French tax authority breached via identity theft, 600,000 affected
Directorate General of Public Finances confirms late June intrusion after hacker claimed mass data exposure using stolen credentials.
France's Directorate General of Public Finances (DGFiP) confirmed unauthorized access to its systems in late June following an identity compromise. The breach, disclosed after a hacker claimed to have obtained data on 600,000 individuals, involved the theft or misuse of legitimate credentials to bypass authentication controls.
French authorities are now investigating the scope and method of the intrusion. The DGFiP manages tax collection and public accounting for the French state, holding sensitive financial records on millions of citizens and businesses. The agency has not publicly detailed what data was accessed or whether the 600,000 figure is accurate, but the hacker's claim suggests exposure of personal and financial information at scale.
Identity-based attacks continue to exploit the weakest link in enterprise security: credential hygiene. The DGFiP breach underscores the risk when attackers obtain valid access tokens, whether through phishing, credential stuffing, or insider compromise. Once inside, lateral movement and data exfiltration become trivial if segmentation and monitoring are weak.
- 01600,000 French taxpayers face potential identity theft and financial fraud exposure
- 02Tax authorities globally must audit credential management and privileged access controls
- 03Breach may expose corporate financial data useful for competitive intelligence or extortion
- 04French government credibility on data protection faces renewed scrutiny ahead of regulatory reviews
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.