Summary
- Attackers used credentials belonging to a DGFiP employee and an authorised third party to access tax systems during June and July.
- The breach exposed fiscal and property information concerning 678,000 individuals and businesses, although taxpayer passwords were not compromised.
- France now plans to use AI tools to find vulnerabilities while favouring sovereign suppliers such as Mistral and excluding OpenAI from that work.
France is preparing to use domestically supplied artificial intelligence to search government services for cyber vulnerabilities after attackers used compromised credentials to extract tax information concerning 678,000 individuals and businesses. The response turns France’s long-running argument for greater technological sovereignty into an operational security decision, with Budget Minister David Amiel naming Mistral as an example of the suppliers the state could use while explicitly excluding OpenAI.
The Direction générale des Finances publiques, or DGFiP, said the unauthorised activity took place during June and July using the credentials of one of its employees and an authorised external party. Investigations conducted after an attacker claimed responsibility in August found that the access had been used to consult and extract information before the relevant accounts were blocked.
The compromised records included fiscal information such as reference tax income, household quotient, and withholding-tax rates, as well as company information including business names and SIREN identifiers. Property addresses and surface areas were also accessed, although DGFiP says its public taxpayer portals were not compromised and that passwords belonging to individual and professional users were not stolen.
The route into the systems is as important as the number of records because the attack did not depend on breaking the citizen-facing login service. Instead, legitimate credentials associated with people already authorised to use internal systems gave the attackers access to information behind the public interface, exposing the difference between protecting customer accounts and controlling privileged access throughout a large organisation.
Sovereign AI moves into security procurement
France has spent years pressing for greater European control over cloud computing, artificial intelligence, and other strategic technologies, but the tax breach gives that policy a direct operational application. Amiel said the government intends to use AI systems to identify weaknesses across its services and will favour sovereign suppliers, explicitly citing French model developer Mistral.
Security analysis is an unusually sensitive use case because vulnerability-scanning systems may need access to software, architecture, configuration, or operational information that an administration would not normally expose to a general-purpose external AI service. Procurement therefore has to address where data is processed, which personnel can see it, how models retain information, what logs are created, and which jurisdiction ultimately governs the provider.
Choosing a domestic supplier can reduce some concerns around strategic dependency and legal jurisdiction without proving that the resulting system is effective or secure. A sovereign product still needs testing, access controls, auditability, and a clear operating model determining what happens when it identifies a weakness.
Meanwhile, the original breach leaves conventional identity controls firmly in view. DGFiP had introduced two-factor authentication for individual taxpayer accounts before the attack, but stronger citizen authentication did not prevent compromised employee and third-party credentials being used elsewhere in the environment.
AI can find problems faster than organisations can fix them
Automated security analysis can help large public administrations inspect code, configuration, and service exposure more quickly than a small specialist team could manage manually. Yet increasing the speed of discovery can produce a second bottleneck if security teams suddenly face hundreds or thousands of findings across applications accumulated over many years.
Government systems frequently combine modern digital services with older back-office applications, external suppliers, specialist databases, and integrations whose dependencies are difficult to change without affecting public services. A tool that discovers a vulnerable component does not remove the need to identify its owner, test a fix, schedule the change, and confirm that remediation has not broken something else.
The DGFiP incident also demonstrates why access architecture deserves equal attention. Privileged staff accounts, contractor credentials, service accounts, and administrative tools can bypass the protections visible to the public, leaving security dependent on authentication strength, permission design, monitoring, and rapid revocation when an identity is compromised.
Tax information presents an additional problem because much of it cannot easily be changed after a breach. Passwords can be reset, but income history, company identifiers, property details, and other contextual information can remain useful to criminals attempting targeted phishing or impersonation long after the compromised account has been secured.
France’s planned AI programme will therefore be judged by the remediation it produces rather than the sophistication of the models involved. The administration needs to identify weaknesses without exposing more sensitive data in the process, then translate the resulting findings into changes across identity, software, suppliers, and system architecture.
The breach began through compromised authorised access rather than an exotic attack on an AI system, which keeps the policy grounded in a familiar cyber problem. France may use sovereign AI to search for vulnerabilities, but the incident that triggered the programme shows that the effectiveness of public-sector security still depends on the less glamorous work of deciding who can reach sensitive systems, how that access is monitored, and how quickly it can be removed when trust fails.












