Piratage DGFiP: ANSSI reveals how stolen passwords led to catastrophe
ANSSI has released its incident report on the recent DGFiP hack. Stolen agent credentials, absent two-factor authentication, and unnoticed data exfiltrations are detailed in the document, explaining how the data of hundreds of thousands of users was leaked this summer.
To steal a vast amount of data from the Directorate General of Public Finance (DGFiP), no unprecedented vulnerability or shadowy genius was required. The data theft that hit impots.gouv.fr this summer was less a thriller and more an accumulation of basic failures. For weeks, a cybercriminal navigated the tax authority's applications using the credentials of real agents, passing through another ministry, without their data extractions being detected. ANSSI, the French cyber agency, reconstructs the timeline, dissects detection failures, and details the necessary work—some of it urgent.
The public learned of the incident on August 12. On that day, a hacker named Zerobytes claimed responsibility on a forum for the data theft from impots.gouv.fr. At 4:32 PM, ANSSI alerted the DGFiP, and by the next morning, the hacker displayed the details of their haul. The files originated from E-Contact, the internal messaging system used by tax agents to communicate with taxpayers. Two figures circulated: ANSSI reported nearly 353,000 individuals and 252,000 professionals affected, while the hacker claimed around 678,000 records. Crucially, the theft was not recent; data was siphoned off at the end of June, seven weeks before the claim.
Gaining access didn't require picking locks; the attacker had the keys. Over three months, they obtained the usernames and passwords of several dozen tax agents, likely stolen by information-stealing malware, possibly from devices not controlled by the DGFiP, such as agents' personal computers. To access ADER and PIGP, two portals leading to tax applications, an agent only needed their username and password—no multi-factor authentication, like a code sent to a phone, was required. This practice was common at high levels of government. The DGFiP did have a safety net: a contractor monitoring sites where credentials were sold and flagging compromised accounts for password changes. ANSSI found this useful, but it wasn't foolproof and sometimes reacted slowly. One account flagged on June 3rd had its password changed nine days later.
Reaching the right level was the next step. The attacker first connected to PIGP, an internet-accessible tax portal. They then moved to ADER, another entry point exclusively for the Interministerial State Network (RIE), a network connecting government departments. To connect to RIE, they used compromised infrastructure from the Ministry of National Education. Once on this shared network, a lack of segmentation meant nothing separated them from sensitive tax applications. An alert had been issued on June 9th; the Ministry of Education had sent security teams from other ministries 17 technical indicators of the attack, including a list of IP addresses to monitor, one of which the hacker was using. They then scraped E-Contact, a program that copies data record by record, between June 24th and 25th, and again on July 22nd.
Unfortunately, none of these data exfiltrations were detected by the DGFiP or ANSSI. The agency's probes monitor network traffic, not activity within applications. Since the hacker used legitimate accounts, they appeared as any other agent. Still, indicators were present. A total of 11 GB of data was transferred between June 22nd and 25th, followed by 3 GB at the end of July. Some connections occurred late at night, via VPNs, from India, or from IP addresses known for malicious activity. Scraping, which requires a query for each accessed record, must have generated an unusually high volume of requests, unhindered by any limits. Simple agent accounts, without special privileges, granted access to large amounts of data. Individually, these signals might seem trivial and risk overwhelming security teams with false alarms. Collectively, they could have betrayed the intruder.
The timeline is, frustratingly, revealing. On June 23rd at 8:50 PM, suspicious searches on PIGP triggered a ticket at the DGFiP's Security Operations Center (SOC), which reset the account's password the next day at 10:40 AM. However, ADER was not monitored, and the reset did not terminate the open session. The scraping, initiated at 4:26 AM, continued until June 25th at 2:31 AM. In July, the account used was reset only two days after the exfiltration resumed. The report also notes that a report of compromised accounts, sent on June 15th, received no response from the DGFiP, nor was there a follow-up from ANSSI. These accounts had, however, already been reset.
On August 13th, Zerobytes claimed responsibility for data from the Professional Cadastral Data Server. According to the hacker, the names, birth dates, parcels, and properties of 2 million French citizens were involved. The entry point, again, was not extraordinary. The likely compromised workstation of a private surveying firm allowed bypassing the two-factor authentication for APEX, the portal reserved for partners like notaries and surveyors. The second factor, a simple code received by email, proved insufficient. According to the DGFiP, access and exfiltration occurred between July 27th and August 8th.
In August, the DGFiP took decisive action. On the 6th, before any public claim, ANSSI alerted them to two suspicious IP addresses; upon reviewing its probe logs retrospectively, it detected suspicious traffic to two tax portals. On the 11th, the DGFiP confirmed abnormal connections, reset five accounts, and blocked these two IP addresses. Access restrictions followed. On August 13th, agents lost access to the ADER portal, followed by PIGP on the 18th. For PIGP, only external partners, such as local government accountants, retained access. Neither of these access points is expected to be reopened to agents. Regarding the cadastral data, the surveyor's account was deactivated on August 14th, the APEX portal was locked, and all accounts from their firm were suspended on the 18th. ANSSI acknowledges that these drastic measures significantly disrupted the work of the DGFiP and its partners.
For the future, ANSSI has drafted comprehensive recommendations. Firstly, it proposes prohibiting personal computers for accessing tax tools and restricting internal applications to DGFiP-managed and secured workstations. Secondly, it suggests mandating multi-factor authentication everywhere, with a second factor distinct from the password. An email code is useless if the email account is accessed with the same credentials; a physical key or a dedicated app, ideally on a separate device, is preferable. All applications should be monitored by a SIEM, a central control system that collects and analyzes connection logs. Quotas for data access, blocking of suspicious IP addresses based on origin or reputation, and session termination upon password changes are also recommended. ANSSI finally calls for agents to have access only to data necessary for their duties, for better segmentation of the Interministerial State Network (RIE) between ministries, and for much faster circulation of attack indicators.
The report, at least, is commendably frank. It states that this compromise "is not the consequence of a sophisticated attack." Instead, it resulted from weaknesses in identity verification (how connections are validated), architecture (network and application organization), and anomaly detection. A full audit is already planned to uncover all exploitable vulnerabilities. The ongoing projects could shape the state's digital security roadmap. ANSSI conditions this on obtaining support from the teams managing these applications daily, the hierarchy of the Ministry of Action and Public Accounts, and other administrations. In other words, the security of the tax authority will not be determined solely within its security center.
Fresh materials — Tech News

Google Analytics for Firebase Glitch Crashed Thousands of iPhone Apps
A data formatting error originating from Google's servers triggered a cascade of crashes in numerous iOS and iPadOS applications that use Google Analytics for Firebase. The issue, which occurred on the night of September 28-29, prevented many apps from launching. The problem stemmed from a

Philips OneBlade 360 Connected Face + Body for under €40: 35€ off on Amazon
Amazon's early Prime Day sale offers the Philips OneBlade 360 Connected Face + Body (QP4631/65) at a 47% discount, priced at €39.99 instead of its recommended €74.99, saving €35. This hybrid razor, designed for trimming, edging, and shaving, includes a body kit and app connectivity. It's id

Anker SOLIX S2000 Power Station Price Drop Ahead of Prime Day
The Anker SOLIX S2000, featuring a 2000Wh LFP battery and a rapid 10ms UPS switchover, is positioned for both home backup and off-grid use. Currently, Amazon offers it for €699.99 as part of their early Prime Day deals, a significant drop from its recent low of €1199.99. This

Amazon Prime Day Tech Deals: Early Bird Discounts Up to 58% Off
Amazon's Prime Day Flash Sales officially start October 6th, but the retailer has already reduced prices on select tech items. We've identified 20 of these early offers, ranging from Roborock and Dreame robot vacuums to Anker solar power banks, distinguishing genuine price drops from minor disc

Ecovacs Robots: Save Up to €300 on Cleaning Devices Until October 7
Ecovacs is offering discounts on three of its robots until October 7th, aiming to reduce daily chores. Savings can reach up to €300. The DEEBOT T90S PRO OMNI handles floor cleaning with its OZMO ROLLER 3.0 system. A 27cm roller cleans continuously with 32 high-pressure jets, s

iPhone Duo: Apple Reveals More StandBy Mode Features
Apple hasn't fully revealed all the capabilities of its first foldable iPhone. Files within iOS point to additional display options for its StandBy mode. At its September 9th event, Apple showcased some of the features for the iPhone Duo's StandBy mode. However, with commercial