Stolen passwords expose French tax data for seven weeks
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Wednesday, September 30th, 2026.
An attacker used stolen staff passwords to take French tax data covering hundreds of thousands of taxpayers and businesses. The activity continued during June and July and went undetected for seven weeks. Neither the tax administration nor the national cybersecurity agency detected the data leaving. The agency’s report described the attack as unsophisticated.
Valid staff credentials can make malicious activity resemble normal access unless identity and data movement are monitored together. This exposure affects both citizens and businesses whose tax information was accessed. For leaders, the incident shows that password theft can become a major data breach without a complex exploit. Defenders should verify multifactor authentication, review privileged access, and alert on unusual searches, downloads, and outbound transfers. The broader lesson is that authentication success doesn’t prove that the person or activity behind a session is legitimate. Require phishing-resistant multifactor authentication, and connect identity alerts with monitoring for unusual access and data movement.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.