Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

71% Positive

Analyzed from 1880 words in the discussion.

Trending Topics

#french#data#tax#trust#found#since#france#nice#lost#hacked

Discussion (52 Comments)Read Original on HackerNews

ChrisArchitect•about 3 hours ago
idoubtit•about 4 hours ago
The post is verbose, but lacks substance:

- The last two sections (≈20% of the article, 5.Cloud and 6.IA) are barely relevant.

- Some comparisons are questionable. It claims that, since some taxes data was compromised, the trust in the national Federated Identity is eroded "as if Facebook Connect was hacked". That's strange, I think it should be "as the trust in Facebook Connect would be eroded when Facebook is hacked". Anyway, I think most people won't care.

- Some sentences make no sense: "Le piratage de Ficoba semble en ĂŞtre l'exemple type"... But "Ficoba" is not mentioned anywhere, and, though I know what the word means, I can't guess what the sentence points to.

The OP should have mentioned another important hack of French national structures that happened in december 2025 and which is well documented. IIRC, through phishing, a keylogger was installed on a teacher's computer. Then the hackers got credentials to an internal training platform for teachers. Then they exploited multiple security breaches and connections between Ministries to get access to the national police files.

dolmen•about 4 hours ago
> t claims that, since some taxes data was compromised, the trust in the national Federated Identity is eroded "as if Facebook Connect was hacked". [... ] Anyway, I think most people won't care.

The taxes services is one of the oldest online government service in France that has existed, with a very wide usage.

As people had already that authentication as an identity provider, it was natural to reuse that authentication (not the password, but 3rd party auth Ă  la OAuth, but a french government standard) to authenticate to government services that went online later.

So if the taxes auth is compromised (so far I haven't seen enough details about the coverage of the leak), that's a real concern.

ninjagoo•about 5 hours ago
After 3-4 decades of networked compute, is it now fair to say that 'there are two types of organizations in the world: those that have been hacked, and those that know that they have been hacked.'
penr0se•about 5 hours ago
"got hacked (in French)".

Got hacqued.

luxcem•about 5 hours ago
"hackĂŠe" would be the real anglicisme of hacked. Lot of english words are used like real french verb (-er termination) (hacker, booker, spoiler, manager, etc)
tgv•about 4 hours ago
I've never had such a linguistic double take after hearing a colleague, who grew up in France, tell me that Nike's or Adidas' billboards in France say: "Le leader en sportswear", pronounced as if it contained four French words (lee-dayr, spĂ´rt-swear, stress on the final syllable in both cases).
1-more•about 2 hours ago
In Russian the word for train is poezd, and the prepositional form is poezdje, so you say "I am on the train" "ya v poezdje" (Russian has no articles and drops the copula when it carries no information, so word for word it's "I on train.") One of my friends once told her mom on the phone "ya v trenje" meaning that she took the word "train," pronounced it as though it were a native Russian word "tren", and added the typical masculine inanimate prepositional ending to it. Kinda funny.
jjgreen•about 4 hours ago
My favourite (heard in a bar in Paris): On y go ?
raverbashing•about 4 hours ago
Actually they use the term 'piratage'
idbnstra•about 4 hours ago
yeah they even used it at the beginning of the article
lwarfield•about 4 hours ago
\s Take my angry upvote!
ChrisRR•about 4 hours ago
'acked
kergonath•about 4 hours ago
That could be cockney, though.
swader999•about 4 hours ago
Is it masculine or feminine?
debo_•about 5 hours ago
I lol'ed, but I imagine outside of Quebec the French probably just use the English word "hacking" when referring to a computer hack.
gregsadetsky•about 5 hours ago
In Quebec, the OQLF [0] recommends "bidouilleur" (which I've heard) and "fouineur" (which makes sense, but isn't really common) instead of hacker [1].

Most media outlets will use "pirate informatique" (or just "pirate") when talking about hackers, and "piratage" for hacking. Example: [2]

[0] https://en.wikipedia.org/wiki/Office_qu%C3%A9b%C3%A9cois_de_...

[1] https://vitrinelinguistique.oqlf.gouv.qc.ca/resultats-de-rec...

[2] https://www.lapresse.ca/actualites/justice-et-faits-divers/2...

lefra•about 5 hours ago
French would use "piratage [informatique]" (roughly "digital piracy"). However, "hacker" is used to name the person committing the crime.
madcaptenor•about 3 hours ago
I would think the person committing piratage would be called a pirate.
9dev•about 5 hours ago
ordinateur-ed
EGreg•about 5 hours ago
I once accidentally left my backpack in Nice’s tram, containing mon ordinateur principal. I was flying to Balaji’s Network State conference in Singapore and had no time to go back. I did get ahold of a tram operator and another tram operator had found it at the end of the line. I had left my whatsapp number for her and had to run.

While in Singapore I was able to get ahold of some policeman who made some calls and was told it was waiting for me at the Lost and Found inside the Nice airport gift shop. I thanked him and made 24 hour layover in Nice.

Well, getting to the airport, I came tk this shop. I asked about the “sac a dos gris” in the other room. They checked their ordinateur: “NO, je suis desolee”. Sorry sir! I said you definitely have it, can you please go to that other room and check? “No sorry we cannot. It is not here. After a week we give things to the municipal lost and found. At the polics station. Go there.”

The day was ending (French govt services work til 4pm) so I raced to the municipal police station in Nice. I arrive and they have a bunch of keys and other things people lost around the city. I barely speak French but luckily a middle-aged lady was there who spoke good English. She helped me ask them. “No. Sorry. It is not here.” Are they sure? “Yes, we checked. Not here.”

She gave me a ride on her vespa (she had a motorcycle) and I treated her to dinner while we discussed the situation. We agreed I should go to the central police station after that and file a missing item report. Which I did (spoiler alert: doesn’t do anything, but standing in line is less than in US cities).

That night I chose to stay at some rinkydink place in Nice, because why not (I was by myself) and got up around 4am to take the bus to the tram network’s lost and found — the last place it could be. I would have aittle time before my flight.

In the morning I got up early and got to that Lost and Found, before my flight. I had one hour. It was located near a university, and after wandering around I had found the little enclave. The staff there were very nice — but they didn’t have it either!

I flew home, dejected. My backups hadn’t been perfect; I had a lot of stuff on that computer, including an iOS App on XCode that I had to release to a lot of people! (And a couple Metamask wallets.)

Anyway I kept in touch with the nice policeman throughout. He went to the airport lost and found - the same one which refused to check the other room because their computer said it wasn’t there — and CONFIRMED that my bag was there. They had let him check the back room, you see!

But I wasn’t in Nice anymore. I filled out a “troov.com” report and explained where it was. They had found it! Paid for FedEx. Over the next few days thanks to the Tracking I saw it go to the central station in France and then sent back. Because it was missing a customs form for USA. I had filled out that form, but something had been wrong. I had spoken to the main FedEx customs-facing team in Memphis for a few days, and they thought it was in USA already. They were wrong. Their system was also blind to this. Anyway, I saw it go back to that airport lost and found, a week later. Lost about $100…

Then, the lady offered to come pick it up for me. She came, and was thankfully given this bag. She mailed it with DHL, and I received it. It was really overjoyed when it finally arrived, a month and a half after I had lost it! I of course sent the lady a payment to cover the cost. She did not want any other compensation. We are still friends to this day, and when my dad goes to France, I am putting them in touch.

One moral from this story is: French employees love to say “No” to anything and everything. If their computer says the thing isn’t there, they won’t budge even when it’s the easiest thing to just check the other room manually. Unless you are a local policeman!

The other moral - back up your stuff! Have SyncThing or your own machine in the cloud. Especially if you travel to conferences, like me.

triceratops•about 5 hours ago
faire l'haque
dmbche•about 4 hours ago
"Ce scÊnario n'est pas thÊorique, il a dÊjà eu lieu. En octobre 2025, la FÊdÊration française de tir se fait voler les donnÊes de près d'un million de licenciÊs et d'anciens licenciÊs : Êtat civil, adresse postale, tÊlÊphone, numÊro de licence.

Les mois suivants, des individus se prĂŠsentent au domicile de licenciĂŠs en se faisant passer pour des policiers ou des gendarmes, parfois en tenue, pour se faire remettre des armes. Des vols sont constatĂŠs Ă  Nice, Ă  Paris, Ă  Limoges, Ă  DĂŠcines."

Sounds like a far fetched movie!

goobatrooba•about 2 hours ago
Wow, indeed rare that hacks result in real-life visits, and here even specifically to pretend-confiscate weapons. That's a well-plannee (or excellently opportunist) coup.
bronks•about 2 hours ago
I wrote this article and I found the comments funny. I have an updated version in English here : https://www.linkedin.com/posts/tariqkrim_french-tax-authorit...
LelouBil•about 5 hours ago
Website dedicated to public and private data breaches in France : frenchbreaches.com/

For government services, they are getting more and more common, it's scary.

iandanforth•about 5 hours ago
Meanwhile in Norway much of this wouldn't matter because the accessed information would have been public anyway. The non-tax PII is still a loss of course.
idoubtit•about 4 hours ago
I'm surprised. The stolen data had two parts: some relevant to the income taxes paid, some detailing the real estate (houses and lands) owned by the household. Are both of them public in Norway?

Anyway, the main problem is that the breaches into the many French national data stores seem increasingly frequent.

travoc•about 5 hours ago
We have a certain degree of financial privacy rights in the rest of the world.
Kinrany•about 4 hours ago
What's the purpose of privacy when it comes to taxes and real estate?
pydry•about 4 hours ago
Protecting oligarchy, mostly.

Those same countries that treat financial privacy as axiomatic are trying their best to undermine chat encryption and would throw ed Snowden in prison given half a chance.

fer•about 5 hours ago
I've lived for 10 years in France and virtually all spam I receive is from French leaks (I know due to dedicated addresses), which have kept happening since I left. Bourse des Vols, Free, even Doctolib and my hospital (!), and now this. I simply can't trust French companies, it's an awful anecdotal experience.
etamponi•about 5 hours ago
A couple of days ago I received a strange letter from the France tax agency. For context: I received it in my home in Italy, and it was addressed to someone else (perhaps a previous tenant of the house?). It seemed legit but completely misdirected. Or perhaps it was generated from the data in this hack.
jokoon•about 5 hours ago
I want to believe this will reveal people who do tax fraud or potentially illegal tax dodging schemes

It's probably the quickest way to punish those people, just regular data leaks from the tax bureau.

I'm probably too optimistic, since this data is probably not admissible in court.

fhdkweig•about 2 hours ago
A similar hack created The Panama Papers. Not much came from those either. Like the Epstein Files, it may make for interesting reading, but I don't expect much legal action.

https://en.wikipedia.org/wiki/Panama_Papers

Advertisement
sunshine-o•about 2 hours ago
I believe that we established all those government systems are fairly easy to hack. I remember some French military naval construction network got owned about a year ago, much worst in a sense.

My guess is since a global conflict is ramping up this is only the beginning and we are about to see some real damage.

It is fairly easy to create chaos in a country for a few weeks if you start disrupting the grid, payments or internet access.

lucabytheway•about 3 hours ago
i think we are on the verge of some serious event that will affect the whole ai industry.
slackfan•about 5 hours ago
They couldn't even wipe out everybody's tax bill.

Weak.

poulpy123•about 3 hours ago
I mean, which official service has not been hacked now ?
zakxxi•about 5 hours ago
Posted this because it's a solid post-mortem on the recent French tax agency breach, going beyond the headlines into the detection gap, the legal angle, and the broader systemic issues. Quick summary of the key points below (original is in French):

* French tax authority (DGFiP) breach › ~678,000 records leaked, names, tax bracket, reference income, withholding rate

* Detection gap › intrusion spotted and cut off in late June, but the actual data theft wasn't discovered until the stolen data went up for sale on Aug 12, over a month later

* Second breach, same attacker › land registry (cadastre) systems, late July, claimed 2M+ people affected, alleged MFA bypass

* Third incident › French Ministry of Education systems also compromised in late July (staff data since 2001), disclosed quietly with little press coverage

* Legal precedent cited › a 2023 EU Court of Justice ruling (stemming from Bulgaria's 2019 tax agency breach) established that fear of misuse alone counts as damage, and shifts the burden of proof onto the agency to show its security was adequate

* Root cause argument › legacy "trust everything once you're inside" architecture, opposite of zero-trust, extended via remote/VPN access since COVID without redesigning the underlying trust model

* Systemic issue › France's NIS2 transposition law has been stalled in parliament since 2024, partly over a dispute involving encryption backdoor provisions

* Broader angle › piece also covers AI's growing role on the offensive side of cybersecurity, and the US scaling back international cyber-cooperation efforts through 2025–2026

INTPenis•about 5 hours ago
* Root cause argument › legacy "trust everything once you're inside" architecture, opposite of zero-trust, extended via remote/VPN access since COVID without redesigning the underlying trust model

How many workplaces have I seen like this? A tale as old as IT.

ericmay•about 4 hours ago
> Broader angle › piece also covers AI's growing role on the offensive side of cybersecurity, and the US scaling back international cyber-cooperation efforts through 2025–2026

I was wondering how they would find a way to blame the United States.

fakedang•about 4 hours ago
Quintessentially French.
eloisant•about 5 hours ago
It's a big mess in schools now, the whole messenging system is down as a preventive measure so the only way they can communicate (between each other, to parents, etc) is by phone.

And kids are back to school in one week.