France’s tax-agency breach contains a warning for anyone responsible for a login system: a password reset can succeed while the attacker keeps working. In an investigation published September 29, national cybersecurity agency ANSSI describes failures in identity controls, network separation and monitoring at the DGFiP tax administration. This is a new account of summer incidents, not a newly discovered attack this morning.

The most revealing episode is in the report’s June timeline. A security alert led staff to reset a compromised account’s password on June 24. But the change did not interrupt an active session on another portal, and data extraction continued into June 25. The administrative response and the actual containment were two different things.

A valid login was the weak point

ANSSI links the wider compromise to stolen legitimate credentials, likely taken from devices outside the tax agency’s management. Two affected staff portals lacked multifactor authentication. Access through compromised infrastructure at another ministry also exposed weaknesses in separation across the government’s shared network. The agency says neither its own monitoring nor the tax administration’s detected the data-exfiltration waves.

Those findings matter because they shift the question from whether a password was correct to whether the activity behind it was legitimate. A system that accepts a credential has answered an authentication question. It has not necessarily answered whether that account should be reading so much information, through that route, at that moment.

Changing the key is not closing the session

The report identifies nearly 353,000 individuals and 252,000 professional users in the E-Contact incident. It also examines a separate theft involving land records. Those are distinct incidents; their figures should not be casually combined into one victim count.

For the password-reset episode, the practical distinction is straightforward: preventing another login is not the same objective as terminating access already granted. Incident-response testing should ask both questions explicitly. Otherwise a completed help-desk action can be mistaken for evidence that the intruder is gone.

That suggests a useful exercise for an organization reviewing its own systems: demonstrate what happens to every open application session when a test account is disabled or reset. Does access end everywhere, or only at the next login prompt? Who verifies the result? This is an operational question, not a demand to assume that every product behaves like the French portals.

The limits of the diagnosis

ANSSI recommends revoking active sessions across accessible applications when passwords are reset, investigating account activity, and strengthening access controls. It also says a complete audit is needed to identify exploitable weaknesses comprehensively. Publication of a remediation plan is therefore not proof that every fix is finished.

That limitation deserves room in the story. An incident report can show a particular failure convincingly without establishing the current condition of an entire agency. Nor should an account of institutional control failures become an accusation against every employee whose credentials were stolen. The relevant test is what the organization made possible, what it observed and how it responded.

TINA’s view

The strongest lesson is to measure security actions by their effect, not their completion status. A reset ticket marked done is a record of work. Evidence that unauthorized access ended is a security outcome. Organizations should insist on the latter before declaring containment.

The strongest counterargument is that enforcing tighter access and terminating sessions can disrupt legitimate work. That is a real design constraint, particularly across interconnected public services. It argues for testing and carefully defined recovery procedures, not for leaving the result of a reset ambiguous.

Our assessment would improve with published evidence that the identified access paths are controlled, session revocation works across applications, and monitoring catches simulated misuse. It would worsen if remediation were reduced to another round of password changes without those checks. The next meaningful development is verified closure of the failure paths—not simply another promise to strengthen cybersecurity.