DEV Community

Jules Robineau
Jules Robineau

Posted on Originally published at jrobineau.com

The French Tax Leak Started With a Password

On 18 August 2026, the French state apologized to its taxpayers. Unknown actors had been able to read the tax records of 678,000 people and businesses. The entry point: stolen credentials, from one agency employee and one authorized third party.

No zero-day. No sophisticated state attack. Passwords.

TL;DR: France Travail, the family-benefits agency, the national ID agency, then the tax administration. None of the big French public-sector breaches needed an advanced attack. The rules had existed since 2014, with no budget and no authority. And do not read this as a state problem. In France, 48% of recorded ransomware victims are micro and small companies. Their flaws are exactly the same. The pressure protecting big companies reaches neither the small ones nor the public sector. Money only arrives after the incident. The missing security is not complex. It is neither funded nor demanded.

This article is an outside post-mortem. I have never worked for these agencies. I secure private systems that face exactly the same attacks.

Two years of leaks, one per major agency

March 2024: France Travail, the national employment agency. The CNIL, France's data protection authority, established that data of 36.8 million people was exfiltrated. Names, social security numbers, contact details.

2024 then 2025: the CAF, the family-benefits agency. First 60,000 compromised accounts. Then a 22-million-row file, attributed to its ecosystem, circulated on forums.

April 2026: the ANTS, the agency behind national ID cards and vehicle registration. 11.7 million accounts confirmed by the Interior Ministry. Almost one French person in six.

June to August 2026: the DGFiP, the tax administration. Three intrusions, 678,000 individuals and businesses affected, tax and land-registry data. The same group claims an attack on the national education ministry.

And the summer of 2026 came in bursts. INSEE in June: 12,800 staff exposed through an internal directory. Bloctel in August: 3 million phone numbers, the day after the service shut down. In late August, a forum post claimed the hack of a public housing-vacancy platform. That one is not confirmed yet.

Add up these incidents alone: over 70 million records, without even deduplicating people. The question is no longer whether an agency leaks. It is which one, this week.

None of it is sophisticated

Look at the published causes, not the volumes.

The ANTS: an IDOR-type flaw, according to published analyses. That kind of flaw has been in the OWASP top 10 for years. It takes an hour to test on an endpoint.

The DGFiP: stolen credentials, with no generalized second factor. Multi-factor authentication, MFA, asks for a second proof besides the password. It is the number one defense against credential theft.

These are the first things I look for in a pentest. These are the first defenses I deploy on a mission. None of them is research. This is chapter 1 of any security guide.

The rules existed, the execution did not

France did not discover security in 2026. The PSSIE dates from 2014. The RGS framework requires a security accreditation for public online services.

So why the leaks? France's supreme audit court answered in 2025, before the tax incident. Its report describes interministerial steering without real authority, very limited means, and no effective evaluation.

ANSSI advises and alerts, but rarely compels other administrations. And the transposition of NIS 2 fell behind schedule.

A framework without budget or control produces paper accreditations. The document exists, the security does not.

Why big companies moved first

This is not about talent. Public teams have excellent engineers. It is about pressure.

A big company has regulators that fine and insurers that demand. Its customers send security questionnaires before signing. At my enterprise clients, MFA everywhere, pipeline scans and access monitoring do not happen out of virtue. They happen because a contract depends on them.

An administration loses no customers. The CNIL rarely fines the state itself. And a security budget is a cost with no ribbon to cut. A SIEM earns no inauguration.

But watch what comes next. That pressure does not trickle down. It stops well before small companies.

Your SMEs have the same flaws as the state

There is a trap in the story I just told. You could believe the private sector is protected and the state is behind. That is wrong. Only the pressured private sector is protected.

Look at the numbers from ANSSI. In its 2025 threat panorama, 48% of recorded ransomware victims are micro, small or mid-sized companies. It was 37% a year earlier.

Small companies are the first category of victims. Ahead of local governments. Ahead of hospitals.

ANSSI also measures the defense level. 74% of these companies sit below its "Essential" baseline. That level is not high security. It is the minimum the agency considers vital.

Cybermalveillance.gouv.fr, the public assistance desk for victims, completes the picture. In 2025, phishing jumped 70%. Assistance requests from companies climbed 73%.

One company in six suffered an incident during the year. Nearly a third of those incidents halt the activity. One in five ends in stolen data.

And one gap sums it all up. Nine SMEs out of ten believe they are equipped. One out of two says it is prepared for an attack.

In the field, I see the same thing. When I audit an SME, I find the DGFiP list again. Accounts without MFA. Third parties with too many rights. Exposed services. Nobody reading the logs. The flaws do not change with size. The pressure does.

The pressure stops at big companies

Take the three drivers from the previous chapter: regulators, insurers, customers. None of the three reaches a twenty-person company.

On the rules side, NIS 2 shows the hole. The directive moves France from about 500 regulated entities to 15,000. Real progress. But the entry ticket remains the medium company: 50 employees, or more than 10 million euros in revenue. Below that, you are out of scope.

France counts about 4 million micro and small companies. The 15,000 NIS 2 entities are less than one in two hundred of them.

And even that reduced scope is still waiting for its law. The European deadline was 17 October 2024. The French transposition bill, the Résilience law, was still not enacted by the summer of 2026. Two years late on obligations already voted in Brussels.

Insurance and customers follow the same logic. Security questionnaires come with big contracts. Compliance audits come with large accounts. An SME selling to other SMEs never meets anyone who demands MFA.

One mechanism is starting to trickle down: the supply chain. NIS 2 forces in-scope entities to secure their suppliers. If your customer is covered, they will come asking you for guarantees, sometimes an audit. It is the first pressure reaching small companies.

The result: the state and small companies share the same blind spot. Nobody forces them. And since security is invisible, nobody asks for it.

Money does not arrive before the incident either

Second half of the question: why does nobody put money in?

Aid exists. Look at its scale. France Relance put 136 million euros into cybersecurity in 2021. Its core program, the security pathways, supported 945 entities in four years. Local governments, hospitals, public bodies. 945, when France alone counts more than 34,000 municipalities.

For companies, MonAideCyber offers a free ninety-minute diagnosis. A good first step. Not an audit, let alone a hardening project. The Cyber PME program of France 2030 adds support, recent and still little known.

Now compare with the state's wake-up call: 200 million unlocked within weeks, after the leaks. So the money exists. It just always arrives after.

Why? Three reasons. None of them technical.

One: security is an invisible expense. It produces nothing you can show. A marketing budget brings customers. A security budget brings incidents that did not happen. Nobody celebrates an avoided incident.

Two: the cost of a leak does not fall on whoever decides the budget. When a company leaks, its customers pay first. Their data circulates, their accounts get attacked. Economists call this an externality: a cost you create and others pay. As long as leaking costs the company less than its victims, the math says do nothing.

Three: imposing rules on small companies carries a political cost. Every new obligation reads as one more administrative burden. So we regulate the big ones, subsidize diagnoses, and wait.

It is the same mechanism that left the PSSIE unfunded for twelve years. The state and the SMEs are not two stories. They are the same one.

2026, the wake-up call that finally sets the standard

The plan came in three waves. And it looks like what the serious private sector already does.

Mid-April 2026, an implementing decree of the SREN law turned a recommendation into an obligation. The state's most sensitive data must now sit on SecNumCloud-qualified clouds. SecNumCloud is ANSSI's qualification for trusted hosting providers. Around 360 requirements, up to immunity from extraterritorial laws like the CLOUD Act.

Late April 2026, after the ANTS: new governance and 200 million euros unlocked. Each ministry must reserve 5% of its digital budget for cybersecurity from 2027. Plus a doctrine: self-attack exercises, generalized MFA, hardened access.

Mid-August, after the tax leak: MFA for all tax-administration staff by the end of 2026. Consultation quotas on sensitive files. Stronger anomaly detection. A bug bounty on state platforms. And an audit supervised by ANSSI.

Measure the paradox. France already had the strictest hosting standard in Europe. But no generalized MFA for its own staff. The datacenter was armored, the account stayed open.

Translate it into engineering terms: security enters the process, with a budget and controls. That is the definition of DevSecOps. Not one more tool at the end, a requirement at every step.

It took 70 million rows to get there.

What this post-mortem gives your own system

You do not run the state's IT. The lessons transpose anyway.

And kill the "too small to matter" myth right away. Attackers do not pick names, they scan entire address ranges. Ransomware does not target your brand. It targets an open door.

MFA first, everywhere, authorized third parties included. The tax attack came through a third-party account. Your perimeter includes the accounts you delegate.

Then quotas and volume alerts. An account reading 678,000 files should ring an alarm long before the thousandth. No AI needed to start: a threshold is enough.

Test for IDOR on every endpoint that carries an identifier. One hour of testing, years of embarrassment avoided.

And the bug bounty comes last. Paying researchers to discover your missing MFA costs more than the MFA.

Finally, price the work honestly. MFA is included in most of the suites you already pay for. Quotas and volume alerts are a few days of development. An open source SIEM like Wazuh runs on a modest server: I host one myself. The cost of the basics is counted in days of work, not in licenses. The project looks out of reach. It is not. That myth feeds the inaction too.

The checklist to transpose

For a public system or a small company alike.

  • [ ] MFA everywhere, staff and authorized third parties included
  • [ ] An inventory of third-party accounts, with review and expiry
  • [ ] Consultation quotas and volume alerts on sensitive data
  • [ ] An IDOR test on every endpoint exposing an identifier
  • [ ] A SIEM centralizing the logs, and someone who reads them
  • [ ] One self-attack exercise per year, results shown to leadership
  • [ ] A security budget as a percentage of the IT budget, protected
  • [ ] One person with the authority to say no to a release
  • [ ] Supplier of a NIS 2 entity? Prepare the guarantees you will be asked for
  • [ ] Starting from zero? Begin with the free MonAideCyber diagnosis

What to remember

Security is not complexity. It is common sense, funded and enforced. The state just paid to learn it: its rules dated from 2014, its 200 million arrived after the leaks.

SMEs will get no national wake-up call and no 200 million plan. The only pressure trickling down to them is the supply chain: NIS 2 customers demanding guarantees from their suppliers. It trickles, slowly.

So do not wait for the law or the subsidy. MFA, quotas, volume alerts, the IDOR test: all of it deploys in weeks, not years. The 200 million was cheaper before. So is your cleanup.

Want to know what an attacker would see in your system before they show you? Let's talk.


Sources: economie.gouv.fr, FAQ and 18 August 2026 press conference · Cour des comptes, "The state's response to cyber threats" · L'Usine Digitale · JDN · Silicon · INCYBER, "France's August 2026 leaks" · Acteurs Publics, on the SREN decree and SecNumCloud · ANSSI, 2025 cyber threat panorama · Cybermalveillance.gouv.fr, 2025 activity report · ANSSI, France Relance cyber program results · Legiscope, NIS 2 transposition in France

Top comments (0)