practical

Why French tax site is yet to fully implement two-factor authentication

France has been hit by several cyberattacks this summer

Two-factor authentication improves security during logins
Published

Concerns over the security of France’s tax website have been raised this summer, following major cyberattacks on French public services including tax authorities. 

The most recent attack led to a data breach impacting 678,000 individuals and professionals.

While the attack targeted government IT infrastructure, it has led to wider considerations on cybersecurity attached to the French tax service, namely user logins. 

Critics have highlighted how France’s tax website does not require users to use ‘two-factor authentication’ to log in. 

Users simply need to enter their numéro fiscal (13-digit tax number) and a password, which has prompted worries over how securely accounts are protected if hackers gain access to either piece of information.

While this summer’s breaches of government IT infrastructure did not take passwords or tax numbers, the simplified login system leaves at risk anyone who has this information compromised.

What is two-factor authentication?

Two-factor or ‘double’ authentication, sometimes abbreviated to 2FA, is a common type of login system used by many public and private companies worldwide. 

Following a person correctly entering information – typically their username/number or email and password – they are prompted to confirm it is them attempting to log in.

This typically takes place through a text message or phone call, usually providing a four- or six-digit code that must also be entered to log-in. 

Other versions see people required to click on an email link to confirm it is them (meaning they also need access to their email account), or opening a smartphone application. 

In some cases, such as for banks, biometric data such as a facial or fingerprint scan using their phone must also be used, providing extra security. 

While frustrating for some – particularly those who do not have a French mobile number – the system provides additional security against both hackers and in the event of a data breach. 

Even if a password is compromised, hackers will need to also access an email account or phone to get past the second authentication – although it is worth noting that many fraudsters now use ‘phishing’ scams in an attempt to bypass this. 

Note that impots.gouv.fr does use a simplified form of the system, with a log-in attempt leading to a six-digit code being sent to the primary email attached to the account.

However, once confirmed this provides access without a further double authentication for six months. 

Other government sites remain without any two-factor system.

European laws require increased security

What makes things more frustrating is that not only is two-factor authentication a good idea – European law requires it. 

However, this is exactly where the issue lies, says former Finance Minister Eric Lombard.

A European directive in 2023 mandated that public and government services use two-factor authentication. 

However, these directives typically have to be transposed into national law for each member state, going through the typical process of being introduced, debated, potentially altered, and voted on. 

France is well behind on the topic, with a bill to implement the EU mandate still awaiting its first reading at the Assemblée nationale even though the original deadline to transpose the directive passed in October 2024.

“A piece of legislation is currently moving back and forth between the Assemblée nationale and the Senate,” said Mr Lombard, quoted in media outlet Capital.  

He criticised the process for being too slow and wants more powers granted to the state to impose additional digital security. 

“What I am proposing, quite simply, is the coordination of the State's IT matters, placed directly under the authority of the prime minister, and that ANSSI (the National Cybersecurity Agency of France) be granted decision-making power,” bypassing parliament. 

Be wary of scams

While the implementation of two-factor authentication will reduce the risk of hackers gaining access to personal data on the French tax site, it will not limit the number of scams targeting individuals. 

France’s tax authority, the Direction générale des Finances publiques (DGFiP), frequently advises people to be wary of fraudulent emails, texts, and letters from scammers posing as officials. 

The DGFiP will never ask for personal information to be emailed or texted, nor ask for it during a phone call. 

You should never give personal data, including your numéro fiscal, password, or bank details to anyone.

If you have been contacted by someone claiming to be a tax official but are unsure, contact the service directly to confirm if this is legitimate.

You can do this by sending a message through your personal login, or by calling (+33 809 401 401 if in France, +33 1 72 95 20 42 if you are a non-resident).