BlueOnyx
CybersecurityAIAccess ManagementCISOData

Six Weeks of Ghost Access Inside Tax Systems

Théodore BaillyPublished on 18 août 20265 min read
Deux professionnels analysant des données suspectes sur écran

Introduction

On August 12, 2026, a threat actor operating under the alias ZeroBytes listed a database belonging to France's Direction générale des Finances publiques (DGFiP) — the country's public tax authority — for sale on a cybercriminal forum. It was through that listing, not through its own monitoring systems, that the DGFiP learned it had been compromised. The intrusion traced back to June — several weeks earlier. That gap says everything.

What Was Stolen

The breach directly affects 678,000 individuals and businesses. Exposed data includes fiscal reference income, family quotient scores, withholding tax rates, cadastral property records, and company names alongside their SIREN registration numbers. A second dimension — tied to the professional access platform for cadastral data — potentially extends the impact to two million property owners. The DGFiP confirmed that personal accounts and user passwords were not compromised, but the stolen dataset is more than sufficient to craft highly targeted phishing campaigns.

Critically, the attack exploited no application vulnerability. It relied entirely on the compromise of legitimate credentials: those of a DGFiP employee, and those of an external contractor with authorized system access. Two entry points. Zero alerts for weeks.

The Blind Spot of Static Monitoring

That operational silence is the real story. Activity logs did record every connection — the credentials were valid, the access formally authorized. A SIEM configured around static rules sees nothing abnormal here.

This is precisely the gap that User and Entity Behavior Analytics (UEBA) tools are designed to close. Rather than matching each action against a library of known malicious signatures, UEBA systems build a behavioral baseline for every account: typical query volumes, login schedules, data categories accessed, session geography. Any meaningful deviation — even with valid credentials — triggers an alert.

The underlying machine learning models train on an organization's actual behavioral history and update continuously. Several vendors offer these capabilities as native extensions to their SIEM platforms or embedded within XDR suites. Applied to this scenario, anomalous query volumes or unusual data extraction sequences would very likely have been enough to trigger an investigation long before the attacker posted the database for sale.

Third-Party Risk: Still Chronically Underestimated

The compromise of the external contractor's credentials reflects a structural reality common to both public institutions and private enterprises. Access granted to third parties — system integrators, software vendors, subcontractors, audit firms — frequently falls outside standard review cycles and receives less granular monitoring than internal accounts, despite often carrying broad system privileges.

For IT and security teams, the principles are well established but inconsistently applied: least privilege for every external account, Privileged Access Management (PAM) with time-limited and fully logged sessions, and periodic access reviews for dormant vendor accounts. Behavioral analytics is the natural complement to these controls — operating precisely where static rules remain blind.

What Affected Organizations Should Do Now

For organizations whose SIREN data and tax information appear in the stolen database, the immediate risk is targeted social engineering. An attacker who knows a company's tax position, its executives, or its property holdings enters any conversation with substantial credibility. Awareness training on enriched phishing attempts — including at the executive level — is a step that should not wait for official notification from the DGFiP.

France's CNIL (data protection authority), ANSSI (national cybersecurity agency), and the Paris prosecutor's office — through the national anti-cybercrime unit — are all involved in the judicial and regulatory aftermath. For CIOs and CISOs, the lesson extends well beyond the public sector: detection can no longer rely solely on rules written before an attack is known. Behavioral analytics powered by machine learning was precisely what should have been at work here — and wasn't.

Share

Six Weeks of Ghost Access Inside Tax Systems