Google Button Μake us preferred on Google

The French government revealed a data breach affecting a large number of taxpayers two months after it happened, while in a separate case, a notorious hacker group is celebrating a breach after a cyberattack wave targetted at dozens of major companies.

The French Ministry of Finance said investigations confirmed a “malicious actor’s” claim that it had broken into the systems of the General Directorate of Public Finances (DGFP) in late June.

Further investigations are now underway to determine the number of taxpayers affected and what data was involved, the ministry said.

It said that affected users would receive a personalized notice explaining which data may have been viewed or extracted and, where necessary, what precautionary steps they should take.

However, FrenchBreaches, a platform that tracks cyberattacks in the country, said it was told by the hackers that the breach involves data on nearly 700,000 taxpayers. The ministry did not respond to a request for comment from FrenchBreaches, according to Reuters.

In the second case, the hacker group Cl0p, known for ransomware attacks reported to have brought in $500 million in revenue, claimed to have stolen large volumes of data from nearly 50 companies worldwide, including Philips, Shell, Fiserv, and GE, according to a post on the group’s website.

Philips admitted it had been targeted by Cl0p, while Shell said it was aware of a recent “possible incident,” confirming an earlier Thursday report from Dutch news outlet BNR.

“We are working with security teams and relevant experts to investigate the situation,” a Shell spokesperson said.

Philips said in a statement that it had identified and contained an attempted breach on a specific company server linked to internal data, adding that the incident does not affect customer environments.

A Fiserv spokesperson said the company is aware of the attacker’s claims but that, based on its assessment so far, it has found no evidence that customer data, banking data, transaction data, or personal data were breached, nor that its operating environment was affected.

A GE spokesperson said the company is aware of the claim and has activated its cyber incident response protocols and is working to assess the potential issue.

Reuters was not able to independently verify the hacker group’s claims, and the group did not respond to a request for comment.

Although it’s not clear how the hackers may have gained access, Ransom-ISAC, an industry information sharing organization, issued a warning on July 22 that the hacker group was exploiting vulnerabilities in PTC Windchill and FlexPLM, software used to support engineering and manufacturing processes.

Brandon Parsons, director of threat intelligence at Ascent Solutions and author of the Ransom-ISAC warning, said some companies began receiving notices from Cl0p on July 19 or 20. According to him, the group consists of “professional data extortionists” who focus on vulnerabilities in widely used software packages rather than targeting specific companies.

“They’re not really targeting a specific company, they’re targeting a specific zero-day vulnerability and exploiting it,” Parsons said, referring to security gaps for which no fix yet exists.

These incidents come amid growing concern that artificial intelligence could be used for automated attacks, since today’s AI models are skilled at finding security flaws and often behave unpredictably, as shown by recent incidents of models breaking out of closed testing environments.

The new cyberattack on the French government follows the theft of medical data belonging to 15 million French citizens this past February.

That same month, the French Ministry of Finance announced that a hacker had gained access to a bank database and searched for information on 1.2 million accounts.

It also said the hacker used a stolen official’s credentials to access details such as account numbers, holder names, and addresses.