Aug 17 / Latest News

France Confirms Tax Authority Breach Exposing Data on 678,000 Individuals

France’s tax authority has confirmed a major data breach after attackers accessed internal DGFiP systems and extracted sensitive information on 678,000 individuals and businesses.

The breach became public when a threat actor known as “ZeroBytes” posted on a cybercrime forum claiming access to a DGFiP administrative portal and offering a stolen database for sale. The attacker said the system contained data on roughly 20 million French citizens but noted they only extracted a portion of the records due to the difficulty of scraping the platform. They claimed to have gained entry using stolen login credentials combined with a multi‑factor authentication bypass technique, and said they remained logged into the panel even after partial extraction.

DGFiP said it suspended all accounts linked to the intrusion as soon as unusual activity was detected. Initial access‑control checks did not show evidence of data theft, which the agency attributed to the sophistication of the attack. However, deeper investigations launched on August 12, 2026 confirmed that the compromised access points had been used to view and extract tax information on hundreds of thousands of individuals and professionals. Exposed data includes reference tax income, family quotient, withholding tax rates, and for businesses, identifiers such as company names and SIREN numbers.

Officials emphasized that France’s public‑facing tax portals used by citizens and businesses were not compromised, and no usernames or passwords from those systems were stolen. DGFiP has notified CNIL, France’s data protection authority, and implemented additional security measures, including preventive shutdowns of sensitive systems and strengthened monitoring. The agency is now working with the finance ministry’s security office (SHFDS) and national cybersecurity agency ANSSI to assess the full scope of the breach and reinforce defenses.

This breach adds to a growing series of cybersecurity incidents affecting French government agencies in recent months. The attack highlights ongoing challenges in protecting public‑sector systems from credential theft, MFA bypass techniques, and increasingly sophisticated intrusion methods. DGFiP says further hardening efforts are underway as investigators continue to analyze the intrusion and its potential long‑term impact.