Background
After a data leak, fraudsters can contact you by mentioning real information: name, tax ID, postal contact details, telephone or email address. This makes their messages credible. The attacks concern both administrations and companies and associations.
Why it's important
Residents, including immigrants, make extensive use of the online services of administrations and banks, exposing them to phishing (fraudful e-mails) and vishing (fraudful calls). Adopting a few simple reflexes severely limits financial losses and account hacking. Knowing what to do in case of an incident makes it possible to react quickly.
What Changes
Public Service publishes updated practical advice following illegitimate access to the information system of the Directorate-General for Public Finance (DGFiP), recalling the protection rules and the assistance services available.
Useful details
- Choose long and complex passwords (follow CNIL's advice) and never use the same password for different sites.
- Update your software, applications and devices as soon as you are offered, in order to correct security deficiencies.
- Enable double authentication: If you connect from an unidentified device, the site will alert you by SMS or email and you can allow or deny access.
- Never communicate your codes, identifiers, passwords or bank details in response to a request; check the sender, beware of links and attachments, and type the site's official address in your browser.
- It is advisable to use a password manager: this tool centralizes your logins in a database protected by a unique password.
- Also recommended: avoid publishing certain personal data, check the privacy settings of your accounts, install only applications from official stores, make regular backups and request the erasure of data that is unlawfully processed.
Terms to know
- DGFiP
- Direction générale des finances publiques, the French tax administration.
- CNIL
- Commission nationale de l'informatique et des libertés, the French authority for the protection of personal data.
- Double authentification
- An additional check to the connection: the site alerts you in case of access from an unknown device and you validate or refuse.
- Hameçonnage (phishing ou vishing)
- Attempts to scam via fake emails, SMS or calls to get your data.
- 17Cyber.gouv.fr
- Public service to assist victims of cyber-malware acts.
- Cybermalveillance.gouv.fr
- Public platform that explains the steps to be taken in case of data leakage or cyberattack.