All incidents

French tax authority data breach exposes 680,000 records

breachopenAug 14, 2026 — Aug 17, 2026
French tax authority data breach exposes 680,000 records

THE French Directorate General of Public Finances (DGFiP) has confirmed that personal data of about 680 000 individuals was accessed without authority after a hacker group called ZeroBytes claimed responsibility, according to the agency’s statement. The intrusion relied on compromised employee and third party credentials and took place between June and July 2026. DGFiP said the breach was identified during routine security monitoring in late June. No evidence suggests that the attackers deployed malware or exploited a software vulnerability.

The data that was viewed includes names, postal addresses and tax identification numbers, but does not appear to contain usernames, passwords or banking details. Because the attackers used legitimate accounts, there is no associated CVE identifier for the incident. Investigators have found no indication that the stolen information has been sold on dark‑web markets, although the possibility remains under review. The agency stressed that the compromised records do not include any authentication material that could allow direct account takeover.

ZeroBytes posted a brief claim on a hacking forum, providing screenshots that allegedly showed extracts from the DGFiP databases. French authorities responded by launching a forensic investigation and by notifying the data protection regulator of the incident. The statement from DGFiP noted that additional security measures, such as forced password resets for affected accounts, have been applied to limit further access. Officials also confirmed that they are working with law‑enforcement partners to trace the origin of the compromised credentials.

The breach follows a similar incident earlier this year in which Romania’s National Agency for Cadastre and Property Registration suffered a disruptive cyberattack that resulted in data loss and service interruption. Both cases show a trend of threat actors targeting government revenue and registration bodies to harvest personal information. Security analysts warn that such data can be used for identity theft, fraudulent tax filings or social engineering campaigns. The lack of ransomware deployment suggests the attackers were focused on espionage or financial gain rather than extortion.

Organisations should immediately rotate any privileged credentials that may have been exposed and enforce multi‑factor authentication on all remote access points. Security teams ought to review authentication logs for anomalous login times, locations or device characteristics and to tighten controls over third‑party service accounts. Conducting a thorough forensic analysis will help determine the exact volume of data taken and whether any additional systems were accessed. Affected individuals should be notified promptly and offered credit‑monitoring services to mitigate the risk of identity theft.

The DGFiP says it will contact those whose records were compromised and urges recipients to treat any unexpected communication requesting personal information as potentially malicious. Updating passwords on unrelated services and remaining vigilant against phishing attempts are sensible precautions for anyone concerned about their data. The agency also reminded the public to monitor bank statements and tax notices for signs of misuse. Although the investigation is ongoing, the current assessment indicates that the breach did not expose authentication material that could lead to immediate account compromise.

Intelligence briefing updated Aug 17, 2026

ZeroBytes
Root sourcepresse.economie.gouv.fr
Timeline Coverage

Swipe to explore timeline