Europe

Hackers claim sale of stolen French tax data for thousands of euros

Published

on

ZeroBytes, the cybercriminal group claiming to be a French duo behind a massive data theft targeting France’s General Directorate of Public Finances (DGFiP), claimed they have sold the stolen data.

The group, already known for previous cyberattacks, claimed in a statement to AFP on Monday that they sold the stolen files to “two people” in exchange for “several thousand euros”.

Refusing to provide details regarding the identity of the buyers, the group said, “The data is still for sale”, noting that the same database could be copied and transferred to multiple clients.

ZeroBytes maintains that they consist of two hackers who describe themselves as French.

AFP contacted the group via Telegram using contact information shared on a dark web forum dedicated to the sale of stolen data. When asked about their motives, the group stated, “I think apart from money,” they had no specific motivation.

Rich data source for fraudsters

The French General Directorate of Public Finances confirmed on August 14 two separate unauthorized access incidents that occurred at the end of June and the end of July, resulting in the theft of information belonging to at least 678,000 individual and corporate taxpayers, as well as approximately 200,000 accounts in cadastre records.

The tax information stolen from individual taxpayers includes first and last names, reference tax income, family quotient, and withholding tax rate.

According to the DGFiP, data belonging to corporate taxpayers is of a “less sensitive” nature. A sample examined by AFP showed a predominance of information belonging to small and medium-sized enterprises, including a subsidiary of a major French automotive supply company.

The details contained in these records are raising concerns over targeted fraud.

In the cybercrime economy, the hacker who infiltrates a system is generally not the person who uses this information directly; stolen databases are mostly sold to fraud specialists.

Remote access connection exploited

ZeroBytes claimed that to carry out the first attack, they gained access to a Virtual Private Network (VPN) used by tax office personnel.

This virtual private network allows agency employees to connect remotely and securely to the administration’s internal tools.

According to the group, the hackers managed to extract approximately 680,000 lines of data through this access before financial authorities severed the connection.

The second cyberattack, launched at the end of July, targeted the Server of Professional Cadastral Data (SPDC), which provides access to property ownership information.

In a statement on Friday, the DGFiP acknowledged that it had been subjected to an attack that was “more complex” compared to previous ones.

Sebastien from the specialized website FrenchBreaches, which published the initial technical findings regarding the incident, told AFP that he found the group’s profile entirely credible.

According to Sebastien, the system intrusion points to “a potential vulnerability of the DGFiP” rather than a technical achievement. Sebastien also questioned why no system alert appeared to have been triggered despite the extraction of hundreds of thousands of lines of data.

DGFiP Director General Amelie Verdier expressed her reaction in a press statement on Friday, stating, “We are facing someone who is clearly playing games by releasing information piece by piece.”

Hackers’ past attack record

Before targeting the tax administration, ZeroBytes had claimed responsibility on dark web forums for cyberattacks targeting the supermarket chain Intermarche and the French Handball Federation.

The group also claimed to have stolen data during the summer period from a major French telephone operator and a hotel group; however, these two attacks were not confirmed by the companies involved.

French institutions frequently appear on target lists in the forums where stolen data is sold. ZeroBytes explained their decision to focus on France by stating that these institutions are “easy to hack”.

The Paris Prosecutor’s Office opened a judicial investigation into the incident, primarily on charges of “unauthorized data extraction” and “forming a criminal association to commit a crime”.

Prime Minister Sebastien Lecornu convened an interministerial crisis meeting. Under the investigation, the hackers face up to seven years in prison for the offense of “unauthorized data extraction”.

Plans were made to contact the 678,000 taxpayers affected by the cyberattack individually starting Monday to warn them against potential targeted fraud attempts.

MOST READ

Exit mobile version