France’s Directorate General of Public Finance (DGFiP) has disclosed a data breach affecting approximately 680,000 individuals.
The incident was discovered after a threat bragged on a hacking forum about accessing DGFiP’s internal systems and exfiltrating data.
According to DGFiP, the threat accessed its systems in June and July and the unauthorized access was stopped immediately after detection. However, state tax authorities found no evidence of data theft at the time.
Last week, DGFiP confirmed that attackers used compromised employee credentials and a third-party account to gain access to its systems and steal the information of 678,000 users.
According to the financial agency, reference tax revenue, withholding tax rate, company names and unique identifiers, as well as cadastral data on real estate addresses and areas were compromised.
No other information, including usernames and passwords, was compromised in the attack, which was immediately reported to the French data protection authority CNIL.
DGFiP says it is continuing to investigate the nature and scope of the data breach, as well as the exact number of individuals potentially affected. The tax authority says it will contact anyone affected directly.
The incident came to light roughly a month after another European government agency, Romania’s National Agency for Cadastre and Property Registration (ANCPI), fell victim to a devastating cyberattack.
The ANCPI was it is reported hacked by a threat known as ByteToBreach, which stole information, including employee credentials and internal documents, and attempted to extort the agency.
When the extortion attempt failed, the hacker deleted the encrypted data, disrupting official apps, websites and email services and bringing Romania’s real estate market to a standstill.
The central database of the cadastral system containing property records and real estate rights was not affected. Still, ANCPI struggled for about three weeks to restore its servers and restore the affected applications.
Related: 40,000 affected by SafePal data breach
Related: Fortune 500 companies fall victim to Azure data theft campaign
Related: Trivi, not LiteLLM, is behind the compromise with 2,500 organizations
Related: Irregular details how a naming error allows AI models to attack a real company