37 comments

[ 0.25 ms ] story [ 34.7 ms ] thread
[flagged]
* Root cause argument › legacy "trust everything once you're inside" architecture, opposite of zero-trust, extended via remote/VPN access since COVID without redesigning the underlying trust model

How many workplaces have I seen like this? A tale as old as IT.

It's a big mess in schools now, the whole messenging system is down as a preventive measure so the only way they can communicate (between each other, to parents, etc) is by phone.

And kids are back to school in one week.

> Broader angle › piece also covers AI's growing role on the offensive side of cybersecurity, and the US scaling back international cyber-cooperation efforts through 2025–2026

I was wondering how they would find a way to blame the United States.

"got hacked (in French)".

Got hacqued.

"hackée" would be the real anglicisme of hacked. Lot of english words are used like real french verb (-er termination) (hacker, booker, spoiler, manager, etc)
I've never had such a linguistic double take after hearing a colleague, who grew up in France, tell me that Nike's or Adidas' billboards in France say: "Le leader en sportswear", pronounced as if it contained four French words (lee-dayr, spôrt-swear, stress on the final syllable in both cases).
My favourite (heard in a bar in Paris): On y go ?
Bet ya un pain au chocolat you heard that in the Marais, where les peoples hang out :D
Actually on the Rue du Faubourg-Saint-Denis
In Russian the word for train is poezd, and the prepositional form is poezdje, so you say "I am on the train" "ya v poezdje" (Russian has no articles and drops the copula when it carries no information, so word for word it's "I on train.") One of my friends once told her mom on the phone "ya v trenje" meaning that she took the word "train," pronounced it as though it were a native Russian word "tren", and added the typical masculine inanimate prepositional ending to it. Kinda funny.
They couldn't even wipe out everybody's tax bill.

Weak.

A couple of days ago I received a strange letter from the France tax agency. For context: I received it in my home in Italy, and it was addressed to someone else (perhaps a previous tenant of the house?). It seemed legit but completely misdirected. Or perhaps it was generated from the data in this hack.
I want to believe this will reveal people who do tax fraud or potentially illegal tax dodging schemes

It's probably the quickest way to punish those people, just regular data leaks from the tax bureau.

I'm probably too optimistic, since this data is probably not admissible in court.

After 3-4 decades of networked compute, is it now fair to say that 'there are two types of organizations in the world: those that have been hacked, and those that know that they have been hacked.'
Meanwhile in Norway much of this wouldn't matter because the accessed information would have been public anyway. The non-tax PII is still a loss of course.
I'm surprised. The stolen data had two parts: some relevant to the income taxes paid, some detailing the real estate (houses and lands) owned by the household. Are both of them public in Norway?

Anyway, the main problem is that the breaches into the many French national data stores seem increasingly frequent.

I've lived for 10 years in France and virtually all spam I receive is from French leaks (I know due to dedicated addresses), which have kept happening since I left. Bourse des Vols, Free, even Doctolib and my hospital (!), and now this. I simply can't trust French companies, it's an awful anecdotal experience.
The post is verbose, but lacks substance:

- The last two sections (≈20% of the article, 5.Cloud and 6.IA) are barely relevant.

- Some comparisons are questionable. It claims that, since some taxes data was compromised, the trust in the national Federated Identity is eroded "as if Facebook Connect was hacked". That's strange, I think it should be "as the trust in Facebook Connect would be eroded when Facebook is hacked". Anyway, I think most people won't care.

- Some sentences make no sense: "Le piratage de Ficoba semble en être l'exemple type"... But "Ficoba" is not mentioned anywhere, and, though I know what the word means, I can't guess what the sentence points to.

The OP should have mentioned another important hack of French national structures that happened in december 2025 and which is well documented. IIRC, through phishing, a keylogger was installed on a teacher's computer. Then the hackers got credentials to an internal training platform for teachers. Then they exploited multiple security breaches and connections between Ministries to get access to the national police files.

> t claims that, since some taxes data was compromised, the trust in the national Federated Identity is eroded "as if Facebook Connect was hacked". [... ] Anyway, I think most people won't care.

The taxes services is one of the oldest online government service in France that has existed, with a very wide usage.

As people had already that authentication as an identity provider, it was natural to reuse that authentication (not the password, but 3rd party auth à la OAuth, but a french government standard) to authenticate to government services that went online later.

So if the taxes auth is compromised (so far I haven't seen enough details about the coverage of the leak), that's a real concern.

"Ce scénario n'est pas théorique, il a déjà eu lieu. En octobre 2025, la Fédération française de tir se fait voler les données de près d'un million de licenciés et d'anciens licenciés : état civil, adresse postale, téléphone, numéro de licence.

Les mois suivants, des individus se présentent au domicile de licenciés en se faisant passer pour des policiers ou des gendarmes, parfois en tenue, pour se faire remettre des armes. Des vols sont constatés à Nice, à Paris, à Limoges, à Décines."

Sounds like a far fetched movie!

Wow, indeed rare that hacks result in real-life visits, and here even specifically to pretend-confiscate weapons. That's a well-plannee (or excellently opportunist) coup.
I mean, which official service has not been hacked now ?
i think we are on the verge of some serious event that will affect the whole ai industry.
I believe that we established all those government systems are fairly easy to hack. I remember some French military naval construction network got owned about a year ago, much worst in a sense.

My guess is since a global conflict is ramping up this is only the beginning and we are about to see some real damage.

It is fairly easy to create chaos in a country for a few weeks if you start disrupting the grid, payments or internet access.