π French Tax Authority Breached Again as Same Ransomware Crew Reuses Old Exploit
678,438 taxpayer records stolen from DGFiP viaβ¦ reused credentials and an MFA they bypassed with an APK device. Two months to notice. π Same crew walked in twice β 2024 and 2026. Same gaping door. ZeroBytes now filtering taxpayers earning β¬100k+ in a country where 30 crypto-targeted violent thefts already happened this year. France spent two years building surveillance for citizens and zero on surveillance for who's inside its network. What's your org's "we'll notice in 60 days" gap? πΈ
You know that sinking feeling when you open your mailbox and find a letter from the tax authorities? Now imagine the tax authorities opening your digital mailbox, and some Moldovan ransomware crew laughing their asses off while scrolling through your income declarations.
That's France in 2026. π«π·π
ZeroBytes Didn't Zero In β They Just Walked In
June 12, 2026: ZeroBytes extracted 678,438 taxpayer records from the DGFiP system. Method? They exploited an internal VPN tool and bypassed multi-factor authentication using APK devices that authorized VPN entry. That's not a zero-day. That's a zero-effort.
July 29, 2026: Same actor claimed intrusion into the cadastre service. Confirmed by August 13, 2026: 252,149 records covering over 2 million people β names, addresses, MAJIC identifiers, property right links, fiscal identifiers. MFA bypass again. Valid credentials reused. No VPN required. Both attacks trace to the same IP block with reverse-engineered certificates.
The French government's detection? August 12, 2026 β through "anomalous log review." The breach started in June. They noticed in August.
Then on August 30: ZeroBytes took down the 'ZΓ©ro logement vacant' portal, claiming recovery of nearly 149 million raw records β housing vacancy data exposing which residences sit empty, who owns them, and where to find them.
The 2024 Prologue They Never Patched
This isn't new. June 30, 2024: ZeroBytes breached the same fiscal system via weak authentication and a compromised VPN route. July 20, 2024: They extracted the entire cadastre database. Land registry, property values, building permits. Hundreds of thousands of citizens exposed.
France had two years to fix the doors. They didn't. The same group walked back in.
What Actually Got Stolen
Let's be concrete:
- Privacy: Up to 2 million residents have personal tax records including names, tax reference income, family quotient, and deduction rates exposed β identity theft, tax-fraud phishing, and wrench-attack risk. Over 30 violent thefts targeting crypto holders occurred in France in early 2026, causing $30 million+ in losses β confirmed by Chainalysis on August 6. The stolen Waltio dataset (50,000 accounts leaked January 2026) had already fueled a kidnapping spree. Now ZeroBytes filters taxpayers earning >β¬100k/year, turning financial surveillance into a street-level hunting list.
- Financial: Data immediately listed on dark-web forums. Commercial value: hundreds of euros per batch. Real cost: fraudulent property transfers, identity-theft loans, blackmail against high-net-worth individuals.
- Trust: The French public's confidence in digital government services is now lower than Bercy's patch cadence.
The Institutional Response: A Comedy of Errors
Bercy launched an investigation. Bruno Retailleau indicted in Paris on June 15 for establishing a cryptocurrency kidnapping network. DGFiP suspended related accounts after detection.
Translation: the accounts were suspended two months late. The theft was missed during initial detection. "Additional security measures" are now active β which in government-speak means they enabled the alert they should have had before 678,000 records left the building. Prime Minister convened a crisis meeting. Arrest warrants issued, requiring proof of encrypted-wallet possession. Good luck enforcing that.
The Realpolitik Playbook
Here's what actually needs to happen, and it won't:
- Mandatory FIDO2/WebAuthn for every single DGFiP employee and contractor. No exceptions. MFA bypassed via APK devices isn't MFA β it's theater.
- Open-source audit of the authentication pipeline. Public code, public shame, public fixes.
- Real-time monitoring that doesn't rely on someone noticing "hey, that login from Moldova seems weird" two months later.
Outlook: More Pain Ahead
- Short-term (Q4 2026): More breaches. ZeroBytes operates on a cadence β each raid builds confidence, enabling later attacks without detection. The 'ZΓ©ro logement vacant' dataset adds 149 million property-level records to the arsenal. Expect a spike in targeted phishing and physical extortion.
- Mid-term (2027): Regulatory fines under GDPR β up to β¬20 million or 4% of global revenue β will hit. Taxpayers foot the bill. Criminal prosecution under Article 323-1 of the French Penal Code carries up to seven years imprisonment for data theft. The CNIL's Marie-Laure Denis will have plenty of paperwork.
- Long-term (2028+): Either France implements actual zero-trust architecture, or citizens demand paper-only filing. Both outcomes are expensive. Only one prevents the next breach.
The Ironic Hook That Writes Itself
The French fiscal system β designed to track every euro you earn, every property you own, every transaction you make β couldn't track who was inside its own network for two months straight.
They built a surveillance state for citizens but left the back door unlocked for anyone with a valid credential and a laughably-bypassable MFA. ZeroBytes even used AI-assisted Python scripts embedded inside PHP pages to dump CSV fields. The duo β two people β systematically dismantled the DGFiP, SPDC, and housing-vacancy platforms while the government held crisis meetings.
Safe to say, the only thing getting audited here is the government's competence.
And it's failing. Spectacularly. π
Comments ()