According to the report from ANSSI (Agence Nationale de la Sécurité des Systèmes d'Information), the attackers used legitimate staff credentials to gain access to DGFiP (Direction Générale des Finances Publiques) systems and extract tax and personal data.
The attackers did not need a sophisticated new technique. They used legitimate DGFiP staff credentials and exploited a series of relatively basic weaknesses in the way government systems were accessed, connected and monitored.
Over about three months, the attackers obtained several dozen sets of credentials belonging to DGFiP staff. ANSSI believes they were probably stolen by information-stealing malware on computers that DGFiP did not manage, including personal devices used against policy. Two of the portals involved did not require multi-factor authentication.
The attackers first compromised infrastructure belonging to the Ministry of Education, which is connected to the government's shared network. There was insufficient separation between the ministries' systems, allowing them to move from one to the other and reach a DGFiP portal.
The portal was not covered by DGFiP's security monitoring. From there, the attackers reached an application used to handle enquiries from taxpayers and built automated tools to extract records from it.
The government has confirmed that data relating to about 678,000 individuals and businesses was accessed and extracted. The data includes tax details such as reference taxable income, family quotient and withholding-tax rate, and, for businesses, company name and business registration number. Reports say bank details were not involved.
A separate incident involved land registry records (cadastre). Attackers compromised the computer of a private surveyor (géomètre-expert) who had legitimate remote access to the system, and used that access to obtain names, dates of birth, parcel references and ownership records. The attacker claimed this covered two million people, but ANSSI's report does not confirm that figure.
The system used a one-time code sent by email as its second authentication factor. ANSSI considers this inadequate when an attacker also controls the victim's computer and email.
Neither DGFiP's security monitoring nor ANSSI's own network monitoring detected the intrusions. Because the attackers were using legitimate accounts, their activity was difficult to distinguish from normal use.
ANSSI says several signals, including repeated connections from unusual IP addresses, logins at unusual times and activity consistent with automated scraping, were recorded but were never correlated into an effective alert. The public learned of the attacks when the attackers publicised them.
ANSSI identifies several areas of weakness, including stolen credentials and missing multi-factor authentication; sensitive applications reachable from the shared government network without sufficient separation; and an unmonitored portal and warnings that were not effectively correlated.
ANSSI recommends mandatory multi-factor authentication across government portals, an end to the use of personal devices for accessing professional systems, monitoring of all business applications rather than selected systems, stronger separation between ministries on the shared network, and a requirement that resetting a compromised password should also terminate all active sessions.
Related Reading:
