Tech News

DGFiP Summer 2026 Cyberattack: What the ANSSI Report Reveals

ANSSI has published its post-mortem analysis following the security incident that affected the DGFiP this summer. This information-rich document retraces the events in detail, with a clear timeline and, above all, additional insight into the attacker's modus operandi, ZeroBytes.

This 20-page report, written by ANSSI teams and delivered to the Prime Minister, details the cyberattacks suffered by the DGFiP between May and August 2026. As a reminder, ZeroBytes claimed responsibility on August 12, 2026 for a data theft linked to impots.gouv.fr, then the following day for cadastral data. According to the details published by the attacker on August 13 and cited by ANSSI, the first batch, extracted from the E-Contact application, concerns nearly 353,000 private individuals and 252,000 professionals.

First of all, the ANSSI report differs from the information communicated by Bercy. Indeed, in its press release dated August 14, 2026, Bercy's press office stated the following: "The access controls carried out on this occasion did not make it possible to detect that these intrusions had led to data theft, due to the sophistication of the attack." - For its part, ANSSI sees things differently: "The compromise of the DGFiP information systems is not the result of a sophisticated attack.", the report says.

Stolen credentials and no strong authentication

Brace yourself before reading what follows. In three months, the attacker got hold of several dozen employee credentials, probably stolen by infostealer-type malware on devices not managed by the DGFiP. In other words, these were devices managed by a third party (a service provider), or even worse, personal devices on which the user is free to do whatever they want (web browsing, running programs, etc.).

The risk is high with these devices, but that risk was not mitigated. In fact, no multi-factor authentication (MFA) protected the PIGP portal (agent accounts) or ADER, which provides access to certain DGFiP applications from the Interministerial Network of the State (RIE). The attacker connected to PIGP from the Internet, then to ADER from the RIE, via compromised infrastructure belonging to the Ministry of Education.

The same logic applied to cadastral data: according to the report, the compromised workstation of a chartered surveyor (within a private firm) made it possible to bypass the second factor on the APEX portal (a code sent by email) and exfiltrate data from July 27 to August 8.

DGFiP monitors credential resale

DGFiP was not starting from scratch when it came to credential theft, as it appears to have monitoring tools in place (Dark Web, Telegram channels, etc.). "For several years, the DGFiP has enhanced its monitoring system for compromise and resale of its users' access credentials using external intelligence sources," the report says. In plain terms, this means monitoring the platforms where stolen credentials are traded. According to the information in the report, DGFiP relies on several sources, including the Recorded Future solution and Orange Cyberdefense services.

The point of this monitoring is to be proactive as soon as a credential is stolen. Indeed, when a compromise is detected or reported, DGFiP's SOC resets the account password, looks for any concurrent activity, and raises awareness among the agent about the risks involved.

This safety net worked several times during the cyberattack, on accounts the attacker did indeed have in hand. At the end of May, one of the three accounts used to try to connect to PIGP was reported by the provider and reset on the same day as the notification. Later attempts with that account failed. On June 15, it happened again: a partner reported 2 compromised accounts to ANSSI. DGFiP did not respond, and ANSSI did not follow up. However, these accounts had already been identified by Recorded Future and reset.

The attacker would try again to use one of them in July, without success. On July 1, the provider alerted DGFiP to the sale of 2 accounts, whose passwords were reset. Failed PIGP logins with these accounts, on June 30 and July 1, from an IP address used for the June 24 exfiltration, would later be discovered. The monitoring tools had therefore indeed spotted accounts targeted by the attacker.

According to ANSSI, this safety net "has proved useful, but by itself does not sufficiently reduce the risk". The report also details its limitations. It is indeed difficult to comprehensively monitor all the channels used to resell and distribute these stolen credentials. "Monitoring carried out by DGFiP's provider probably cannot cover all resale platforms," ANSSI believes. It is therefore to be expected that some compromised accounts will not be reported to the SOC. This was the case for one of the three accounts compromised in mid-May: its compromise was not notified.

A delay that gives attackers free rein

Between the compromise of an account and the reset of its password, the report describes a period that is "difficult to compress". "This time window is sufficient for an attacker to access a business application and begin exfiltration," ANSSI continues. Even so, this delay can still be reduced as much as possible. The event timeline illustrates this several times:

  • May 16 -> June 12 : an account compromised on May 16 is only identified as such on June 3. Its password is not changed until June 12, i.e. 9 days later.
  • June 23 : Recorded Future identifies the account that will be used for the first exfiltration as compromised, on the same day the attacker uses it on ADER.
  • July 18 : two new accounts are compromised. The attacker checks their validity on PIGP as early as July 21, then exfiltrates data on July 22 with one of them. That account is not reset until July 24. ZeroBytes was still one step ahead.

A reset that does not cut the session

Let's go back to that account identified as compromised by Recorded Future on June 23, 2026. That day, the attacker uses it to connect to PIGP from the Internet, then to ADER from the RIE, where he begins developing his scraping tools for E-Contact. At the same time, his suspicious searches on PIGP automatically open a ticket with DGFiP's SOC at 8:50 p.m. The next day, starting at 4:26 a.m., he uses the same account to launch the automated extraction of E-Contact data. At 10:40 a.m., the SOC handles the ticket by resetting the password. "The reset does not interrupt the session or the ongoing exfiltration, which continues", ANSSI notes. The extraction continues until June 25 at 2:31 a.m. Nearly 16 more hours.

ANSSI specifically recommends pairing every password reset with the revocation of active sessions across all accessible applications and portals. Still, you first have to know that the account has an open session on ADER, a portal the SOC was not supervising. Here, that is what allowed the attacker to continue exfiltrating data.

The search for concurrent activity also misses the mark. The password was reset and access to PIGP checked, but the exfiltration carried out via the RIE was not identified, the report says. On June 29, a partner reported the same account to ANSSI. DGFiP replied that it was already aware of it and that it had been reset. However, the June 24 exfiltration was only established after the August 12 claim, even though suspicious connections had been identified from August 6. More broadly, the volume of compromised accounts makes systematic analysis of their activity "very time-consuming", and it "cannot be carried out exhaustively," ANSSI acknowledges.

Resetting the password is good; clearing active sessions is even better. But there is still one problem: the infected device was not cleaned. This is a real issue, as ANSSI explains: "Password resets following the compromise of these accounts can only be effective if the device on which the account was compromised is also cleaned." Easier said than done when it is a personal workstation or one belonging to a third-party organization. The event timeline also includes a case pointing in this direction: an account reset on June 7 is used again by the attacker on July 6 and 7, without the report specifying how he obtained the new password. My own hypothesis: the agent logged into the portal with the new credentials from the computer already infected by the infostealer.

A SOC blind to ADER

During the incident, DGFiP's SOC was not monitoring ADER, the portal used to exfiltrate E-Contact data. Yet there were several signals that could have generated very clear alerts, especially if correlated:

  • Volumes : 11 GB exchanged from June 22 to 25, then 3 GB from July 21 to 23, with no alert.
  • IP addresses : connections via VPNs, from India or from addresses known to be malicious, with no analysis.
  • Times : nighttime connections, not interpreted.
  • Reports : on June 9, the Ministry of Education asked ministerial CSIRTs to remain especially vigilant regarding connections originating from its RIE IPs. One of them was used by the attacker to reach ADER.

ANSSI, here both judge and party, does not spare itself. Its own supervision did not allow the attackers to be detected: it had no application-layer monitoring on this scope, and its probes, placed only at the RIE and Internet entry and exit points according to the report presentation page, did not flag anything at the time. It was not until August 6 that a retrospective search on these probes revealed suspicious traffic to two DGFiP portals. The Agency nevertheless believes that the cumulative volume of requests the attacker must have generated "should have triggered alerts".

What ANSSI recommends

DGFiP has since closed ADER (as of August 13) and PIGP (August 18) to its agents. Below are ANSSI's main recommendations following this incident, some of which relate purely to basic cybersecurity hygiene:

  • Devices : forbid connections from personal devices and harden workstations (monthly updates, EDR, always-on VPN).
  • Authentication : deploy MFA on all applications, with a second factor that resists compromise of the first (hardware token, authentication app).
  • Sessions : revoke active sessions across all applications and portals whenever a password is reset.
  • Monitoring : integrate applications into a SIEM, with quotas and blocking based on geolocation and IP reputation.
  • Privileges : limit each account to the information required for its role.
  • Exposure : make internal-use applications accessible only from workstations managed by DGFiP, reserve partner access for internal networks or a VPN, and more finely filter traffic between ministries within the RIE.

This report comes three weeks after the launch of REACTIV, which allows ANSSI to impose emergency measures on ministries. You can use this link to access the incident report published by ANSSI.

I'll leave you with this AI-generated infographic that clearly retraces the timeline of events.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.