DGFiP Cyberattack: The Response Plan That Struggles to Convince

Following the sequence of apologies from Public Accounts Minister David Amiel to the 678,000 individuals and professionals whose tax data were stolen, a government response was needed to address this “technical debt” with “human and financial resources”.

After an interministerial crisis cell convened by the Prime Minister on August 17, a series of measures intended to plug the breaches in Bercy’s information system were announced in the wake of the event.

First totem of the government’s response: the generalization of two‑factor authentication for all agents of the DGFiP, promised by the end of the year. But Bercy itself acknowledges: several accounts already protected by this mechanism could have been compromised during the latest incidents. The two factors, indispensable as it may be, do not do everything: you still must monitor what happens after logging in.

That is the second axis of the plan: strengthen detection mechanisms to improve the identification of account takeovers and suspicious behaviors. Moreover, access quotas, already applied to certain files such as FICOBA, should be rolled out more broadly. As if under a “zero trust” banner…

Authenticate, educate, detect

The third pillar, more human: intensification of bug bounty campaigns and strengthening training. Also mentioned is a renewed reliance on AI to simulate attacks and detect vulnerabilities before they can be exploited.

Read also: How Lazarus hijacks job offers to infiltrate the defense industry

A minimum service in cyberspace, one might say…

All the more so given that the surge in massive breaches affecting state services’ databases is well documented.

In a report published in January 2025, the CNIL noted 5,629 personal data breaches in 2024, a 20% rise year over year, with the number of incidents affecting more than a million people doubling in twelve months.
The report described, scene by scene, the five‑act modus operandi that would replay itself at the DGFiP: obtaining legitimate login data, gaining access to the information system, massive data exploration due to overly broad authorizations, large‑scale extraction because of insufficient detection indicators, then sale of the data without the organization realizing it.

The institution recommended, in black and white, multi‑factor authentication, staff awareness, a policy of restricted authorizations, and real‑time analysis of login logs…In short, almost word for word, the measures that Bercy announces today in a state of emergency.

The question that arises is the delay between the diagnosis and the implementation.

Solidaires Finances Publiques: “communicating isn’t securing”

In a press release published the same day as the crisis cell, the Solidaires Finances Publiques union denounces announcements deemed far below the stakes. The union questions the fate of the first €200 million envelope, already promised in April after the ANTS data breach.

One sum whose use remains, to date, largely unclear.

Read also: Palo Alto Networks launches its Frontier AI Critical Defense program

On substance, the union ties the fiscal administration’s vulnerability to budget choices made for years. The ongoing shrinkage of human and technical resources would have directly weakened the DGFiP’s defensive capacities.

As for the intrusion tests recommended to identify internal vulnerabilities, the union considers the announcement all the more surprising given that they should already be standard in a tax administration’s information system and have long been recommended by the ANSSI.

The plan presented by Bercy faces a double skepticism. If technically, as seen, the measures check the right boxes, their credibility will depend on rapid deployment and on the traceability of budgets promised since the ANTS affair.

Massive data theft: eight years of intrusions in state services

Date Target Operational Method Extent / Data Exfiltration Official / Institutional Source
Dec. 2018 Ariane Service
Ministry of Europe and Foreign Affairs
Operational method never disclosed 540,563 people : identity, phone numbers, emergency contacts Official press release from the Ministry of Europe and Foreign Affairs (Dec 15, 2018)
June 2021 Pôle emploi File created by an employee on their workstation 58,124 job seekers Pôle emploi press release / CNIL notification
2023 National Service (SNU)
Ministry of the Armed Forces
Origin never disclosed by the administration 150,000 people : 62,500 youths and 87,500 mentors CNIL report / Ministry of the Armed Forces
Aug. 2023 Pôle emploi Compromised contractor, MOVEit flaw 10 million people Pôle emploi press release (Aug 23, 2023) & CNIL
Feb. 2024 Viamedis & Almerys
(third-party payers’ operators)
Usurpation of healthcare workers’ credentials / partner account 33 million people : civil status, social security numbers, health coverage(Private contractors, outside the core administration) CNIL 2024 report / Official statements from Viamedis & Almerys
Feb. 2024 Caisse d’allocations familiales (CAF) Reuse of passwords, without a technical flaw 600,000 accounts claimed National CNAF press release (Feb 2024)
Mar. 2024 France Travail Counselor accounts for Cap Emploi hijacked 43 million people : identity, social security number France Travail press release & Paris Prosecutor’s Office investigation (JUNALCO)
Dec. 2025 Ministry of the Interior Professional mailboxes compromised Police files accessed, including the wanted persons file Ministry of the Interior press release / CNIL report
Dec. 2025 Ministry of Sports Not publicly detailed Not disclosed CNIL notification
Jan. 2026 HubEE
Interministerial Directorate for Digital
Breach on the inter‑administration exchange platform 70,000 files and 160,000 documents DINUM press release / Cybermalveillance.gouv.fr
Jan. 2026 Urssaf Partner account with valid credentials 12 million employees Unpssraf communiqué / National Urssaf
Jan. 2026 OFII Compromised partner operator 2 million records CNIL notice / OFII press release
Jan. 2026 Ficoba
DGFiP – Ministry of Finance
Credentials of an authorized official 1.2 million bank accounts DGFiP press release / Ministry of the Economy
Mar. 2026 Compas
National Education
Not publicly detailed 243,000 teachers Ministry of National Education press release
Mar. 2026 CNOUS Not publicly detailed 774,000 students, 2 million claimed CNOUS / CNIL notice
Apr. 2026 ANTS IDOR flaw, a modifiable identifier in the URL 11 to 18 million accounts ANTS press release / Ministry of the Interior
Apr. 2026 ÉduConnect IDOR flaw 3.5 million students Ministry of National Education press release
Jun. 2026 Tchap
State messaging
Hijacked account linked to the Ministry of Education 73,467 agents claimed DINUM / ANSSI
Jun. 2026 INSEE Not publicly detailed 12,800 current and former agents INSEE management’s statement
Jun. 2026 DGFiP VPN access by agents, per the hacker 678,438 lines claimed, 678,000 entries confirmed DGFiP press release / Ministry of Budget
Jul. 2026 Cadastre
DGFiP
Multifactor authentication bypassed 252,149 lines, 2 million people according to the hacker DGFiP press release / CNIL notice
Jul. 2026 National Education
Training system
Compromise of a professional account All agents since 2001, volume not disclosed Ministry of National Education press release
Jul. 2026 Ministry of Culture Not publicly detailed 45,362 agents claimed CNIL notice / Ministry of Culture press release
Dawn Liphardt

Dawn Liphardt

I'm Dawn Liphardt, the founder and lead writer of this publication. With a background in philosophy and a deep interest in the social impact of technology, I started this platform to explore how innovation shapes — and sometimes disrupts — the world we live in. My work focuses on critical, human-centered storytelling at the frontier of artificial intelligence and emerging tech.