France’s Tax Agency Lost 678,000 Accounts To A Cyberattack – How Will SaaS Fight AI-Accelerated Breaches?

The French tax authority, Direction Générale des Finances Publiques, has suffered a severe breach compromising 678,000 user accounts which exposed citizen names, physical addresses and tax reference codes. The event reinforces a pattern of targeted attacks aimed at Western public institutions, health networks and financial institutions during the past 18 months. A 2025 Verizon report tracked a 30% annual jump in credential attacks powered by automated AI phishing vectors and credential stuffing tools, highlighting the speed of this threat evolution. Financial losses are tracking similar upward trends, with IBM’s 2025 Cost of a Data Breach report placing average incident costs at $4.88 million following a 10% year-on-year climb.

These figures paint an unambiguous picture, as AI cuts overall operational costs while making advanced cyberattacks accessible to those lacking deep specialist training. Phishing emails that at one point required human authorship can now be generated in volumes, A/B tested and personalised automatically. Vulnerability scanning that took days can now run in hours. Social engineering that relied on human research can also be automated using publicly available data. The work of a sophisticated attacker has now become highly cost-effective and infinitely repeatable.

 

How Security Defences Are Evolving Around AI

 

Managing customer security now places SaaS platforms in an asymmetric environment driven by unequal execution speeds. Automated threat vectors allow malicious parties to iterate fresh AI phishing variants before corporate governance workflows approve a single security patch. Meanwhile, automated credential stuffing tools test millions of login combinations, rendering standard rate limits completely insufficient against the relentless algorithmic volume.

The Aura breach earlier this year was initiated through just one successful vishing call – a voice phishing attack on one employee that granted unauthorised access for roughly an hour. The France breach, the Aura breach and the general pattern of institutional attacks share a common thread: they rarely succeed by defeating technical controls alone. They succeed by exploiting people, process gaps and the mismatch between the speed of attacker iteration and the cadence of institutional defence.

The core question for SaaS leaders now is how their security models keep pace. We asked founders and security specialists how their threat models have changed, what AI has done to the attack surface they’re defending and whether the industry is operating on assumptions that no longer hold.

 

Our Experts

 

 

  • Viktor Bulanek, Founder, Penetrify
  • Michal Piszczek, Chief Technology Officer, Archdesk
  • Mudita Khurana, Staff Security Engineer, Airbnb
  • Omar Tahir, CTO and Founding Engineer, deepidv

 

 

Viktor Bulanek, Founder, Penetrify

 

Viktor Bulanek, Founder, Penetrify
 

“Worth saying first: the DGFiP breach was a stolen credential. An employee login plus an authorised third party, according to their own statement. That is a 1998 attack and no AI was required for it. I would be careful using it as the AI example, because the real lesson is duller and more useful.

“What AI has changed is not capability, it is cost per attempt. I can put a number on this because I sell the thing. We run agents that perform penetration tests unattended, and measured across our recent runs on our quick tier, one full autonomous attack run against a live web application costs a median of about $1.72 in model spend, roughly 21 cents a minute. That is the number founders should sit with. When probing a target costs a couple of dollars instead of a day of a specialist’s time, the question stops being whether you are hackable and becomes whether you are worth attacking. For basically every small SaaS company that answer has just flipped. You did not get weaker. You came into scope.

“So my own threat model moved in one direction over the last twelve months, and it is less exotic rather than more. The thing we actually fixed on our own product was session handling, getting auth tokens out of localStorage and into HttpOnly cookies, because stolen sessions are what ends up in stories like this one.

“Are most SaaS companies prepared? No, but not in the way the marketing implies. They are shopping for AI threat tooling while a contractor’s API token from 2024 still works.”

 

Michal Piszczek, Chief Technology Officer, Archdesk

 

Michal Piszczek, Chief Technology Officer, Archdesk
 

“From 2004 to 2012 I was a hacker. I broke into systems, never damaged them, and disclosed what mattered. Today I run AI agents in enterprise SaaS, so I now sit on the side I used to attack.

“AI didn’t make attackers smarter. It made attacking cheaper. A job that used to take a skilled team a couple of weeks now runs as an agent loop that costs single dollars per try and never sleeps. An attacker can afford to miss a thousand times a night. You get one chance to get it right. Once each attempt costs nothing, the volume is set by how big your attack surface is, not by how many people the attacker can pay.

“That changed our threat model over the last 12 months. We now assume the probing is constant and automated. So anything agentic is deny-by-default for egress. Credentials are short-lived and scoped to one task. And there’s a separate policy engine sitting in front of irreversible actions, because no agent should be able to pull its own kill switch. We also measure defence the same way attackers measure offence: cost per detected attempt, and how long it takes from an anomaly to a pair of human eyes.

“Are most SaaS companies ready? Not even close. Their security is still priced per year, an annual pentest, rate limits tuned for human speed. The offence is priced per attempt. AI took the cost of failure to zero for attackers, and a defence you haven’t tested is a loan. The incident is just how the market eventually calls it in.”

 

Mudita Khurana, Staff Security Engineer, Airbnb

 

Mudita Khurana, Staff Security Engineer, Airbnb
 

“SaaS threat models now need two major changes.

“First, companies should not ask whether they will get breached and build their threat model around that. They should assume an attacker will gain some form of access one way or the other, given AI’s speed and scale. The security model should then focus on limiting what that compromised access can reach, so the blast radius is contained. This can mostly be done through short-lived sessions, object-level authorisation, strict tenant isolation and narrowly scoped permissions. For companies to know when such a breach happens they need alerting on unusual activity so they can react quickly and have the ability to revoke credentials, isolate affected systems and stop an attack within seconds.

“Second, companies should treat every AI agent connected to internal systems as a potentially compromised insider. An agent generally has access to sensitive data and tools that can take actions, which it may need to do the work it was tasked to do. But having visibility into an agent’s access, the ability to limit its access and not letting one agent accumulate too many permissions is key to ensuring the blast radius remains limited. Each agent should have its own identity, short-lived permissions, clearly defined data boundaries and complete logs of every data call, tool invocation and action it performs.

“Threat modelling still remains essential, but it now needs to factor in AI’s scale for outside attackers and assume AI as a potentially compromised insider.”

 

Omar Tahir, CTO and Founding Engineer, deepidv

 

Omar Tahir, CTO and Founding Engineer, deepidv
 

“The threat surface hasn’t just expanded. It’s changed shape. Twelve months ago, we were defending against attacks that required human skill and patience. Today, the same attacks are automated, cheaper and faster. The economics have flipped.

“What concerns me most as a CTO handling customer identity data is the identity layer specifically. AI-generated documents, synthetic biometrics and deepfake-based impersonation have crossed from theoretical risk to operational reality. The verification stacks most SaaS companies rely on were not built to detect any of it.

“At deepidv, we responded by building every detection model in house. No third-party vendor anywhere in our fraud or verification stack. The reasoning is this: you cannot audit what you do not own. And in the current threat environment, auditability is not optional. It is the thing that separates companies that can demonstrate their security posture from companies that can only describe it.

“Most SaaS companies are not prepared. They are operating on assumptions built for a world where the attacker was human, slow and expensive to scale. That world is gone.”

 

For any questions, comments or features, please contact us directly.
techround-logo