France’s Tax Authority Breach Exposes the Hidden Danger of Stolen Identities and Trusted Access + Video

Listen to this Post

Featured ImageA Breach That Turned Trusted Credentials Into a Gateway

France is facing a serious cybersecurity incident after attackers gained unauthorized access to systems operated by the country’s Directorate General of Public Finance, known as the DGFiP, exposing sensitive tax, business, and property-related information belonging to hundreds of thousands of people and organizations.

The incident is particularly concerning because this was not simply a case of an attacker breaking through a firewall or exploiting an obvious software vulnerability. Investigators say the intruders used impersonated credentials belonging to a DGFiP employee and an authorized third party. In other words, the attackers were able to make legitimate access look illegitimate only after the fact.

The French Ministry of Economy and Finance confirmed the intrusion in August 2026 after a malicious actor publicly claimed responsibility. The authorities said the unauthorized activity occurred during June and July, while subsequent investigation established that compromised accounts had been used to consult and extract information.

That distinction matters. A stolen password is dangerous, but a stolen identity inside a trusted government environment can be considerably more powerful. Once an attacker appears to be a legitimate employee or authorized partner, traditional perimeter defenses may see a normal login rather than an intrusion.

The 678,000 Figure Puts the Incident in Perspective

The breach is being associated with approximately 678,000 affected individuals and businesses, although the precise number of records and the total amount of information extracted remain part of the ongoing investigation.

Reports surrounding the incident have also described a sample containing hundreds of thousands of records. French reporting has indicated that the exposed information could include highly sensitive financial and identifying details, although the precise final scope must be distinguished from claims made by the attacker or third parties.

The most important point is that the incident is no longer being treated as a theoretical compromise. DGFiP has acknowledged that data was consulted and extracted, meaning the risk has moved beyond unauthorized access and into confirmed data exposure.

How the Attackers Entered the Environment

According to DGFiP, the attackers impersonated the credentials of both an internal employee and an authorized third party.

The authority has not publicly explained exactly how those credentials were obtained. It also has not confirmed whether the attackers bypassed multi-factor authentication, stole authentication tokens, abused an existing session, compromised an endpoint, or used another identity-based technique.

That missing technical detail is important because it prevents defenders from confidently identifying the initial attack vector.

Credential theft can occur through phishing, infostealer malware, malicious browser extensions, session-token theft, social engineering, compromised endpoints, password reuse, help-desk manipulation, or weaknesses in identity federation.

The central lesson is therefore broader than the specific technique used in this incident: authentication alone does not prove that the person behind an account is legitimate.

The First Investigation Did Not Immediately Reveal Exfiltration

One of the most troubling elements of the incident is the apparent gap between initial access-control reviews and the later discovery that information had actually been extracted.

DGFiP initially found no evidence of data theft during its first access-control assessment. Further investigation subsequently determined that compromised accounts had been used to consult and extract information before the accounts were disabled.

The authority attributed the difficulty in identifying the extraction activity to the sophistication of the attack.

This is an important cybersecurity warning because modern attacks increasingly focus on blending into legitimate activity rather than generating obvious alarms.

An attacker who logs into a government system using valid credentials may not trigger the same detection mechanisms as someone exploiting a vulnerable server. The login can look legitimate. The session can look legitimate. The account can have legitimate permissions. Even the data queries may resemble normal administrative work.

The malicious behavior may only become visible when defenders correlate identity, device, location, time, volume, and access patterns.

What Information Was Exposed?

The compromised information reportedly included tax-related and cadastral information associated with private individuals and professional entities.

For individuals, potentially exposed information includes reference taxable income, family quotient information, withholding-tax rates, and property-related information such as addresses and surface-area details.

For businesses, information may include company names and SIREN identifiers, which are used to identify French legal entities.

This combination creates a dangerous intelligence package for criminals.

A name alone may have limited value. A name combined with a property address, tax information, business affiliation, and withholding rate can become the foundation for an extremely convincing impersonation attempt.

Why Tax Data Is So Valuable to Criminals

Financial information does not need to contain a bank password to be dangerous.

A criminal who knows approximately how much someone earns can construct a believable tax-related message. Someone who knows a person’s property information can impersonate a government representative discussing cadastral records. Someone who knows a company’s legal identifier can make a fake invoice, compliance request, tax notice, or corporate-registration message appear considerably more authentic.

This is where the breach could have consequences far beyond the original database.

The stolen information can become social-engineering infrastructure.

Instead of sending a generic message saying, “Your tax account has a problem,” an attacker can potentially construct a message containing details that the victim recognizes as private.

That psychological advantage can dramatically increase the probability that a target will trust the communication.

The Taxpayer Portal Was Not the Directly Compromised Target

DGFiP has emphasized that the online Finances publiques spaces used by individual and business taxpayers were not compromised.

The authority has also stated that taxpayer login credentials and passwords were not exposed during the incident.

That is an important distinction, but it should not be interpreted as meaning that affected individuals have no reason to worry.

The primary risk has shifted from direct account takeover toward identity-based fraud, phishing, social engineering, and targeted impersonation.

A criminal does not necessarily need access to the victim’s tax account if they already possess enough information to convince the victim that they are speaking with the tax administration.

The Threat May Continue Long After the Breach Is Closed

Closing compromised accounts can stop an attacker from continuing to use those specific credentials.

It cannot automatically erase information that has already been copied.

This is one of the hardest realities of data breaches: remediation can secure the system while leaving the stolen information permanently useful to criminals.

Tax records may remain relevant for years. Property information changes slowly. Business registration information can remain valid for long periods. Historical financial details can also help attackers build profiles of individuals and organizations.

Consequently, the operational incident may eventually be closed, while the social-engineering risk remains active for years.

DGFiP Has Taken Additional Security Measures

Following the discovery of the broader scope, DGFiP introduced additional security restrictions and precautionary shutdowns affecting access to sensitive information systems.

The authority is coordinating with the Ministry of Economy and Finance’s security leadership as well as France’s National Agency for the Security of Information Systems, ANSSI.

The response also involves the French data-protection regulator, CNIL, which is responsible for overseeing compliance with data-protection requirements.

CNIL describes a personal-data breach as unauthorized access, disclosure, loss, alteration, or destruction affecting personal information, and French organizations subject to the GDPR have specific obligations concerning notification and response.

Why CNIL Notification Matters

The involvement of CNIL is more than an administrative formality.

A major government data breach involving tax and property information raises questions about security controls, access governance, monitoring, breach detection, incident response, and protection of sensitive personal information.

CNIL has demonstrated in other cases that inadequate security controls can result in substantial enforcement action. In January 2026, for example, the regulator imposed a combined €42 million in penalties on Free and Free Mobile over data-security failures following a major breach.

The DGFiP investigation will therefore have both cybersecurity and regulatory dimensions.

The Most Dangerous Part May Be What Comes Next

The immediate intrusion is only one stage of the incident.

The next stage could involve attackers using the stolen information to identify valuable targets, construct personalized phishing campaigns, impersonate officials, target businesses, or combine the data with information obtained from other breaches.

This is why victims should not assume that the absence of a stolen password means there is no meaningful risk.

In modern cybercrime, context is often more valuable than credentials.

A criminal who knows enough about a person can sometimes manipulate that person into voluntarily providing the final credential.

Phishing Could Become Extremely Convincing

Traditional phishing is relatively easy to identify because the message is generic.

A fake tax message that contains the

The attack becomes psychological rather than purely technical.

The criminal is no longer asking the victim to believe something completely unfamiliar.

Instead, the criminal is presenting real information and using it to make a false story believable.

Businesses Face a Different Layer of Risk

Companies affected by the incident could face targeted business-email compromise, fake tax correspondence, fraudulent compliance requests, and impersonation attempts against finance departments.

SIREN identifiers and company information can make malicious communications appear legitimate.

A criminal could potentially impersonate a tax official, accountant, supplier, regulator, or business partner while using authentic corporate information as supporting evidence.

For finance teams, this reinforces an old but increasingly important rule: never approve sensitive financial actions solely because an email contains accurate company information.

What Individuals Should Do Now

People who may be affected should be especially cautious with unsolicited tax-related communications.

Do not click links in unexpected emails or text messages claiming to be from the tax administration.

Instead, access official government services through a trusted bookmark or by manually navigating to the legitimate government website.

Users should also be suspicious of anyone who claims to know their tax information and then asks for passwords, authentication codes, banking details, or identity documents.

French public-service guidance has repeatedly warned about scams impersonating DGFiP personnel and requesting credentials or banking information.

What Organizations Should Do

Businesses should treat the incident as a reminder to review identity security rather than simply update antivirus software.

Security teams should examine privileged accounts, third-party access, authentication logs, unusual data queries, impossible-travel events, session activity, and large-volume database access.

They should also verify that former employees, contractors, vendors, and dormant accounts cannot retain unnecessary access.

The most effective defense is not a single security product. It is a combination of strong identity controls, least privilege, continuous monitoring, segmentation, behavioral analytics, and rapid incident response.

Deep Analysis

Identity Has Become the New Perimeter

Modern government networks cannot assume that an authenticated user is trustworthy.

Identity must be continuously evaluated.

A successful login should answer only one question: “Can this identity authenticate?”

Security monitoring must answer a much harder question: “Does this behavior make sense for this identity?”

The Importance of Least Privilege

If an employee needs access to one repository, that employee should not automatically have access to every sensitive database.

The principle of least privilege limits the damage caused by stolen credentials.

The same principle should apply to contractors and third-party organizations.

An external account should have exactly the permissions required for its function and nothing more.

Monitoring Database Behavior

Defenders should monitor not only successful logins but also what authenticated users do afterward.

A normal employee account suddenly querying thousands of taxpayer records should be investigated.

A third-party account accessing information outside its normal working hours should generate additional scrutiny.

A user downloading unusually large amounts of information should trigger behavioral detection.

Defensive PowerShell Example

Windows administrators can begin examining recent authentication and security events with commands such as:

Get-WinEvent -FilterHashtable @{
LogName='Security'
Id=4624,4625,4672
StartTime=(Get-Date).AddDays(-7)
} | Select-Object TimeCreated, Id, ProviderName, Message

This can help security teams investigate successful and failed logons as well as privileged-logon activity.

Investigating Unusual Account Activity

Administrators can also review local account information when investigating a potentially compromised Windows system:

Get-LocalUser |
Select-Object Name, Enabled, LastLogon, PasswordExpires

The objective is not to identify an attacker from one command.

The objective is to establish whether the

Searching Authentication Logs

Security teams using Windows event logs can filter authentication events for suspicious activity:

Get-WinEvent -FilterHashtable @{
LogName='Security'
Id=4624,4625
StartTime=(Get-Date).AddHours(-24)
} | ForEach-Object {
$_ | Select-Object TimeCreated, Id, Message
}

Organizations should correlate these results with identity-provider logs, endpoint telemetry, VPN records, proxy logs, and database auditing.

Linux Log Review

Linux administrators investigating authentication anomalies can review recent SSH activity:

sudo journalctl -u ssh --since "24 hours ago"

On systems using traditional authentication logs, defenders can also inspect:

sudo grep -Ei "accepted|failed|invalid" /var/log/auth.log

These commands are defensive investigation techniques and should be combined with centralized logging rather than used as a standalone detection system.

Looking for Impossible Travel

One of the strongest signals of credential compromise can be an account appearing to authenticate from geographically or logically incompatible locations within a short period.

For example, an account might authenticate from Paris and then appear minutes later from another continent.

This is not definitive evidence of compromise because VPNs, proxies, remote-access infrastructure, and corporate networks can distort location.

However, it is an excellent signal for investigation.

Third-Party Accounts Deserve Equal Attention

The DGFiP incident is particularly important because the reported compromise involved an authorized third party.

Third-party accounts often receive less attention than internal employee accounts.

That is dangerous.

Attackers understand that external identities can provide a path into trusted environments.

Organizations should therefore enforce MFA, conditional access, device verification, session controls, time restrictions, and least-privilege permissions on third-party identities.

Privileged Access Should Be Temporary

Permanent administrative privileges create enormous risk.

Where possible, sensitive access should be granted only when required and removed automatically afterward.

Just-in-time access can significantly reduce the period during which stolen credentials remain useful.

Database Exfiltration Requires Behavioral Detection

Detecting an attacker after data extraction begins is already late.

The better strategy is to identify unusual database behavior before a large extraction succeeds.

Security teams should establish baselines for normal query volume, normal datasets, normal working hours, and normal administrative behavior.

Deviation from those patterns should trigger investigation.

Data Loss Prevention Is Not Enough

Data-loss prevention technologies can help identify sensitive information leaving an organization.

But DLP should not become the only line of defense.

Attackers may move slowly, extract smaller datasets, use legitimate tools, or disguise activity as normal administrative work.

Identity analytics, database monitoring, endpoint telemetry, and network visibility must work together.

Session Tokens Can Be More Valuable Than Passwords

Organizations sometimes focus heavily on password protection while overlooking authenticated sessions.

If an attacker steals an active session token, they may be able to operate without knowing the original password.

This is why modern identity security needs device binding, risk-based authentication, session expiration, token protection, and continuous evaluation.

MFA Is Necessary but Not Magical

Multi-factor authentication remains one of the most important defenses against credential theft.

However, MFA should not be treated as an impenetrable barrier.

Phishing-resistant authentication methods, such as passkeys and hardware-backed credentials, provide stronger protection against phishing and credential replay than many traditional authentication mechanisms.

Government Data Requires Exceptional Security

Government agencies often hold information that citizens cannot simply choose to stop providing.

That creates a special security responsibility.

Tax information, identity information, property records, business registrations, and public-service data can collectively create extraordinarily detailed profiles of individuals and organizations.

Protecting these datasets is therefore not merely an IT requirement.

It is a matter of public trust.

The Breach Demonstrates the Power of Data Correlation

The danger is not necessarily contained within the stolen DGFiP records.

Criminals can combine tax information with data from previous breaches, public records, social media, business directories, leaked credentials, and other criminal databases.

Each individual dataset may seem incomplete.

Together, they can create a highly accurate victim profile.

Attackers Do Not Need Every Record

A common misconception is that a breach becomes dangerous only when millions of records are stolen.

That is not necessarily true.

A smaller dataset containing wealthy individuals, senior executives, business owners, or people with significant assets can be disproportionately valuable.

Attackers may prefer quality over quantity.

The Human Factor Remains Central

Technology can identify suspicious authentication.

Technology can detect abnormal queries.

Technology can block malicious traffic.

But a convincing social-engineering attack eventually targets a human decision.

Employees and citizens must therefore be included in the security architecture.

Awareness training is not a substitute for technical controls, but technical controls are incomplete without informed users.

Incident Response Must Assume Data Was Copied

When an attacker has accessed sensitive information, defenders should avoid assuming that nothing was extracted simply because an initial investigation found no obvious evidence.

Investigators should preserve logs, endpoint evidence, identity-provider records, database audit trails, network telemetry, and cloud activity.

The investigation must establish what was accessed, when it was accessed, by which identity, from which device, and whether the behavior was consistent with legitimate work.

Breach Notification Is Only the Beginning

Telling victims that their data may have been exposed is necessary.

It is not the end of the response.

Affected individuals need clear explanations of what information was exposed, what attackers could realistically do with it, and what protective actions they should take.

Ambiguous notifications can increase anxiety and reduce trust.

The DGFiP Case Raises a Larger Security Question

The most important question is not simply how attackers obtained two identities.

The larger question is why those identities were able to reach sensitive information and how quickly unusual activity could be detected.

If an attacker compromises a legitimate account, the security architecture should still limit what that account can reach.

That is the purpose of defense in depth.

What Undercode Say:

Identity Security Is Now the Battlefield

The DGFiP incident demonstrates why identity has become one of the most attractive targets in modern cybercrime.

Trusted Accounts Can Become Dangerous Weapons

A legitimate account can bypass many traditional perimeter controls because the infrastructure recognizes the identity as authorized.

Credential Theft Is Only the Beginning

The real danger begins when stolen credentials are converted into persistent access to valuable information.

Government Systems Hold Unusually Valuable Data

Tax and property databases contain information that can support highly convincing fraud.

A Password Does Not Define the Entire Risk

Even when passwords are not stolen, exposed personal information can be used to manipulate victims into surrendering credentials later.

Third Parties Need Stronger Controls

External identities should receive the same level of scrutiny as internal privileged accounts.

Least Privilege Should Be Non-Negotiable

No employee or contractor should have unrestricted access simply because their role exists inside a trusted organization.

Monitoring Must Follow the User

Security teams need to understand not only who logged in but what that person did after authentication.

Data Access Needs Behavioral Baselines

A legitimate account suddenly accessing an unusual volume of records should immediately attract attention.

Exfiltration Can Be Quiet

Attackers do not always download everything in one dramatic operation.

Slow Theft Can Be More Difficult to Detect

Small, carefully selected extractions can blend into normal administrative behavior.

Sensitive Data Can Have a Long Shelf Life

Tax and property information may remain valuable long after the original breach has been contained.

Phishing Will Become More Personalized

Attackers can use authentic information to construct messages that feel legitimate.

Social Engineering Will Follow the Data

The stolen database can become the foundation for future attacks against victims.

Organizations Must Prepare for Secondary Attacks

The first breach can create opportunities for phishing, fraud, extortion, identity theft, and business compromise.

Security Teams Should Investigate Identity Anomalies

Unexpected locations, devices, times, applications, and data-access patterns should receive attention.

MFA Should Be Phishing-Resistant

Strong authentication remains essential, but organizations should move toward methods that resist credential and session theft.

Session Security Matters

Protecting passwords alone is not enough when attackers can steal authenticated sessions.

Third-Party Access Should Be Temporary

Permanent vendor privileges create unnecessary attack surfaces.

Privileged Access Should Be Monitored Closely

Administrative identities can create disproportionate consequences when compromised.

Data Access Should Be Segmented

A compromise of one account should not automatically expose unrelated repositories.

Databases Need Their Own Security Layer

Identity security and endpoint protection cannot replace database monitoring.

DLP Should Work With Detection

Preventing data movement is valuable, but detecting abnormal access is equally important.

Security Logs Must Be Preserved

When a breach is discovered, missing logs can make it impossible to reconstruct the attack.

Detection Speed Determines Damage

The longer a compromised identity remains active, the greater the attacker’s opportunity.

Government Agencies Face a Unique Challenge

Citizens cannot simply opt out of many government databases, making security failures particularly consequential.

Public Trust Is Part of Cybersecurity

A government breach can damage confidence even when attackers never obtain passwords.

Transparency Matters

Clear communication can help citizens distinguish between confirmed facts and speculation.

Victims Need Practical Guidance

People need to know what information was exposed and what scams to expect.

Generic Security Advice Is Not Enough

Victims should be warned about the specific types of impersonation enabled by the stolen information.

Attackers May Combine Multiple Breaches

A tax database can become more dangerous when combined with previously leaked credentials or personal information.

Criminals Value Context

Knowing a

The Most Valuable Target May Be a Person

Organizations often protect servers more aggressively than identities.

Zero Trust Is Increasingly Relevant

Every access request should be evaluated according to identity, device, context, privilege, and risk.

Authentication Must Become Continuous

A user should not be trusted indefinitely simply because authentication succeeded once.

Security Architecture Must Assume Compromise

Organizations should design systems around the possibility that an identity will eventually be stolen.

Recovery Must Include Long-Term Monitoring

Closing an account does not invalidate information already copied by attackers.

Data Breaches Have Long Tails

The consequences may continue months or years after the initial intrusion.

This Incident Is a Warning for Europe

The same identity-based attack pattern could affect other government agencies holding high-value citizen information.

The Real Lesson Is Bigger Than DGFiP

The incident demonstrates that cybersecurity is no longer just about stopping unauthorized people from entering.

The Harder Problem Is Detecting Authorized Identities Being Abused

That requires behavioral analytics, strong identity governance, segmentation, and rapid investigation.

Security Teams Should Assume Attackers Will Adapt

Once traditional defenses improve, criminals increasingly turn toward identities and trusted relationships.

Trust Must Be Earned Continuously

The future of cybersecurity will depend on continuously proving that an identity, device, session, and action are legitimate.

✅ The DGFiP Incident Is Confirmed

France’s Finance Ministry and DGFiP confirmed that unauthorized access occurred and that subsequent investigation established that data had been consulted and extracted.

✅ Credential Impersonation Is Central to the Reported Attack

DGFiP said attackers used impersonated credentials associated with an employee and an authorized third party. However, the precise mechanism used to obtain or abuse those credentials has not been publicly established.

⚠️ The Exact 678,000 Scope Should Be Treated Carefully

Approximately 678,000 affected individuals and businesses is widely reported, but the investigation into the precise number of affected records and total extracted information has continued. Some figures circulating online originate from samples or attacker claims rather than a completed government forensic assessment.

✅ Tax and Property Information Are Part of the Reported Exposure

Available reporting identifies tax-related and cadastral information among the potentially affected data. The precise dataset exposed to each individual or business remains dependent on the ongoing investigation.

✅ CNIL Has a Formal Role in Personal-Data Breaches

CNIL explains that organizations handling personal information have obligations concerning data breaches, including notification requirements under the GDPR when applicable.

⚠️ MFA Bypass Has Not Been Confirmed

There is currently insufficient public evidence to state that attackers bypassed multi-factor authentication. The precise credential-compromise technique has not been fully disclosed.

Prediction
(+1) Identity-Based Attacks Against Government Agencies Will Increase

The DGFiP incident is likely to reinforce a broader cybersecurity trend in which attackers prioritize identities, sessions, contractors, and trusted relationships rather than relying exclusively on software vulnerabilities.

(+1) Government Agencies Will Tighten Third-Party Access

Organizations holding sensitive public data are likely to increase scrutiny of external accounts, introduce stronger conditional-access controls, and reduce standing privileges.

(+1) Behavioral Detection Will Become More Important

Security teams will increasingly monitor what authenticated users do rather than treating successful authentication as proof of legitimacy.

(+1) Phishing Campaigns Will Become More Personalized

If exposed tax and property information reaches criminals, it could provide material for highly convincing impersonation campaigns targeting both individuals and businesses.

(+1) Phishing-Resistant Authentication Will Gain Momentum

The incident strengthens the case for passkeys, hardware-backed credentials, device-bound authentication, and other controls designed to make stolen passwords less useful.

(-1) Public Confidence Could Decline

Repeated attacks against public institutions can make citizens question whether highly sensitive government information is being adequately protected.

(-1) Secondary Fraud Could Continue After Containment

Even after compromised accounts are disabled, stolen information can remain useful for identity fraud, social engineering, and targeted phishing.

(+1) The Long-Term Security Lesson Will Be Zero Trust

The strongest lesson from this incident is that legitimate identities cannot automatically be considered trustworthy. Future government security architectures will increasingly depend on continuous verification, least privilege, segmentation, and behavioral monitoring.

The Bigger Picture: When Trust Becomes the Attack Surface

A Different Kind of Cybersecurity Crisis

The DGFiP breach illustrates a fundamental transformation in cybercrime.

Attackers no longer need to look like attackers.

They can look like employees.

They can look like contractors.

They can look like administrators.

They can operate through legitimate applications and legitimate accounts.

And when that happens, cybersecurity becomes much more complicated than simply blocking malicious traffic.

The New Security Question

The most important question for government agencies and large organizations is no longer simply, “Who is allowed to enter?”

It is:

“Does this identity have a legitimate reason to perform this action right now?”

That question requires context.

It requires continuous monitoring.

It requires strong identity governance.

And above all, it requires organizations to assume that eventually, one trusted identity may be compromised.

Why This Incident Matters Beyond France

The DGFiP case should be viewed as a warning for every organization that stores financial, property, healthcare, legal, or government information.

A database does not need to be publicly exposed to become vulnerable.

A trusted account can be enough.

That is why the next generation of cybersecurity will increasingly focus on identity behavior, least privilege, continuous authentication, data-access analytics, and rapid response.

The attackers may have entered through credentials.

But the deeper issue is trust.

And in modern cybersecurity, trust without continuous verification is becoming one of the most dangerous vulnerabilities of all.

▶️ Related Video (80% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.medium.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube