Select a theme from the list.
Insights

From our experts

Latest
Ransomware Disrupts Business Systems at Major Japanese Railway GroupStolen Passwords Left French Tax Data Exposed for Seven WeeksCheap AI Decisions Could Create an Expensive Security ProblemApple Closes CoreGraphics Flaw Linked to Sophisticated Targeted AttacksThousands of Supabase Databases Leak the Secrets Behind Rapid App DevelopmentNeedyMantis Gives Targeted Intruders a Modular Foothold Inside Windows NetworksSharePoint Code-Execution Flaw Moves From Patch Notes to Active AttacksLunex Leaves Security Tools Running but Blind Before Raiding BrowsersCloudflare Container Flaw Broke the Wall Between Customer WorkloadsStorm-3168 Turns Stolen Azure Identities Into a Seven-Minute WipeoutOne Encoded Character Lets Attackers Slip Past WAFs and Hit PeopleSoftClop Ransomware Gang Gets Hacked Through Its Own Outdated CMSRansomware Disrupts Business Systems at Major Japanese Railway GroupStolen Passwords Left French Tax Data Exposed for Seven WeeksCheap AI Decisions Could Create an Expensive Security ProblemApple Closes CoreGraphics Flaw Linked to Sophisticated Targeted AttacksThousands of Supabase Databases Leak the Secrets Behind Rapid App DevelopmentNeedyMantis Gives Targeted Intruders a Modular Foothold Inside Windows NetworksSharePoint Code-Execution Flaw Moves From Patch Notes to Active AttacksLunex Leaves Security Tools Running but Blind Before Raiding BrowsersCloudflare Container Flaw Broke the Wall Between Customer WorkloadsStorm-3168 Turns Stolen Azure Identities Into a Seven-Minute WipeoutOne Encoded Character Lets Attackers Slip Past WAFs and Hit PeopleSoftClop Ransomware Gang Gets Hacked Through Its Own Outdated CMS
Security Insight

Stolen Passwords Left French Tax Data Exposed for Seven Weeks

Stolen Passwords Left French Tax Data Exposed for Seven Weeks
Photo by Ann H on Pexels

An attacker used stolen employee passwords to access information associated with hundreds of thousands of French taxpayers and businesses. Investigators found that weak authentication, insufficient network separation and monitoring gaps allowed the activity to remain undetected for approximately seven weeks.

News Date: 2026-09-29

A breach involving France's tax administration demonstrates how ordinary credential theft can become a major government data incident when identity and network controls are weak. According to the findings reported by The Hacker News, an attacker accessed data associated with more than 350,000 individuals and over 250,000 businesses.

The exposed individual information may include tax identifiers, contact details, family circumstances, taxable income references, withholding rates and records describing communications with the tax authority. Taxpayer account passwords were reportedly not compromised, but the available information remains valuable for impersonation, targeted fraud and convincing social engineering.

No Advanced Exploit Was Required

The attacker reportedly relied on several dozen employee passwords collected over a period of months, potentially through information-stealing malware operating on unmanaged personal computers. Two of the portals used in the intrusion required only a password, allowing the stolen credentials to provide immediate access.

The incident became more serious because connected government systems were not adequately separated. The attacker reached tax applications through infrastructure associated with another ministry and attempted to move toward additional public-sector organizations.

Investigators also found that accounts without exceptional privileges could reach substantial amounts of information. This illustrates an important principle: a standard account can still create enterprise-level risk when applications expose broad datasets by default.

Detection Failed at Multiple Layers

The data theft was not recognized while it was happening. Authorities learned of the incident after the attacker publicly claimed responsibility, approximately seven weeks after the first known extraction.

Organizations managing sensitive records should respond to this pattern with layered controls:

  • Require phishing-resistant multifactor authentication for every remote portal.
  • Block sensitive access from unmanaged or noncompliant devices.
  • Segment government, partner and administrative networks according to operational need.
  • Limit each account to the smallest practical dataset.
  • Monitor unusual downloads, new access locations and cross-agency movement.

A Warning Against Calling Basic Attacks Sophisticated

In my view, describing a breach as sophisticated can sometimes conceal familiar control failures. This attacker did not need an exotic zero-day if valid passwords, permissive access and limited monitoring were enough.

The lasting lesson is that identity security cannot stop at verifying a password. Organizations must continuously evaluate the device, location, requested resource and volume of data involved in every authenticated session.

Talk to our team →

Latest

Ransomware Disrupts Business Systems at Major Japanese Railway GroupSep 30, 2026Stolen Passwords Left French Tax Data Exposed for Seven WeeksSep 30, 2026Cheap AI Decisions Could Create an Expensive Security ProblemSep 30, 2026Apple Closes CoreGraphics Flaw Linked to Sophisticated Targeted AttacksSep 29, 2026Thousands of Supabase Databases Leak the Secrets Behind Rapid App DevelopmentSep 29, 2026NeedyMantis Gives Targeted Intruders a Modular Foothold Inside Windows NetworksSep 29, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Global CMS Exploitation Wave Plants Webshells on Business Websites5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path