France's finance ministry confirmed on 14 August an unlawful access to the systems of the Directorate General of Public Finances, the French tax authority. The investigation finds that data on 678,000 individuals and businesses was viewed or extracted. For individuals, reference income, family quotient and withholding rate. For companies, business name and registration number. And land-registry data, addresses and floor areas of properties.
What matters is the how. There was no hole in the software. There was a takeover of the credentials of an administration employee and of an authorised third party. With those two keys, the accesses took place in June and July. Nobody saw them. The alarm came on 12 and 13 August, when the attacker claimed the intrusion and put the database up for sale on a forum. The administration then shut down access to sensitive systems, notified the data protection authority, is working with the national cybersecurity agency and has filed a criminal complaint. Taxpayers' personal online accounts and passwords were not affected.
Two lessons fit any SMB. First, your supplier's access is your access. One of the two credentials was not in-house, it belonged to someone outside with permission to get in, and it worked just the same. Second, two months passed between the first access and detection, and detection came from the attacker himself. If nobody reviews who gets in and when, the breach becomes known when others announce it. The four access checks that fit in one morning are in The company shuts down in August, but your access doesn't.