Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Stolen Passwords. Show all posts

French Tax Data Theft: Threat Actors Steal Password and Remain Undetected


A threat actor used stolen passwords of employees at France’s tax admin to steal tax data on businesses and hundreds of thousands of taxpayers in June.

Agencies could not detect intrusion 

Neither France's national cybersecurity nor the tax administration could notice the data leaving. According to the agency ANSSI’s report, the attack worked because of weak login security, weak monitoring, and poorly separated networks.

DGFIP, the tax administration, handles France’s tax website impots.gouv.fr. The data came from a tool called E-Contact that taxpayers use to contact the tax administration.
According to the DGFIP, the stolen data includes slightly over 250,000 firms and slightly over 350,000 individuals. Passwords and internet accounts belonging to taxpayers were not hacked.

Attack tactic

For individuals, the data that may have been accessed or copied includes their tax ID, contact details, family circumstances, reference taxable income and tax withholding rate, and a summary of the messages they exchanged with the DGFIP. The messages themselves might have been intercepted by less than 250 individuals.
For companies, it includes the firm name, SIREN registration number, address and basic details of their messaging. 

Different routes used

The threat actor used two different routes, the first started with suspicious logins in May and resulted in E-Contact. 
The first route depended on various stolen passwords of DGFIP staff. The passwords were stolen by infostealers, malware that secretly saved login details, from systems the DGFIP did not handle, most probably from staff’s own systems.

The two portals that the threat actor exploited, ADER and PIGP, required only a password, so the stolen password worked. DGFIP staff use PIGP web portal for HR services and email. ADER offers access to a few DGFIP applications through the RIE, the network that links French government ministries. 

The threat actor reached the RIE via compromised Education ministry systems linked to it. Sensitive DGFIP apps were not taken out from the rest of the RIE, allowing threat actors to access them from parts of the network with no apparent need. Officials also discovered signs of various attempts to hack into other government entities on the network.

The attacker was able to access a lot of data even though the accounts they used had no special rights. ANSSI did not look at how user rights were managed for this report.
Data from the land registry was obtained via the second path. It passed through APEX, a portal for partners like land surveyors and notaries, which requested an email with a one-time code and a password.