On 29 September 2026, France's national cybersecurity agency ANSSI published its incident report on the attacks against the country's tax administration, the DGFiP. There is no exploit in it. Several dozen valid staff credentials, which the report attributes to infostealer malware on computers the DGFiP did not manage, were presented to portals that asked for nothing more than a password. Roughly 14 GB left across activity running from late May, and the theft became public only when the actor advertised the data in August.
The reporting has focused on the absent multi-factor authentication and the monitoring that did not correlate, both correctly. The list of missed signals repays a closer look.
What actually happened
| Date | Event |
|---|---|
| Late May 2026 | ANSSI's report places the start of the malicious activity here |
| 22 to 25 June | Roughly 11 GB extracted through the E-Contact application |
| 24 June | A password reset on a compromised account leaves the attacker's existing session running, per ANSSI's account |
| Late July | A further 3 GB extracted in a second wave |
| 12 August | The actor using the alias Zerobytes advertises the data publicly |
Four systems appear in the report. Clubic describes PIGP as the internet-facing staff portal that required only a username and a password, and E-Contact, the taxpayer correspondence tool that 11 GB came out of, as reachable through it. ADER, the portal onto the interministerial network, also had no second factor and was reached after another ministry was compromised. APEX, the partner portal for notaries and surveyors, had a one-time code sent by email, worth little, ANSSI notes, when the mailbox opens with the same password. ANSSI puts the totals at roughly 353,000 individuals and 252,000 businesses, against the 678,000 records the actor claimed.
The gap: the origin evidence arrived first and was read last
Monitoring recorded the activity faithfully enough that ANSSI reconstructed the whole intrusion from it months later. That is not a broken sensor.
Now look at the whole list The Hacker News draws from the report: logins at night, connections from commercial VPN services, addresses in India, addresses already known to be malicious, data volumes that raised nothing including the 11 GB moved between 22 and 25 June, and the number of requests each user made, unchecked although scraping needs one request per page.
ANSSI is careful here, noting that signals like these throw up many false alarms alone and that it is together that they could have raised one. That is a fair account of why no single one was acted on: correlation arrives afterward.
Three of those describe where a connection came from, and those three existed before the login they belonged to. The hour is a property of the login too. But the 11 GB and the request counts could not have fired until the theft was already under way: they are evidence of a door that is open, not of a door about to be opened.
Multi-factor authentication was absent on PIGP and ADER, and ANSSI is right to put it first among the remedies. But notice what MFA is here: a control that engages once a credential has been presented to a service that has already answered. It would have raised the cost of every one of these logins, and it engages second.
What would have had to be true
Ask something narrower than how to stop credential theft. Ask instead: what would have had to be true for a valid DGFiP password, held by somebody connecting from a commercial VPN exit node at three in the morning, to be worth nothing?
The portal would have had to not answer that network.
Source-restricted access on a published staff portal is not an advanced capability, and ANSSI's recommendations reach for the neighborhood of it: confine work to agency-managed devices, and use address reputation to refuse connections. Reputation answers which addresses are known bad. The harder question is which are known good today, continuously and across vendors, and nothing answers that. A list written by hand is wrong the day after it is written, so it gets widened until it means nothing, or dropped. No DGFiP portal was restricted this way because the control the advice describes has never been maintainable, not because somebody was careless.
Where Veribound would have fitted
Veribound is a Pre-session Edge Access Control platform and an intelligence layer. It replaces nothing: the portals, the identity systems, the monitoring and ANSSI's multi-factor rollout all stay, and the customer's own edge keeps enforcing its own policy.
Agents attest that each device is still the one the organization authorized, and a trust-scoring engine turns those attestations into a per-device decision. What reaches the edge is a trusted origin: the network that device is connecting from, in practice its public address, while the device behind it is still trusted. Those origins are kept current in the address groups the organization's own firewall policy already references.
Applied to an internet-facing staff portal:
- The stolen passwords are still stolen, still valid, and arriving at a service that is not answering the network they arrived from.
- The origin question gets asked before the session, rather than reconstructed from logs seven weeks later, and a compromise that still happens arrives from an authorized origin, traceable to a token the organization issued to somebody it admitted.
- Nobody stops working, because the portal still answers the staff who need it, from wherever they are.
What it would not have done needs stating plainly. It would not have kept an infostealer off a personal computer the agency never managed: that is endpoint and device policy, and ANSSI's recommendation to confine work to managed machines is the right control there. It would not have covered the ADER path, reached from inside the interministerial network, where ANSSI names segmentation as the gap. And it would not have ended the session that outlived the password reset, nor supplied the missing correlation.
APEX is a different kind of limit. An authorized origin is not one the organization owns; it is one where somebody the organization admitted to an authorized group is working, whoever owns the machine and whoever sells the broadband. Notaries and surveyors are the sort of population a customer can admit, not one out of reach. What would have made APEX hard is scale: enrolling a large body of independent professionals is a much bigger undertaking than covering your own staff, and an agency may reasonably decide not to.
The claim that holds is narrower than the incident and sits on its first system: a portal published to the whole internet, asking for a password and nothing else, answered somebody who had one.
Source: French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks, The Hacker News, 29 September 2026.