Aug 16, 2026 · 6 min read
French Tax Authority Breach Hits 678,000 Taxpayers
A hacker calling themselves ZeroBytes posted a claim on a criminal forum on 12 August. Two days later the French finance ministry confirmed someone had spent part of June and July inside the tax administration's systems using a stolen agent identity.
Two accounts of this breach are circulating, and they measure different things: what France verified in its own logs, and what the seller advertised.
Key Takeaways
- France's Direction générale des Finances publiques (DGFiP) confirmed on 14 August 2026 that illegitimate access to its systems led to the extraction of data on 678,000 individuals and businesses, per the finance ministry press release.
- The intrusion came from usurped credentials belonging to a DGFiP agent and an authorised third party, not from a flaw in impots.gouv.fr, which the ministry says was not compromised.
- DGFiP confirmed the theft of reference tax income, family quotient, withholding tax rate, company names and SIREN numbers, plus land registry addresses and property surface areas. User logins and passwords were not compromised.
- Email addresses are not on the confirmed list. The hacker claims they are in the stolen dataset, and that claim has not been independently verified.
- DGFiP said it would contact every affected person by email or post from the week of 17 August, so 678,000 taxpayers now expect an unsolicited message about their tax file.
What Did DGFiP Actually Confirm?
DGFiP confirmed that an intruder read and extracted tax records on 678,000 individuals and professionals after taking over the identity of one of its own agents. The official finance ministry statement of 14 August 2026 names the fields: revenu fiscal de référence, quotient familial and taux de prélèvement à la source for individuals, business names and SIREN numbers for companies, plus cadastral addresses and floor areas.
Two exclusions deserve equal billing. User logins and passwords were not compromised, and the portal held: DGFiP's notice on impots.gouv.fr says the site and the Finances publiques user spaces were not breached. This was not a hacked website. It was a hacked employee.
The ministry says CNIL was notified once the theft was confirmed, a criminal complaint would follow, and ANSSI is investigating.
What Is the Hacker Claiming That France Has Not Confirmed?
A wider dataset and a far wider reach. The Record's reporting on the disclosure lists the attacker's claimed haul as names, tax identification numbers, email addresses, family circumstances and tax status details, and states flatly that neither the claim nor the authenticity of the data has been independently verified.
The counting is contested too. Brussels Signal puts the advertised file at roughly 678,000 records, about 393,000 individuals and 286,000 professionals, a breakdown the ministry has not verified. The attacker suggested the access could have reached millions. A seller talking up inventory on a criminal forum is the least reliable narrator available.
So the honest position on email addresses is: unconfirmed. They appear in the attacker's description of the file, not the government's list of extracted fields. Plausibly exposed, not proven.
How Did the Attacker Get In?
Through a person, not a product. The ministry attributes the intrusion to usurped credentials of a DGFiP agent and an authorised third party, which gave the attacker internal VPN access and then a search tool agents use to look up taxpayer files. No vulnerability has been named and no CVE published.
The shape will be familiar to anyone who followed the FICOBA case, where a single stolen password exposed 1.2 million French bank account records: a legitimate internal lookup tool, an account that was supposed to be using it, and a search function that answered every query because the credentials were valid.
Coverage is arguing over whether the real number is 678,000 or two million. The number that explains this incident is one. One agent identity, replayed for two months against a tool built to return citizen records on demand.
Why Do Tax Records Make Such Good Phishing Fuel?
Because they let a stranger prove they know you. A message opening with your reference tax income, withholding rate and household size does not read like spam. It reads like the tax office, because until this month only the tax office had those figures.
Tax themed fraud already works at scale without stolen data. Microsoft mapped one season's campaign that hit 29,000 users across 10,000 organisations using nothing more personal than a logo and a deadline. The cadastral records raise that ceiling: paired with reference tax income, addresses and property surface areas let a fraudster sort 678,000 people by apparent wealth before writing a word. That is target selection, not merely impersonation.
What This Means for Your Inbox
Here is the part almost nobody has flagged. The ministry says DGFiP "prendra directement contact dès la semaine prochaine" with each affected person, who will be notified "par courriel ou courrier", by email or post. All 678,000 are now primed to open an unexpected email about their tax file and act on it.
A legitimate mass notification is the best cover a phishing crew could ask for. The government announced the pretext, the timing is public, the recipient list is in the attacker's possession, and the audience expects this exact message. It is the dynamic that made the three month delay in the EY client tax data breach so costly: by the time the official warning lands, the warning itself is worth imitating.
Is This a Pattern in French Public Systems?
It is the fourth large French public sector exposure we have covered in under two years, alongside the ANTS passport agency breach affecting 19 million identity records and the France Travail case that ended in a €5 million CNIL fine.
The compliance question is narrower than headlines suggest. CNIL's guidance on the rules for personal data breaches sets the 72 hour clock for notifying the regulator, not the public, while individuals must be told "au plus tôt" where risk is high. DGFiP says it notified CNIL once the theft was confirmed. Not in dispute: the intrusion began in late June, the public learned of it on 14 August, and the trigger was a forum post.
What Should Affected Taxpayers Do Now?
Assume the notification email you receive might be fake, and verify it through a channel the attacker does not control. Four steps:
- Never follow a link inside a DGFiP notification. Type impots.gouv.fr into the address bar yourself and sign in to your Finances publiques space. The ministry confirmed the portal was not compromised, so it stays trustworthy.
- Refuse any request for payment or credentials. Passwords were not stolen here, so nothing about this incident requires you to supply one by email. A message asking for bank details or a login is fraudulent by definition.
- Treat correct personal details as no proof at all. A sender quoting your reference tax income or household size is demonstrating access to leaked data, not authority. That used to be a trust signal. Since 14 August it is the opposite.
- Report suspicious messages instead of deleting them. The government's guidance on hameçonnage from Cybermalveillance.gouv.fr lists the routes, Signal Spam for email and 33700 for SMS, that feed the takedown pipeline.
One note for readers outside France: an internal lookup tool, valid credentials and no exfiltration alarm is a configuration that exists in revenue agencies, health systems and payroll providers everywhere.