In June, someone sat down at France’s tax administration the way a clerk would. They had staff passwords. They pulled records on hundreds of thousands of taxpayers and businesses, then they kept going into July. The agency did not see the data leave. Neither did ANSSI. France’s national cybersecurity shop later called the operation unsophisticated. That is the part that should stick with you: for seven weeks, the country’s tax files walked out through a login that already worked.

A clerk session that lasted all summer
You know this pattern from your own logs. A staff account authenticates. Queries run. Files move. Your firewall records a session. Your threat-protection stack stays quiet because nothing looks like malware. If the password was stolen rather than guessed live, you may not even get a brute-force spike to explain later. The French case is that pattern at national scale, and the dwell time is the insult. Seven weeks is enough to copy, recopy, and walk the same corridors again while everyone waits for a louder alarm.
ANSSI’s Tuesday report, published in French, is blunt about the tradecraft. The attacker used stolen staff passwords. The haul covered taxpayers and businesses. Detection failed on the way out. You can spend a week arguing whether those passwords came from phishing, reuse, or an infostealer dump. The operational fact is simpler. Bulk export of crown-jewel records looked like ordinary work. Your incident response plan probably still opens on malware, command-and-control, or a perimeter exploit. This incident would have sat in the authorized-user bucket until a journalist or a regulator asked why the files were gone.
That is a cyber security failure you can reproduce in any shop that treats a successful login as the end of the trust decision. Tax files, HR dumps, finance extracts, patient exports: same shape. The identity is the tool. The export is the crime. The SIEM is waiting for a signature that never arrives. This is a bad look for a tax authority, and it is a worse look if your board still thinks “we have MFA somewhere” counts as a control.
The path ran through a trusted login
The same week, Microsoft walked through how Storm-3068 turned a compromised identity into broader cloud access. The identity opened pipelines and infrastructure. That was the prize, the actual keys to the kingdom. France’s tax theft and that cloud path rhyme even if the actors do not. Steal a principal people already trust. Use it the way a tired employee would. Expand. Leave without tripping the controls that only watch unauthenticated noise.
Cisco Talos used the same keys-to-the-kingdom language to launch Executive Threat Detection, a retainer aimed at hunting around high-value IT assets. You don’t need their SKU to hear the market. Vendors are packaging dedicated hunts for executives, identity planes, and the systems those people can touch because commodity detections keep missing quiet, privileged work. If your threat detection program still spends most of its budget on endpoint malware and north-south firewall denies, you’re staffed for last year’s ticket queue.

Read those stories next to the French export and the posture question gets rude. Who in your tenant can pull hundreds of thousands of records in a single role? Which of those accounts still live on a password plus a VPN? Which bulk jobs have a destination allowlist? Defense in depth that stops at the login screen is a slogan you’ve been reciting in audits. The French tax files left after that slogan had already been satisfied. Someone had credentials. The rest was patience.
Cybersecurity that starts after the login succeeds
Do the ugly inventory this week. List every human and service identity that can run a bulk export of customer, citizen, payroll, or financial data. Count the ones that still live on password plus VPN. Kill shared staff logins. Rotate anything you cannot kill today, then put phishing-resistant MFA on every remaining account in that set. Pull 90 days of authentication and query logs for those identities and look for concurrent sessions, odd hours, new source IPs, and query volumes that dwarf the person’s baseline. That hunt is your immediate incident response, even if nobody has opened a ticket.
On internet-facing admin and staff portals, stop treating repeated failures as background radiation. Rate-limit logins. Autoban source IPs that hammer authentication, the ipban pattern operators have used for years on mail and remote desktop. If you already run IPBan Pro on those edges, keep it there as a brute-force brake. A stolen password that works on the first try will never trip a ban list, so pair it with alerts on successful logins from new geographies and new devices. Security hardening here is boring on purpose: disable unused admin interfaces, bind management to a jump path, and make the staff portal refuse legacy auth protocols.
Then change what “detected” means. Alert on export volume, destination, and after-hours staff-pattern breaks, not only on malware. Feed your threat-protection stack identity and data-access signals, not just file hashes. Your firewall should log who talked to the export store, and a human should read those logs when volume jumps. Ongoing work looks like quarterly access reviews, canary records in sensitive tables, and a tabletop where the inject is a real account and a quiet SIEM. That’s defense in depth you can operate without buying a new logo.
Your next quiet week is already booked
France had a national agency, a tax authority, and seven weeks of silence. You have a helpdesk that resets passwords for people who sound busy, and a dashboard that turns green when logins succeed. The next time someone calls identity monitoring “executive hunting theater,” hand them the dwell time. Staff passwords, a working session, and a silent export will beat a lot of tools you already paid for. Hunt the work those accounts can do, or you’ll learn about the copy the same way Paris did: after the files are gone.
Sources
- French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
- Beyond source code: A path to the keys to the kingdom
- Securing the keys to the kingdom: Announcing Executive Threat Detection
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
