HomeCyber AttacksFrance's Tax Authority Confirms Data Breach Affecting 680,000 Taxpayers

France’s Tax Authority Confirms Data Breach Affecting 680,000 Taxpayers

France’s tax administration, the Direction Générale des Finances Publiques (DGFiP), has confirmed that unauthorized parties accessed its systems and copied data belonging to roughly 680,000 people. The agency disclosed the incident in mid-August 2026, after a threat actor began advertising the stolen data on a hacking forum.

According to DGFiP, the intrusion itself took place earlier, over June and July 2026, before it came to light. The agency says it moved to cut off the unauthorized access as soon as it was detected, though it has not said publicly how long the attacker was inside its systems before that happened.

The point of entry was not a software flaw. Investigators traced the access back to compromised login credentials, specifically an employee account and a separate third-party account with access to DGFiP systems. That detail puts this breach in the same category as a growing number of recent government-sector incidents where stolen or reused passwords, rather than a technical exploit, gave attackers their way in.

DGFiP has been careful to specify what was and was not taken. The exposed data includes reference tax income figures, individual withholding tax rates, company names and their official identifying numbers, and cadastral records covering property addresses and surface areas. The agency has stated that no usernames, passwords, or similar account credentials belonging to the affected taxpayers were part of the stolen data.

Even without login credentials in the mix, the exposed information is still sensitive. Income and property data of this kind is commonly used to verify identity or approve financial transactions, so people affected by this breach have an elevated risk of being targeted by phishing attempts or fraud that uses these details to appear legitimate.

DGFiP said it has reported the incident to France’s data protection authority, the CNIL, as required under national and EU data protection rules, and that it plans to contact each affected individual directly. The agency says its investigation into the scope and origin of the breach is ongoing.

The incident follows a similar pattern seen in a recent breach at a Romanian cadastral agency, where a threat actor tracked under the name ByteToBreach used stolen credentials to access government property records and reportedly threatened destructive action as part of an extortion attempt. Security researchers have pointed to both cases as examples of attackers increasingly targeting the credentials of government employees and contractors rather than trying to find and exploit vulnerabilities in the software those agencies run.

As of publication, no CVE or specific technical vulnerability has been associated with the DGFiP breach, since the access was gained through valid but compromised login credentials rather than a software flaw.

Source: SecurityWeek, “680,000 Impacted by French Tax Authority Data Breach”

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular