The Seven-Week Heist: How Stolen Passwords Opened France’s Tax Data Vault

The thieves did not arrive wearing masks.
There was no explosion at the vault. No broken window. No sophisticated lockpick.
They arrived carrying employees’ keys.
And once inside, they discovered something even more valuable: the guards were watching individual doors, but nobody was watching the entire bank.
For seven weeks, data left France’s tax administration without the DGFIP or France’s national cybersecurity agency, ANSSI, identifying the theft.
The attack only became known after the attacker claimed responsibility publicly.
Phase 1 — Steal the Bank Employees’ Keys
The first tool in the robbery was surprisingly simple: stolen passwords.
Several dozen DGFIP employee credentials had been compromised over approximately three months, probably through infostealers running on unmanaged computers, most likely personal devices.
Two portals used by the attacker, PIGP and ADER, required only a password.
No second key.
No guard asking for another form of identification.
With a stolen credential, the door opened.
🔑🏦🚪
Phase 2 — One Door Opens Into Another Room
Getting through reception should not automatically provide a path toward the vault.
But segmentation weaknesses made movement possible.
The attacker reached France’s interministerial RIE network through compromised systems belonging to the Education ministry. Sensitive DGFIP applications were insufficiently separated from other parts of that network.
Even accounts without special privileges could reach substantial amounts of information.
The thieves had entered through one corridor and discovered that too many doors inside the building were connected.
Phase 3 — Start Emptying the Vault
Then the robbery became industrial.
The attacker used automated scraping tools against E-Contact, extracting information page by page.
More than 350,000 individuals and 250,000 businesses were affected.
Potentially exposed individual information included tax IDs, contact information, family situation, reference taxable income, withholding rates and message lists. Some message contents were also potentially accessed.
A separate attack route through the APEX portal affected land-registry information concerning nearly 435,000 households.
The thieves were no longer looking for the vault.
They were already carrying its contents outside.
📂📤🏃
Phase 4 — The Guards See Something
And this is where the story becomes more striking.
The guards were not completely blind.
The DGFIP SOC detected suspicious activity several times.
On June 7, activity from a stolen account triggered an alert and its password was reset.
On June 23, another compromised account was flagged. A SOC ticket followed.
At 4:26 a.m. the next morning, the attacker began extracting E-Contact data through ADER.
At 10:40 a.m., defenders reset the password.
The lock had been changed.
But nobody removed the thief already standing inside the vault.
Phase 5 — Changing the Lock Does Not Remove the Thief
The attacker’s existing ADER session remained active.
And the extraction continued.
For almost 16 additional hours.
This distinction is critical: resetting compromised credentials without terminating existing sessions may stop somebody from opening the door again while doing nothing about the person who has already crossed it.
The same pattern returned in July.
Suspicious searches were detected.
Another password was reset.
But the broader theft remained unidentified.
🔐🚪🥷
Phase 6 — 11 GB Walks Through the Lobby
There were more clues.
Night-time logins.
VPN connections.
Connections from India.
Known malicious IP addresses.
Unusually large numbers of requests.
Automated page-by-page scraping.
And approximately 11 GB of data exchanged between June 22 and 25.
Yet these signals were not correlated into a single picture.
ADER was not being monitored by the DGFIP SOC, while ANSSI’s sensors operated at the boundaries of the RIE and internet and lacked access to application logs.
Because the attackers were using legitimate employee accounts, individual actions could appear less suspicious when viewed separately.
One person walking out of a bank carrying a bag may mean nothing.
Hundreds of trips to the vault, at unusual hours, through unusual entrances, carrying increasingly heavy bags?
That is a different story.
The problem was that nobody connected the cameras.
🚨📹🏦
Phase 7 — The Thieves Announce the Robbery
The first extraction occurred weeks earlier.
But the theft became known on August 12, when the attacker claimed it publicly.
Only then did the full scale of the incident emerge.
ANSSI’s assessment was notable: the attack was not technically sophisticated.
Its effectiveness came from weak authentication, insufficient segmentation and monitoring gaps.
The thieves did not build a better drill.
The bank gave them working keys and failed to recognize what they were doing with them.
Phase 8 — Rebuild the Bank Around the Assumption That Keys Get Stolen
ANSSI’s recommendations address precisely those weaknesses.
Strong MFA should protect every application.
When a compromised password is reset, all existing sessions across applications and portals should also be revoked.
Security teams should investigate what the account did from the probable moment of compromise rather than treating the password reset as the end of the incident.
Business applications should feed logs into a SIEM, while organizations should monitor and correlate unusual numbers of requests, records accessed and volumes of data transferred.
Personal devices should not be allowed to access work resources.
And network architecture should prevent one compromised area from becoming a corridor toward sensitive systems.
🛡️🔐📊
The Perfect Bank Robbery Did Not Need to Be Perfect
This incident demonstrates why security cannot depend exclusively on keeping attackers outside.
Passwords will be stolen.
Accounts will be compromised.
Individual alerts will sometimes look harmless.
The decisive question is what happens next.
Can one stolen identity travel too far?
Can an authenticated session remain alive after compromise is detected?
Can hundreds of thousands of records leave without triggering a meaningful response?
Can separate warning signs be connected into one attack story?
Because this time, the thieves did not need to defeat the security system.
They entered with the employees’ keys, walked through interconnected corridors and carried the vault outside piece by piece.
For seven weeks, the bank was being robbed.
The alarms simply never understood what they were seeing.
The Hacker News




Comentarios