's cyber agency ANSSI published its incident report on the cyberattacks against the tax administration. No rare technique: passwords stolen from personal computers, a second factor sent by email, sensitive applications reachable without segmentation, and a portal nobody was watching. All four links exist in most SMEs.

The short version

On 29 September 2026 ANSSI published its incident report on the cyberattacks against the Direction generale des finances publiques, dated 23 September 2026 and referenced 3033/ANSSI/SDO/NP[1][2]. The ANSSI DGFiP report covers malicious activity spread from May to August 2026, with two automated exfiltration waves - 11 GB on 24 and 25 June, 3 GB on 21 and 22 July - then access to cadastral data between 27 July and 8 August[1]. For an SME the value of the document is not the size of the leak: the attack chain it describes needs no rare skill and works the same way in a ten-person company.

Four links, all of them ordinary

The first link is identity. The report describes the theft, over a three-month period, of several dozen credentials belonging to legitimate staff, probably compromised by infostealer malware on computers not managed by the administration, as a consequence of personal device use[1].

The second link is authentication. Two portals did not enforce strong authentication, and where a second factor did exist, ANSSI calls it insufficient because it was a one-time code sent by email[1]. A code delivered to a mailbox the attacker already controls is not a second factor; it is the same factor twice.

The third link is architecture. Sensitive applications were reachable from the French interministerial network without segmentation, which increased their exposure and opened a lateral movement risk from third-party resources[1]. The attacker reached that network through the compromise of another ministry, the ministry of education[1]. In plain terms: a neighbour's perimeter became the front door.

The fourth link is detection. During the incident the DGFiP security operations centre was not monitoring the ADER portal - the very portal used to exfiltrate - and no mechanism correlated the suspicious signals: night-time logins, abnormal volumes, malicious IP addresses, industrial-scale page scraping[1].

What it changes for an SME

Each of the four links has an equivalent in a small company, and none of them is expensive to fix.

Accounting firms, fiduciaries and software vendors are first in line

The report puts the E-Contact portion at close to 353,000 individuals and 252,000 professionals[1]. Firms that file electronically on behalf of clients, and vendors connected to tax portals, concentrate the data of dozens of companies inside a single account: the value of one stolen credential there has nothing to do with the size of the firm. The CNIL, which received the breach notification, states that individual and professional usernames and passwords are understood not to be affected, but warns about phishing built from the extracted tax and address data[3]. The actor separately claimed two million French people for the cadastral part - that is an attacker's claim, not a figure confirmed by ANSSI[1]. If this is your business, re-read our analysis of NIS2 scope for accounting firms and fiduciaries in France.

And if the leak starts with you?

The four countries CyberNovaLabs.io works in apply the same GDPR, with different authorities and the same 72-hour deadline to notify a breach likely to result in a risk.

CountryData protection authorityLead cyber authority
FranceCNILANSSI / CERT-FR
BelgiumAPD / GBACCB
NetherlandsAutoriteit PersoonsgegevensNCSC-NL / RDI
LuxembourgCNPDILR

If your company falls within the scope of NIS2, the directive adds a report to the competent CSIRT on top of the GDPR notification: an early warning within 24 hours, then an incident notification within 72 hours. Check your scope before the incident, not during it. Our article on breach notification duties after the Jims leak sets out the procedure and the expected content.

Do this week

  1. List every business portal (banking, tax, payroll, CRM, invoicing) and note, for each one, which second factor is actually active.
  2. Replace every email one-time code with an authenticator app or a hardware key.
  3. Ban in writing any access to company tools from an unmanaged personal computer, and provide the alternative.
  4. Turn on unusual-sign-in and mass-download alerts on mail and file storage.
  5. List the providers holding access to your systems and remove the ones you no longer use.
  6. Confirm that a password leaked elsewhere opens nothing of yours: no credential reused across two services.
  7. Write on one page who calls whom, in what order, the day a leak is confirmed - and which authority to notify within 72 hours.

At CyberNovaLabs.io

We audit this exact perimeter for SMEs in the Netherlands, Belgium, France and Luxembourg: access inventory, the real state of multi-factor authentication, application exposure, and a minimum set of detection alerts. The method is described on our cybersecurity page, and our B2B teams also run appointment setting from Brussels. If you want to know in thirty minutes which of the four links is open in your company, let us talk it through in a first call.

Sources

  1. ANSSI - Rapport d'incident n° 3033/ANSSI/SDO/NP sur les cyberattaques ayant touche la DGFiP (date du 23/09/2026, publie le 29/09/2026)
  2. ANSSI - L'ANSSI publie le rapport d'incident sur les cyberattaques ayant touche la DGFiP (29/09/2026)
  3. CNIL - Piratage du systeme d'information des impots : les verifications sont en cours (18/08/2026)
CyberNovaLabs.io

Qualified meetings, no lock-in.

Criteria in writing before launch, pay per meeting or monthly, stop with a simple email.

→ Get meetings booked

Read next

Newsletter · CyberNovaLabs.io

Security Briefing

One email a month: a figure from our barometer, the NIS2 and CRA dates that matter in the Netherlands, Belgium and Luxembourg, and one practical guide. In English. Unsubscribe in one click.

→ Get meetings booked