France’s tax authority has confirmed a major cyberattack in which attackers accessed government systems and extracted data linked to about 678,000 individuals and professionals. The incident affects the General Directorate of Public Finances, known as DGFiP, which manages taxation and public finance services in France. The breach became public after a threat actor claimed on August 12, 2026, that they had gained unauthorized access to the administration’s systems and stolen a large amount of data.

According to the French Finance Ministry, the unauthorized access happened after the identity of a DGFiP employee and an authorized third party was misused. The intrusions were detected and the related accounts were blocked. However, investigators later found that the access had already been used to view and extract information. The authorities said the sophistication of the attack meant that their access controls did not initially detect that data was being stolen.
The investigation found that information belonging to a total of about 678,000 individuals and professionals had been consulted and extracted. For individuals, the exposed information includes tax-related details such as reference taxable income, family quotient and withholding tax rate. For businesses, the affected information includes company names and SIREN numbers, which are official identification numbers used to identify French businesses. Cadastral information linked to addresses and property sizes was also accessed.

French authorities have stressed that the incident did not compromise users’ online tax accounts. The DGFiP said user IDs and passwords were not compromised, meaning the stolen information cannot be used directly to sign in to secure taxpayer accounts. The administration nevertheless considers the incident serious because tax and property information can reveal sensitive details about people and businesses. The French data protection authority, CNIL, was notified after the data theft was identified.
The attack was first publicly claimed by a threat actor using the name ZeroBytes, who reportedly offered stolen information for sale on a cybercrime forum. The criminal claim helped bring the incident to wider attention, after which French authorities carried out deeper investigations into the affected systems. Reports about the alleged stolen database appeared online before the government confirmed the scale of the incident. Authorities are continuing to examine the attack and determine its full impact.

The stolen information could create a serious phishing and social engineering risk even without access to taxpayers’ online accounts. Criminals could use real tax information, addresses or business details to make fake emails, messages or phone calls appear convincing. A scammer who already knows someone’s tax situation may be able to create a much more believable request for money, documents or account information. This makes the breach especially concerning for people whose information was exposed.
French authorities are working with the National Agency for Information Systems Security, known as ANSSI, as investigations continue. The DGFiP has also taken additional security measures following the incident and has begun preparing notifications for affected people and businesses. The administration said those affected would be contacted by email or letter with information about the data involved and guidance on precautions. Officials have also urged taxpayers to remain careful with unexpected messages or requests.

The incident adds to a series of cyberattacks and data breaches that have recently affected French public institutions. Earlier in 2026, other government systems were targeted, including services holding employment, banking and identity-related information. The latest DGFiP breach shows why government databases remain attractive targets for cybercriminals: they contain large amounts of valuable personal and financial information in one place. French authorities are continuing their investigation while affected users are being warned to stay alert.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news