GoFirm
Back to Blog
Case Studies·4 min read

How did stolen credentials and a bypassed MFA prompt reach 678,000 French taxpayers?

By GoFirm

The Direction Générale des Finances Publiques (DGFiP), France's tax authority within the Ministry of the Economy and Finance, disclosed on 17 August 2026 that an attacker had spent time inside its systems using stolen login credentials and, the attacker claims, a technique for bypassing multi-factor authentication. The intrusion only came to light after a threat actor using the alias ZeroBytes posted on the cybercrime forum PwnForums on 12 August, offering a stolen database for sale. DGFiP had suspended the compromised access points once its own monitoring flagged unusual activity, but at the time its access controls found no evidence that data had actually left the system. It took an in-depth investigation, launched only once ZeroBytes' forum post forced the issue, to establish what had really happened.

ZeroBytes claims to have reached the Serveur Professionnel de Données Cadastrales (SPDC), an online portal DGFiP operates for professional access to France's central land registry and property ownership records. The portal, according to the attacker, held data on roughly 20 million French citizens. ZeroBytes says the extraction stopped short of the full database simply because scraping it in full would have taken months, nothing DGFiP did brought it to a halt. What was taken, by the attacker's own account, was 252,149 records covering more than two million people.

DGFiP's own investigation, running since 12 August, has put a narrower and more concrete figure on the confirmed damage: 678,000 individuals and professionals, whose reference tax income, family quotient, withholding tax rate, cadastral addresses and property sizes were consulted and extracted. For registered businesses, the stolen data included company names and SIREN numbers. The online tax portals used by ordinary taxpayers and companies were not touched, and DGFiP says usernames and passwords on those consumer-facing systems remain uncompromised. The theft ran instead through professional access points, the credentials of people who were trusted with bulk lookup and export capability that an individual taxpayer never has.

This is the fourth disclosed breach of a French government data system in eight months. France Travail, the national employment agency, was fined five million euros in January after hackers took the personal data of 43 million people. In February, the FICOBA bank account registry, also run out of the Ministry of Finance, disclosed a breach affecting 1.2 million accounts. In April, France Titres, the agency behind the country's national identity document register, confirmed a breach after a hacker offered 19 million records for sale. Four incidents, four different systems, the same ministry, and the same pattern each time: a login that should not have been enough on its own was enough.

The defences that failed at DGFiP were not absent. Multi-factor authentication was in place. Access monitoring was in place, and it worked well enough to flag the anomaly and suspend the compromised accounts. What was missing was any control that treated a bulk data export from a national land and tax registry as a distinct, high-stakes event requiring its own separate confirmation, rather than as just another authenticated session. A login plus a passed MFA challenge, however that challenge was passed, was treated as proof enough that the person on the other end was who the credentials said they were.

A bulk export from the SPDC, or any system holding tax and cadastral records on millions of people, is an execution event. Under GoFirm, before a professional account can pull records at that scale, a confirmation request goes out over a separate channel to the named accountholder's registered device, asking for a real biometric confirmation, not a password re-entry, not a one-time code, not an approval tap that any session token can trigger. If the confirmation does not arrive from that specific device, the export is blocked, regardless of how valid the login credentials appear or how the MFA prompt was satisfied.

This is precisely the boundary that a credential theft and MFA bypass cannot cross. ZeroBytes did not need to deceive a person; the account's authentication was ultimately a set of checks that stolen credentials and a bypass technique could satisfy without alerting anyone. A credential thief who has bypassed MFA, however convincingly, still cannot produce a biometric confirmation on the real accountholder's own registered device. The execution boundary holds regardless of how the login was obtained.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.


References
1. Gatlan, S. 2026. French tax authority data breach affects 678,000 individuals. BleepingComputer, 17 August 2026.
2. Markovic, S. 2026. France's tax authority admits hackers made off with data on 678,000 individuals. Help Net Security, 17 August 2026.
3. Ministère de l'Économie, des Finances et de la Souveraineté industrielle et numérique. 2026. Accès illégitime au système d'information de la Direction générale des finances publiques. Press release, 14 August 2026.

Share this article