The data breach affecting 678,000 taxpayers is more of a political issue than a technical one

The data of 678,000 French taxpayers and approximately 200,000 accounts in stolen property registry files! The DGFiP scandal is causing quite a stir. “Technical debt” accounts for much of this failure, as does the stalling of the NIS2 law. A real lesson.

The scandal is causing quite a stir. And for good reason. The “always more” policy—without sufficient resources allocated to security—will come at a high cost. For the Solidaires Finances Publiques union, the current crisis deserves better than outcries and demagogic promises. These come from those who have played a major role in creating this situation by consistently voting for budget cuts in the name of the sacrosanct reduction of public spending…

SWhile it is clear that there is no such thing as zero risk, the size of the technical debt poses a problem. This is reportedly evident in this government agency, as it is in others. According to the consulting firm Gartner, local governments and public institutions spend well over half of their IT budgets on maintaining their information systems. This is more than in any other sector.

Public administrations: prime targets for hackers

The explanation? Financial, but not solely so. For the most part, public information systems were built very early on with a vast array of applications, features, services, and inter-application exchanges. A public agency may have as many as 200 different business functions, each with its own IT requirements. Not to mention that every institution interacts with numerous government departments, ministries, regional councils, or agencies—which adds another layer of complexity.

In its “Roadmap for Priority Efforts in Government Cybersecurity 2026–2027,” ANSSI acknowledges that ministries have still not rolled out multi-factor authentication across the board for access to their information systems. Specifically, this is a target for “high-stakes” information systems by February 2027, and for all systems by February 2028.

Technical debt: debt… with interest!

A study by the IBM Institute for Business Value shows that organizations that fully account for the cost of managing technical debt in their profitability analyses generate a 29% higher ROI than those that do not. The logic also works the other way around: ignoring technical debt leads to an 18% to 29% drop in ROI. This is, of course, without even considering the issue of cybersecurity.

Technical debt management is often viewed as an engineering problem. But it is also a cultural issue, according to IBM.

Just like financial debt, technical debt accrues interest. And this interest can quickly spiral out of control if not managed properly. Technical debt will therefore hinder digital performance. And, as a result, it will weigh on an organization’s evolution, future costs, and the value of its technology assets.

The Transposition of the NIS2 Directive Hampered by a “Parliamentary Delay”

In addition to technical debt, let’s mention the “delay” regarding NIS2. The bill intended to strengthen the French government’s cybersecurity has never been debated on the floor of the National Assembly. Adopted by the Senate on March 12, 2025, and forwarded to the National Assembly the following day, it was reviewed for six months by a special committee. The report was submitted on September 10, 2025. It has been waiting ever since!

Eleven months later, as the DGFiP announced the theft of tax data from 678,000 taxpayers and Prime Minister Sébastien Lecornu convened an interministerial crisis task force, the bill still had not been placed on the agenda for a public session. The reason? Officially, a “delay in the parliamentary schedule.”

If the law had been enacted, the DGFiP would have been officially classified as an “essential entity.” This would have subjected it to much stricter security requirements and controls

Virtual threats, physical risks…

From a cyberattack, we’ve moved on to a political issue. Clearly, this affair is eroding the bond of trust between the state and its citizens. In fact, how can citizens still place their trust in government agencies that fail to follow “basic cybersecurity hygiene”? Above all, how can they accept that the digitization of public services and data collection continue as if nothing had happened?

Not to mention that for taxpayers—especially the wealthiest—the danger—today—is not merely virtual; it could become physical. The stolen file contains nearly 27,000 tax returns exceeding 100,000 euros, including, in addition to first and last names, specific details. Specifically: family quotient, taxable income, and withholding tax rate. The sample analyzed by FrenchBreaches based on the data claimed by the hacker also contains the address, phone number, email address, and number of dependents…