frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

France's tax agency got hacked (in French)

https://www.cybernetica.fr/piratage-des-impots-comment-en-est-on-arrive-la/
55•zakxxi•1h ago

Comments

zakxxi•1h ago
Posted this because it's a solid post-mortem on the recent French tax agency breach, going beyond the headlines into the detection gap, the legal angle, and the broader systemic issues. Quick summary of the key points below (original is in French):

* French tax authority (DGFiP) breach › ~678,000 records leaked, names, tax bracket, reference income, withholding rate

* Detection gap › intrusion spotted and cut off in late June, but the actual data theft wasn't discovered until the stolen data went up for sale on Aug 12, over a month later

* Second breach, same attacker › land registry (cadastre) systems, late July, claimed 2M+ people affected, alleged MFA bypass

* Third incident › French Ministry of Education systems also compromised in late July (staff data since 2001), disclosed quietly with little press coverage

* Legal precedent cited › a 2023 EU Court of Justice ruling (stemming from Bulgaria's 2019 tax agency breach) established that fear of misuse alone counts as damage, and shifts the burden of proof onto the agency to show its security was adequate

* Root cause argument › legacy "trust everything once you're inside" architecture, opposite of zero-trust, extended via remote/VPN access since COVID without redesigning the underlying trust model

* Systemic issue › France's NIS2 transposition law has been stalled in parliament since 2024, partly over a dispute involving encryption backdoor provisions

* Broader angle › piece also covers AI's growing role on the offensive side of cybersecurity, and the US scaling back international cyber-cooperation efforts through 2025–2026

INTPenis•49m ago
* Root cause argument › legacy "trust everything once you're inside" architecture, opposite of zero-trust, extended via remote/VPN access since COVID without redesigning the underlying trust model

How many workplaces have I seen like this? A tale as old as IT.

eloisant•40m ago
It's a big mess in schools now, the whole messenging system is down as a preventive measure so the only way they can communicate (between each other, to parents, etc) is by phone.

And kids are back to school in one week.

penr0se•54m ago
"got hacked (in French)".

Got hacqued.

debo_•48m ago
I lol'ed, but I imagine outside of Quebec the French probably just use the English word "hacking" when referring to a computer hack.
9dev•39m ago
ordinateur-ed
EGreg•20m ago
I once accidentally left my backpack in Nice’s tram, containing mon ordinateur principal. I was flying to Balaji’s Network State conference in Singapore and had no time to go back. I did get ahold of a tram operator and another tram operator had found it at the end of the line. I had left my whatsapp number for her and had to run.

While in Singapore I was able to get ahold of some policeman who made some calls and was told it was waiting for me at the Lost and Found inside the Nice airport gift shop. I thanked him and made 24 hour layover in Nice.

Well, getting to the airport, I came tk this shop. I asked about the “sac a dos gris” in the other room. They checked their ordinateur: “NO, je suis desolee”. Sorry sir! I said you definitely have it, can you please go to that other room and check? “No sorry we cannot. It is not here. After a week we give things to the municipal lost and found. At the polics station. Go there.”

The day was ending (French govt services work til 4pm) so I raced to the municipal police station in Nice. I arrive and they have a bunch of keys and other things people lost around the city. I barely speak French but luckily a middle-aged lady was there who spoke good English. She helped me ask them. “No. Sorry. It is not here.” Are they sure? “Yes, we checked. Not here.”

She gave me a ride on her vespa (she had a motorcycle) and I treated her to dinner while we discussed the situation. We agreed I should go to the central police station after that and file a missing item report. Which I did (spoiler alert: doesn’t do anything, but standing in line is less than in US cities).

That night I chose to stay at some rinkydink place in Nice, because why not (I was by myself) and got up around 4am to take the bus to the tram network’s lost and found — the last place it could be. I would have aittle time before my flight.

In the morning I got up early and got to that Lost and Found, before my flight. I had one hour. It was located near a university, and after wandering around I had found the little enclave. The staff there were very nice — but they didn’t have it either!

I flew home, dejected. My backups hadn’t been perfect; I had a lot of stuff on that computer, including an iOS App on XCode that I had to release to a lot of people! (And a couple Metamask wallets.)

Anyway I kept in touch with the nice policeman throughout. He went to the airport lost and found - the same one which refused to check the other room because their computer said it wasn’t there — and CONFIRMED that my bag was there. They had let him check the back room, you see!

But I wasn’t in Nice anymore. I filled out a “troov.com” report and explained where it was. They had found it! Paid for FedEx. Over the next few days thanks to the Tracking I saw it go to the central station in France and then sent back. Because it was missing a customs form for USA. I had filled out that form, but something had been wrong. I had spoken to the main FedEx customs-facing team in Memphis for a few days, and they thought it was in USA already. They were wrong. Their system was also blind to this. Anyway, I saw it go back to that airport lost and found, a week later. Lost about $100…

Then, the lady offered to come pick it up for me. She came, and was thankfully given this bag. She mailed it with DHL, and I received it. It was really overjoyed when it finally arrived, a month and a half after I had lost it! I of course sent the lady a payment to cover the cost. She did not want any other compensation. We are still friends to this day, and when my dad goes to France, I am putting them in touch.

One moral from this story is: French employees love to say “No” to anything and everything. If their computer says the thing isn’t there, they won’t budge even when it’s the easiest thing to just check the other room manually. Unless you are a local policeman!

The other moral - back up your stuff! Have SyncThing or your own machine in the cloud. Especially if you travel to conferences, like me.

slackfan•52m ago
They couldn't even wipe out everybody's tax bill.

Weak.

etamponi•47m ago
A couple of days ago I received a strange letter from the France tax agency. For context: I received it in my home in Italy, and it was addressed to someone else (perhaps a previous tenant of the house?). It seemed legit but completely misdirected. Or perhaps it was generated from the data in this hack.
jokoon•43m ago
I want to believe this will reveal people who do tax fraud or potentially illegal tax dodging schemes

It's probably the quickest way to punish those people, just regular data leaks from the tax bureau.

I'm probably too optimistic, since this data is probably not admissible in court.

ninjagoo•40m ago
After 3-4 decades of networked compute, is it now fair to say that 'there are two types of organizations in the world: those that have been hacked, and those that know that they have been hacked.'
iandanforth•32m ago
Meanwhile in Norway much of this wouldn't matter because the accessed information would have been public anyway. The non-tax PII is still a loss of course.
travoc•27m ago
We have a certain degree of financial privacy rights in the rest of the world.
LelouBil•31m ago
Website dedicated to public and private data breaches in France : frenchbreaches.com/

For government services, they are getting more and more common, it's scary.

fer•26m ago
I've lived for 10 years in France and virtually all spam I receive is from French leaks (I know due to dedicated addresses), which have kept happening since I left. Bourse des Vols, Free, even Doctolib and my hospital (!), and now this. I simply can't trust French companies, it's an awful anecdotal experience.
idoubtit•8m ago
The post is verbose, but lacks substance:

- The last two sections (≈20% of the article, 5.Cloud and 6.IA) are barely relevant.

- Some comparisons are questionable. It claims that, since some taxes data was compromised, the trust in the national Federated Identity is eroded "as if Facebook Connect was hacked". That's strange, I think it should be "as the trust in Facebook Connect would be eroded when Facebook is hacked". Anyway, I think most people won't care.

- Some sentences make no sense: "Le piratage de Ficoba semble en être l'exemple type"... But "Ficoba" is not mentioned anywhere, and, though I know what the word means, I can't guess what the sentence points to.

The OP should have mentioned another important hack of French national structures that happened in december 2025 and which is well documented. IIRC, through phishing, a keylogger was installed on a teacher's computer. Then the hackers got credentials to an internal training platform for teachers. Then they exploited multiple security breaches and connections between Ministries to get access to the national police files.

lefra•33m ago
French would use "piratage [informatique]" (roughly "digital piracy"). However, "hacker" is used to name the person committing the crime.
triceratops•33m ago
faire l'haque
gregsadetsky•20m ago
In Quebec, the OQLF [0] recommends "bidouilleur" (which I've heard) and "fouineur" (which makes sense, but isn't really common) instead of hacker [1].

Most media outlets will use "pirate informatique" (or just "pirate") when talking about hackers, and "piratage" for hacking. Example: [2]

[0] https://en.wikipedia.org/wiki/Office_qu%C3%A9b%C3%A9cois_de_...

[1] https://vitrinelinguistique.oqlf.gouv.qc.ca/resultats-de-rec...

[2] https://www.lapresse.ca/actualites/justice-et-faits-divers/2...

luxcem•25m ago
"hackée" would be the real anglicisme of hacked. Lot of english words are used like real french verb (-er termination) (hacker, booker, spoiler, manager, etc)
raverbashing•12m ago
Actually they use the term 'piratage'
idbnstra•3m ago
yeah they even used it at the beginning of the article
swader999•5m ago
Is it masculine or feminine?
lwarfield•2m ago
\s Take my angry upvote!

Apple introduces M6 and M5 Ultra for a big leap in performance and AI compute

https://www.apple.com/newsroom/2026/08/apple-introduces-m6-and-m5-ultra-for-a-big-leap-in-perform...
215•interpol_p•52m ago•141 comments

Apple Introduces New Mac Studio with M5 Max and M5 Ultra

https://www.apple.com/newsroom/2026/08/apple-introduces-new-mac-studio-with-m5-max-and-m5-ultra/
136•interpol_p•50m ago•71 comments

US data centers tripled annual water consumption to 17B gallons

https://forgeeks.net/us-data-centers-water-use-17-billion-gallons/
35•kuuuzya•46m ago•29 comments

France's tax agency got hacked (in French)

https://www.cybernetica.fr/piratage-des-impots-comment-en-est-on-arrive-la/
56•zakxxi•1h ago•24 comments

Don't Wordle

https://dontwordle.com/
105•Hbruz0•2h ago•43 comments

Qwen 3.8-Flash-Next releasing tomorrow (125B a6B)

https://modelscope.cn/models/Qwen/Qwen3.8-Flash-Next
57•garo-pro•2h ago•14 comments

HelloAssembly The smallest possible complete Windows application

https://github.com/PlummersSoftwareLLC/HelloAssembly
29•Bluestein•2h ago•22 comments

iCloud+ Hide My Email addresses will remain on icloud.com

https://developer.apple.com/news/?id=1ptvdtcm
534•K7PJP•15h ago•163 comments

OpenAI restores 5-hour Codex and Work limits for ChatGPT Plus users

https://9to5mac.com/2026/08/24/openai-restores-5-hour-codex-and-work-limits-for-chatgpt-plus-users/
45•MC995•1h ago•28 comments

MS Paint and Photos inivisibly watermark even locally generated output with GUID

https://xusheng.dev/posts/reversing/mspaint_invisible_watermark/main/
780•ComputerGuru•22h ago•379 comments

Xiaomi: New CPU matches Apple cores single threaded, much faster multithreaded

https://twitter.com/lemire/status/2091894299289874926
928•tosh•22h ago•664 comments

How Universities Should Prepare Founders

https://paulgraham.com/prepare.html
182•gmays•12h ago•219 comments

SiFive's First Server Platform

https://chipsandcheese.com/p/sifives-first-server-platform
91•geerlingguy•10h ago•24 comments

The state of AI in 2026: On the road to ROI

https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai
7•swolpers•21m ago•5 comments

How Europe is killing makers and micro-entrepreneurs

https://lectronz.com/u/lectronz/articles/how-europe-is-killing-makers-and-micro-entrepreneurs
1495•l-one-lone•1d ago•934 comments

The entire city of San Francisco as a video game

https://sf.thijs.gg/
534•centrosphere•20h ago•155 comments

Moon (2024)

https://ciechanow.ski/moon/
228•simonebrunozzi•15h ago•38 comments

What's new in Emacs 31.1

https://www.masteringemacs.org/article/whats-new-in-emacs-311
251•geospeck•1d ago•49 comments

Bookshelf – Self-hosted eBook library that runs on object storage

https://github.com/murerkinn/bookshelf
133•arbayi•14h ago•50 comments

Where did all the public bathrooms go?

https://daily.jstor.org/where-did-all-the-public-bathrooms-go/
289•herbertl•20h ago•629 comments

Headlong: A Microharness for Persistent Agents

https://www.laude.org/updates/headlong-a-microharness-for-persistent-agents
95•lbw1215•9h ago•39 comments

Vintage Artificial Intelligence: Before It Got Awkward

https://blog.archive.org/2026/08/16/vintage-artificial-intelligence-before-it-got-awkward/
129•signor_bosco•16h ago•24 comments

Peppermint oil reduces blood pressure by 8.48 mmHg in small study

https://journals.plos.org/plosone/article?id=10.1371/journal.pone.0344538
194•brandonb•23h ago•92 comments

Autostep (YC P26) Is Hiring AI/Fullstack Engineers and a Chief of Staff

https://app.dover.com/Autostep/careers/e9510e3b-a854-4e48-9e5d-c89796acaed4
1•adawg4•20h ago

Training AI to Paint with Code

https://surya.website/rling-qwen-to-paint-with-code
136•Tiberium•1d ago•16 comments

Show HN: I wrote a BASIC interpreter that boots on UEFI machines

https://tarjan.itch.io/thoreaubasic
89•Gorsefound•1d ago•31 comments

Was modern art a CIA psy-op? (2020)

https://daily.jstor.org/was-modern-art-really-a-cia-psy-op/
112•neom•12h ago•196 comments

Crafting QR Codes: A deep dive into QR code art (2024)

https://kylezhe.ng/writes/crafting-qr-codes
108•subset•23h ago•11 comments

Walgit – a Git server that is one binary in front of an object store

https://github.com/tobi/walgit
123•matallo•23h ago•42 comments

Jabber/XMPP: 25 Years of Digital Independence

https://gultsch.de/posts/25-years-of-digital-independence/
249•inputmice•22h ago•149 comments