Following the sequence of apologies from Public Accounts Minister David Amiel to the 678,000 individuals and professionals whose tax data were stolen, a government response was needed to address this “technical debt” with “human and financial resources”.
After an interministerial crisis cell convened by the Prime Minister on August 17, a series of measures intended to plug the breaches in Bercy’s information system were announced in the wake of the event.
First totem of the government’s response: the generalization of two‑factor authentication for all agents of the DGFiP, promised by the end of the year. But Bercy itself acknowledges: several accounts already protected by this mechanism could have been compromised during the latest incidents. The two factors, indispensable as it may be, do not do everything: you still must monitor what happens after logging in.
That is the second axis of the plan: strengthen detection mechanisms to improve the identification of account takeovers and suspicious behaviors. Moreover, access quotas, already applied to certain files such as FICOBA, should be rolled out more broadly. As if under a “zero trust” banner…
Authenticate, educate, detect
The third pillar, more human: intensification of bug bounty campaigns and strengthening training. Also mentioned is a renewed reliance on AI to simulate attacks and detect vulnerabilities before they can be exploited.
A minimum service in cyberspace, one might say…
All the more so given that the surge in massive breaches affecting state services’ databases is well documented.
In a report published in January 2025, the CNIL noted 5,629 personal data breaches in 2024, a 20% rise year over year, with the number of incidents affecting more than a million people doubling in twelve months.
The report described, scene by scene, the five‑act modus operandi that would replay itself at the DGFiP: obtaining legitimate login data, gaining access to the information system, massive data exploration due to overly broad authorizations, large‑scale extraction because of insufficient detection indicators, then sale of the data without the organization realizing it.
The institution recommended, in black and white, multi‑factor authentication, staff awareness, a policy of restricted authorizations, and real‑time analysis of login logs…In short, almost word for word, the measures that Bercy announces today in a state of emergency.
The question that arises is the delay between the diagnosis and the implementation.
Solidaires Finances Publiques: “communicating isn’t securing”
In a press release published the same day as the crisis cell, the Solidaires Finances Publiques union denounces announcements deemed far below the stakes. The union questions the fate of the first €200 million envelope, already promised in April after the ANTS data breach.
One sum whose use remains, to date, largely unclear.
On substance, the union ties the fiscal administration’s vulnerability to budget choices made for years. The ongoing shrinkage of human and technical resources would have directly weakened the DGFiP’s defensive capacities.
As for the intrusion tests recommended to identify internal vulnerabilities, the union considers the announcement all the more surprising given that they should already be standard in a tax administration’s information system and have long been recommended by the ANSSI.
The plan presented by Bercy faces a double skepticism. If technically, as seen, the measures check the right boxes, their credibility will depend on rapid deployment and on the traceability of budgets promised since the ANTS affair.
Massive data theft: eight years of intrusions in state services
| Date | Target | Operational Method | Extent / Data Exfiltration | Official / Institutional Source |
|---|---|---|---|---|
| Dec. 2018 | Ariane Service Ministry of Europe and Foreign Affairs |
Operational method never disclosed | 540,563 people : identity, phone numbers, emergency contacts | Official press release from the Ministry of Europe and Foreign Affairs (Dec 15, 2018) |
| June 2021 | Pôle emploi | File created by an employee on their workstation | 58,124 job seekers | Pôle emploi press release / CNIL notification |
| 2023 | National Service (SNU) Ministry of the Armed Forces |
Origin never disclosed by the administration | 150,000 people : 62,500 youths and 87,500 mentors | CNIL report / Ministry of the Armed Forces |
| Aug. 2023 | Pôle emploi | Compromised contractor, MOVEit flaw | 10 million people | Pôle emploi press release (Aug 23, 2023) & CNIL |
| Feb. 2024 | Viamedis & Almerys (third-party payers’ operators) |
Usurpation of healthcare workers’ credentials / partner account | 33 million people : civil status, social security numbers, health coverage(Private contractors, outside the core administration) | CNIL 2024 report / Official statements from Viamedis & Almerys |
| Feb. 2024 | Caisse d’allocations familiales (CAF) | Reuse of passwords, without a technical flaw | 600,000 accounts claimed | National CNAF press release (Feb 2024) |
| Mar. 2024 | France Travail | Counselor accounts for Cap Emploi hijacked | 43 million people : identity, social security number | France Travail press release & Paris Prosecutor’s Office investigation (JUNALCO) |
| Dec. 2025 | Ministry of the Interior | Professional mailboxes compromised | Police files accessed, including the wanted persons file | Ministry of the Interior press release / CNIL report |
| Dec. 2025 | Ministry of Sports | Not publicly detailed | Not disclosed | CNIL notification |
| Jan. 2026 | HubEE Interministerial Directorate for Digital |
Breach on the inter‑administration exchange platform | 70,000 files and 160,000 documents | DINUM press release / Cybermalveillance.gouv.fr |
| Jan. 2026 | Urssaf | Partner account with valid credentials | 12 million employees | Unpssraf communiqué / National Urssaf |
| Jan. 2026 | OFII | Compromised partner operator | 2 million records | CNIL notice / OFII press release |
| Jan. 2026 | Ficoba DGFiP – Ministry of Finance |
Credentials of an authorized official | 1.2 million bank accounts | DGFiP press release / Ministry of the Economy |
| Mar. 2026 | Compas National Education |
Not publicly detailed | 243,000 teachers | Ministry of National Education press release |
| Mar. 2026 | CNOUS | Not publicly detailed | 774,000 students, 2 million claimed | CNOUS / CNIL notice |
| Apr. 2026 | ANTS | IDOR flaw, a modifiable identifier in the URL | 11 to 18 million accounts | ANTS press release / Ministry of the Interior |
| Apr. 2026 | ÉduConnect | IDOR flaw | 3.5 million students | Ministry of National Education press release |
| Jun. 2026 | Tchap State messaging |
Hijacked account linked to the Ministry of Education | 73,467 agents claimed | DINUM / ANSSI |
| Jun. 2026 | INSEE | Not publicly detailed | 12,800 current and former agents | INSEE management’s statement |
| Jun. 2026 | DGFiP | VPN access by agents, per the hacker | 678,438 lines claimed, 678,000 entries confirmed | DGFiP press release / Ministry of Budget |
| Jul. 2026 | Cadastre DGFiP |
Multifactor authentication bypassed | 252,149 lines, 2 million people according to the hacker | DGFiP press release / CNIL notice |
| Jul. 2026 | National Education Training system |
Compromise of a professional account | All agents since 2001, volume not disclosed | Ministry of National Education press release |
| Jul. 2026 | Ministry of Culture | Not publicly detailed | 45,362 agents claimed | CNIL notice / Ministry of Culture press release |