Clermont-Ferrand, 16 August 2026

It is the most widely discussed public-sector data leak of the summer, and probably the most instructive. On 12 August 2026, a malicious actor publicly claimed illegitimate access to the information system of the Directorate General of Public Finances (DGFiP). The next day, the administration confirmed it: tax data had indeed been consulted and extracted. The published count covers roughly 678,000 individuals and businesses, while the perpetrator claims 678,438 records. Those concerned are being informed individually from Monday 17 August, the French data protection authority (CNIL) has been notified, a criminal complaint has been filed, and the Paris public prosecutor has opened an investigation for fraudulent data extraction and criminal conspiracy, entrusted to the specialised cybercrime units.

For a company director, the temptation is to file this away as "the government's problem". That would be an analytical mistake. What happened at the DGFiP is not an accident peculiar to the tax administration: it is the dominant attack pattern of 2026, and it works just as well against a forty-person SME as against a government department.

What we know about the facts

The intrusion dates back to the end of June 2026, with access continuing into July. The vector was not a spectacular application vulnerability but an identity takeover: that of a DGFiP officer and that of an authorised third party. With those identities, the attacker obtained legitimate remote access, then the use of an internal search tool able to query both individuals and businesses. Access was cut at the end of June as part of the controls carried out, but the extraction had already taken place, spread over time.

For individuals, the data involved includes surname and first names, the family quotient, the reference tax income and the withholding tax rate; for businesses, the company name and SIREN number. The administration stated that this data does not, in itself, allow access to the secure area of the impots.gouv.fr website. A second claim, made on 14 August, concerns an application interface linked to land registry data; other French organisations have also been named by the same actor.

Timeline of the DGFiP incident FROM INTRUSION TO DISCLOSURE — 7 WEEKS late June July 12 August 13 August 15 August Intrusion via stolen identity Extraction drop by drop Public claim Official DGFiP confirmation Paris prosecutor opens a case The blind spot: between the intrusion and its public disclosure, detection did not come from internal monitoring but from the attacker's own claim, seven weeks later.
Sources: official communications from the DGFiP and the Ministry of the Economy, 13-15 August 2026.

The real lesson: the attacker broke nothing, he logged in

This point deserves emphasis, because it determines the entire defensive strategy. No zero-day, no ransomware, no noise. A valid credential, legitimate remote access, a business tool used exactly as an officer would use it. Classic controls see nothing: authentication succeeds, the source is authorised, the queries match the expected format. And the exfiltration is spread over weeks, in small requests, precisely so that no volume threshold is crossed.

This is the scenario that defeats almost every security setup built on rules and thresholds. A well-configured firewall does not block an authorised user. An antivirus does not detect a legitimate session. A SIEM tuned to volume thresholds does not fire on a thousand small requests spread over six weeks. The only thing that betrays this kind of attacker is the coincidence of weak signals: a credential circulating in a leak, a connection from a country never seen for that account, a rate of application requests that does not match the user's habits, an unusual sharing destination. Taken separately, each of these signals is meaningless. Correlated on the same account at the same moment, they point to a stolen account.

Where does the attacker find valid credentials?

The question deserves a direct answer, because the answer is industrial. The credentials used in these intrusions are no longer harvested one by one through artisanal phishing. They are mass-produced by infostealers — information-stealing malware installed on a machine, often a personal one, often outside the perimeter managed by the IT department. In seconds, the infostealer siphons off passwords saved in the browser, session cookies, authentication tokens and VPN configuration files. The result, known as a "log", is then resold or distributed on Telegram channels, criminal forums and specialised marketplaces, in batches of several thousand.

Between the theft of a credential and its use in an intrusion, several weeks usually pass, sometimes several months. That window is the one opportunity to win the game before it starts. An organisation that continuously monitors the appearance of its domain names, its corporate addresses and those of its executives in these channels can reset a compromised account before anyone uses it. An organisation that does not monitor them discovers the problem when the attacker announces it publicly.

The government's response: a real plan, but one that does not cover your company

The government has not been idle. The strategy announced by the Prime Minister mobilises 200 million euros to fund investment in applications, detection tooling and post-quantum cryptography, and creates a new state digital authority, ARIANE, reporting directly to the Prime Minister's office and tasked with standardising and securing ministerial digital infrastructure. An emergency plan of priority actions has been imposed on every ministry, with quarterly follow-up. All of this sits within the National Cybersecurity Strategy 2026-2030, which deliberately goes beyond a purely technical approach to establish cybersecurity as a broad resilience policy.

This plan is necessary, and its scale is welcome. But its reach must be measured precisely: it protects the state, not companies. And it does not put back in the box the data that has already left. The 678,000 exposed records will fuel, in the weeks and months to come, phishing campaigns of unprecedented credibility. A message quoting your exact reference tax income, your family quotient and your withholding tax rate does not look like a scam: it looks like the tax authority. On the business side, the combination of company name, SIREN number and tax data is direct fuel for supplier fraud, CEO fraud and corporate identity theft with banks and partners.

What SYLink puts in front of it

Our conviction is simple: against this pattern, you have to cover the three phases of the attack — before the intrusion, by monitoring leaked credentials; during, by correlating the weak signals of a hijacked account; after, by containing and documenting. That is exactly how our offering is organised.

SYLink Leaks — darkweb monitoring, upstream of the intrusion

SYLink Leaks continuously monitors your organisation's exposure on the surface web, the deep web, the darkweb and criminal marketplaces. Detection relies on sovereign crawlers (Tor, I2P), on partnerships with European threat intelligence providers, and on targeted agents deployed on the Telegram and IRC channels where infostealer logs circulate. Three levels cover different degrees of maturity: Basic (12 modules, monitoring of email, domain and brand, weekly reporting) for very small structures; Enterprise (28 modules, adding compromised credentials, IOCs and marketplaces, daily reporting) for SMEs and mid-caps; VIP (58 modules, adding executive protection, brand impersonation detection and targeted deep web, real-time alerting) for large accounts, critical operators and government entities. One decisive point: final qualification is human. Our French analysts validate every alert and assign it a criticality level before it reaches you. The principle is deliberate — zero junk alerts, because a team drowning in false positives eventually stops reading.

Infostealer monitoring — finding the stolen account before the attacker does

This is the module that answers the DGFiP scenario directly. We continuously cross-reference credentials appearing in infostealer log dumps against your perimeters: company domains and subdomains, URLs of your exposed applications, corporate addresses, and — at the customer's explicit request — the personal addresses of privileged accounts, since the personal machine is very often the source of the leak. Every match triggers a credential-exposure alert together with an immediate remediation plan: resetting the account in the directory or in the Microsoft 365 tenant, revoking active sessions and tokens, checking remote access opened with that identity. By design, passwords are never stored in clear text on our side: only cryptographic fingerprints are kept, with a limited retention period, in line with the GDPR.

UniSOC — detecting the hijacked legitimate account

When a credential has slipped past upstream monitoring, in-flight detection remains. UniSOC, our sovereign SOC platform operated jointly by SYLink Technologie and Unitel, correlates in a single place SIEM logs, EDR agents (Windows, macOS, Linux), DPI probes, authentication events and threat intelligence signals, including credential-exposure alerts from SYLink Leaks. The detection engine does not reason in absolute thresholds but in deviations from each account's usual behaviour: access from a country never observed for that user, outbound volume abnormal relative to its own baseline, and above all an out-of-norm number of application requests — the exact signature of the drop-by-drop pattern, a thousand small requests that no volume threshold will ever catch. Several of these axes concurring on the same account push signals over the alert line that would otherwise have stayed silent. Beyond that, escalation is handled by French analysts, with a target of under fifteen minutes between a critical detection and the first containment action, isolating an endpoint or disabling an account. The infrastructure is hosted in France, HDS V2 certified, with no outbound request to any third-party service: our customers' logs do not leave the country, and AI analysis runs on our own GPUs, locally.

Covering the three phases of a stolen-account attack BEFORE · DURING · AFTER BEFORE THE INTRUSION SYLink Leaks Darkweb, deep web, marketplaces and Telegram channels Infostealer logs matched against your domains and accounts Outcome: the account is reset before it is ever used DURING UniSOC Exposed identity + never-seen geography + abnormal application activity Multi-axis correlation, no thresholds Outcome: the drop-by-drop becomes visible AFTER Incident response Network isolation, accounts cut off Memory, disk and network forensics Regulatory notification file and communication support Outcome: controlled timeline, defensible evidence Hosted in France, French analysts, no outbound request — AI analysis runs locally. Compliant with NIS2, GDPR, HDS V2 and PSSIE.

Five measures to take this week

1. Inventory remote access and privileged accounts. The question to ask your IT department or your provider is not "do we have a secure VPN" but "which identities can open remote access today, and which one was last used from an unusual country". Any remote access without hardware multi-factor authentication should be treated as public access.

2. Check your existing exposure. Your credentials may already be circulating. A first exposure report on your domains, corporate addresses and executives takes a few days and provides a factual, quantified basis for the budget discussion that follows.

3. Treat the personal machine as an attack surface. The employee who saves a work password in the browser of the family computer creates a door your firewall will never see. Clear policy, a company-provided password manager, and monitoring of the personal addresses of sensitive accounts with their consent.

4. Warn the teams exposed to tax-themed phishing. Accounting, payroll, finance: these functions will receive, in the coming months, messages built on accurate tax data. The rule must be formalised: no change of bank details, no exceptional payment, no transmission of a tax document without validation through a channel separate from the one carrying the request.

5. Move from threshold logic to correlation logic. This is the underlying shift. As long as detection rests on absolute rules, a hijacked legitimate account will stay invisible. That is precisely what a SOC is for: bringing together signals that nobody looks at side by side.

What to take away

The DGFiP incident does not say that the tax administration is poorly protected; it says that perimeter protection, however solid, is no longer enough once the attacker shows up with valid keys. French companies face the same pattern, with far weaker detection capabilities and, often, no visibility at all on which of their employees' credentials are already in circulation. The good news is that the window exists: weeks pass between the theft of a credential and its use. It only benefits those who watch it.

SYLink Technologie is an independent French vendor, founded in Clermont-Ferrand, whose code, hosting, support and teams are entirely in France. To assess your exposure, the SYLink teams can be reached via sylink.fr/contact, and a free cyber diagnostic, delivered within 48 hours by an expert, is available from the home page. The SYLink Leaks page details the three monitoring levels, and the SOC supervision page presents the detection architecture and service commitments.