Posted this because it's a solid post-mortem on the recent French tax agency breach, going beyond the headlines into the detection gap, the legal angle, and the broader systemic issues. Quick summary of the key points below (original is in French):
* French tax authority (DGFiP) breach › ~678,000 records leaked, names, tax bracket, reference income, withholding rate
* Detection gap › intrusion spotted and cut off in late June, but the actual data theft wasn't discovered until the stolen data went up for sale on Aug 12, over a month later
* Second breach, same attacker › land registry (cadastre) systems, late July, claimed 2M+ people affected, alleged MFA bypass
* Third incident › French Ministry of Education systems also compromised in late July (staff data since 2001), disclosed quietly with little press coverage
* Legal precedent cited › a 2023 EU Court of Justice ruling (stemming from Bulgaria's 2019 tax agency breach) established that fear of misuse alone counts as damage, and shifts the burden of proof onto the agency to show its security was adequate
* Root cause argument › legacy "trust everything once you're inside" architecture, opposite of zero-trust, extended via remote/VPN access since COVID without redesigning the underlying trust model
* Systemic issue › France's NIS2 transposition law has been stalled in parliament since 2024, partly over a dispute involving encryption backdoor provisions
* Broader angle › piece also covers AI's growing role on the offensive side of cybersecurity, and the US scaling back international cyber-cooperation efforts through 2025–2026
> Broader angle › piece also covers AI's growing role on the offensive side of cybersecurity, and the US scaling back international cyber-cooperation efforts through 2025–2026
I was wondering how they would find a way to blame the United States.
It's a big mess in schools now, the whole messenging system is down as a preventive measure so the only way they can communicate (between each other, to parents, etc) is by phone.
And kids are back to school in one week.
* Root cause argument › legacy "trust everything once you're inside" architecture, opposite of zero-trust, extended via remote/VPN access since COVID without redesigning the underlying trust model
How many workplaces have I seen like this? A tale as old as IT.