When attackers obtained staff credentials at France's tax administration (DGFIP) in June, they spent seven weeks extracting tax data on hundreds of thousands of taxpayers and businesses. Neither the tax authority nor France's national cybersecurity agency (ANSSI) noticed the exfiltration until July. The incident offers a stark lesson in what happens when organisations assume that strong perimeter defences are sufficient.
The Gap Between Access and Detection
Credential compromise is rarely a sophisticated attack. An attacker with valid staff passwords can move through a network with far less friction than someone trying to exploit unpatched services or bypass firewalls. Yet organisations often treat password theft as a detection problem to be solved after the fact, rather than a visibility problem to be prevented.
In this case, the attacker used legitimate credentials to access systems and exfiltrate data. From a firewall perspective, this looks like authorised traffic. The account owner may have been offline, unaware their credentials were compromised. The attacker's behaviour—pulling data across the network—should have been anomalous enough to trigger alerts, yet it went unnoticed for weeks.
This reveals a common blind spot: organisations invest heavily in intrusion detection at the network boundary, but far less in understanding what their own staff should actually be doing. When a valid user account suddenly queries hundreds of tax records at 3 am or transfers gigabytes to an unfamiliar destination, that should register as unusual. It didn't.
Why Egress Monitoring Remains Undervalued
Most breaches involve data leaving the network. Yet many organisations still treat egress filtering as a secondary concern. Inbound threats get the security budget; outbound traffic is assumed to be fine because it came from an internal account.
Proper egress detection requires baseline profiles: which users access which datasets, at what times, in what volumes. When someone with a tax analyst's credentials suddenly accesses personnel records or bulk-downloads entire tax files, that divergence from the baseline should trigger investigation. The absence of such baselines meant the attacker's activity appeared normal.
For organisations running infrastructure where sensitive data lives—whether cloud storage, databases, or file shares—egress monitoring should be treated as a first-class security control, not an afterthought. This means not just logging flows, but actively comparing traffic patterns against expected behaviour.
Credential Hygiene and Privileged Access
ANSSI's report notes that the attack succeeded partly because of weak access controls. The implication is clear: staff credentials should not have granted access to such large swathes of sensitive data in the first place. Principle of least privilege—giving users only the permissions they need for their role—is a bedrock security principle that remains poorly implemented in practice.
For infrastructure teams managing systems with sensitive data, this means regularly auditing who has access to what, and why. A tax analyst should not routinely need access to all taxpayer records; their role should grant access only to specific datasets or regions they work with. When credential theft does occur, the damage is automatically contained.
Additionally, stolen credentials should be harder to use. Multi-factor authentication, even if not preventing the initial breach, would have made it much more difficult for the attacker to sustain activity over seven weeks. Each session would have required a second factor, which either the staff member would notice or which the attacker simply couldn't obtain.
The Cost of Silent Breaches
Seven weeks is a long time to remain undetected. In that window, the attacker could copy data multiple times, ensure persistence, or hand credentials off to other groups. The longer a breach remains unnoticed, the more damage can accumulate and the harder remediation becomes.
For organisations running high-sensitivity infrastructure, undetected exfiltration is perhaps the most dangerous scenario: attackers have time to be thorough, while defenders have no opportunity to respond. This argues for investing in detection systems that don't rely on signature-based alerts or manual log review, but instead build statistical models of normal activity and flag deviations.
The French tax breach is not a story about a clever exploit or a zero-day. It is a story about how organisations can fail at the basics: understanding what normal looks like, so they notice when things are not. That lesson applies whether you are running a government agency or hosting infrastructure for customers with sensitive data.

