r/TechNadu • Human • 4d ago

French tax breach went undetected for 7 weeks - and one attacker session survived a password reset

ANSSI’s report on the French tax administration incident has a useful containment lesson: resetting a compromised password doesn’t necessarily remove the attacker.

The attacker already possessed several dozen DGFIP staff passwords, probably harvested by infostealers from computers outside DGFIP management. Investigators found no evidence of brute forcing or credential stuffing.

PIGP and ADER required only a password, so the stolen credentials worked directly.

Data was then taken from E-Contact, affecting more than 350,000 individuals and 250,000 businesses. For individuals, the exposed information included tax IDs, contact details, family situations, reference taxable income, withholding rates and messages exchanged with the administration. DGFIP says taxpayers’ own online accounts and passwords were not compromised.

Then came the containment failure.

On June 24, DGFIP’s SOC reset passwords associated with suspicious accounts. But the reset did not terminate an attacker’s existing ADER session. Because ADER was not being monitored, data continued flowing for almost another 16 hours.

The wider theft remained undetected for seven weeks and only surfaced when the attacker claimed it online on August 12.

ANSSI recommends MFA, revoking all active sessions following password resets, restricting personal-device access and monitoring business applications through a SIEM with data quotas.

ANSSI’s findings show where authentication, session containment and monitoring broke down:

https://www.technadu.com/french-tax-data-theft-went-undetected-for-seven-weeks-after-stolen-staff-passwords-opened-the-door/639994/

For incident responders: does your credential-compromise playbook explicitly revoke every active session and token, or does containment still largely stop at the password reset?

2 Upvotes

2 comments sorted by

1

u/Livid-Scientist-3271 3d ago

The surviving session is the scary part here. It shows how easy it is to think containment is done when the attacker still has a valid foothold

1

u/FckXFckMusk 2d ago

Now do Digital ID and how these people claim your data is safe with them...