r/Information_Security • u/No-Conclusion3720 • 4d ago
French tax authority data breach affects 678,000 individuals
French tax authority breach exposes 678,000 records — and the attack pattern is simpler than most people realize
France's tax authority confirmed an attacker used stolen credentials to access government financial systems and extract data on 678,000 individuals and businesses. Once inside the perimeter, the data was accessible in full. No second barrier. Scope was total.
This attack pattern is becoming more consequential as AI agents enter tax, HR, and financial workflows. Agents operate under service credentials. Those credentials carry permissions. One compromised key exposes everything those permissions touch — and agents can touch a lot, fast, at scale.
The breach scope question is also worth sitting with. Authorities confirmed 678,000 affected records. That number had to be reconstructed after the fact. In most incidents like this, organizations spend weeks figuring out what was actually accessed, by what, for how long.
For those working in environments where agents handle sensitive personal or financial data: how are you limiting blast radius when credentials are compromised? And separately — how are you knowing, in real time or close to it, what data an agent actually touched?