Senate report on DGFiP cyberattack highlights two-factor authentication absence and remote access as structural failings
The Senate Finance Committee identifies two major structural weaknesses in the attack that resulted in the theft of tax data belonging to approximately 350,000 taxpayers.

Senate: report on tax authority cyberattack points to structural failings
The Senate Finance Committee has published its initial analytical findings on the cyberattack targeting the General Directorate of Public Finance (DGFiP) during the summer. According to the memo written by the committee's chairman, Senator Claude Raynal, and rapporteur Jean-François Husson — revealed by Le Monde and consulted by acteurspublics.fr — the attack resulted, among other consequences, in the theft of tax data belonging to approximately 350,000 private individuals.
The document, enriched by an interview with the General Director of Public Finance, Amélie Verdier, provides a clear assessment of the situation. In 2025, the DGFiP detected 6,972 cyberattacks, compared to 2,579 in 2023, "representing an increase of around 170 per cent over two years," the authors note. By the end of August 2026, the count already stood at 7,810 attacks detected since the start of the year, exceeding the total for the entire year 2025.
Inter-ministerial interconnections and remote access
The memo identifies two principal blocking points. The first concerns the proliferation of access channels to the directorate's applications and data. The senators emphasise the need to "find a better balance between data circulation and access security".
The reconstructed timeline of the intrusion reveals fraudulent access at several successive levels: first via credentials of an Education Ministry official, allowing access to the state's inter-ministerial network; then via credentials of a DGFiP official to penetrate the ADER portal, which provides access to the directorate's applications for its partners. These incidents "illustrate the risks associated with the interconnection of information systems at the inter-ministerial level," the memo states.
The authors also note that "connection channels multiplied for DGFiP officials, particularly during the health crisis, without subsequently being deactivated". These remote access points "constitute an additional source of vulnerabilities, with personal equipment being more exposed to malicious software". Officials had been authorised to connect from their personal equipment for uses deemed less sensitive: professional email, calendars, human resources services. Most of these access points have since been cut off by the DGFiP.
Absence of two-factor authentication on a compromised account
Another failure identified in the report — and already acknowledged by the government following the attack — is the absence of an active two-factor authentication system on one of the compromised accounts, "despite the fact that the accessible data were covered by tax confidentiality". Two-factor authentication is nonetheless among the flagship measures of the state's national cybersecurity strategy presented in February. It constitutes one of the principal points of tension in recent cyberattacks, a majority of which were made possible by compromised accounts.
The senators also point out the absence of mechanisms capable of automatically detecting an abnormal volume of database consultations or extractions. In the event that an authorised account generates massive extractions — a routine operation in the DGFiP's missions given the volume of data it handles — no automatic alert was in place. "We believe that such mechanisms should be rapidly generalised, according to an approach proportionate to the level of risk," the senators state. The Minister for Public Action and Accounts, David Amiel, told them that the rollout of these mechanisms would be accelerated by prioritising the most sensitive applications.
Weaknesses already flagged, a long-term undertaking
The memo emphasises that these structural weaknesses "had already been highlighted on several occasions," as had "the need for the tax administration to address its technical debt," a major undertaking already underway for several years.
During her interview with the commission's representatives, Amélie Verdier presented three lines of action adopted following the cyberattack: access security, improvement of attack detection capabilities, and strengthening of training and support for both officials and users. "Their practical implementation will need to be closely monitored by the commission," the senators state.
The commission also awaits the conclusions of the audit conducted by the National Information Systems Security Agency (Anssi), requested by the government. The Senate further intends to conduct broader future work on the cybersecurity of public administrations.
Source: Google News LU FR