French Tax Authority Data Breach Exposes Over 600,000 Users’ Personal Tax Data
Key Takeaways France’s tax authority, DGFiP, confirmed a data breach impacting approximately 678,000 individuals and businesses. Threat actors gained access to internal systems using...
Key Takeaways
- France’s tax authority, DGFiP, confirmed a data breach impacting approximately 678,000 individuals and businesses.
- Threat actors gained access to internal systems using compromised employee and third-party credentials.
- Exposed data includes personal tax information, property details, and business identifiers, but not online account credentials.
- The stolen data poses a significant risk for targeted phishing, identity fraud, and tax scams.
- DGFiP is notifying affected parties and collaborating with national cybersecurity agencies on the ongoing investigation.
French Tax Authority Confirms Major Data Breach Affecting 678,000 Users
The French tax authority, the Directorate General of Public Finances (DGFiP), has officially confirmed a significant data breach impacting an estimated 678,000 individuals and businesses. The incident saw unauthorized actors infiltrate the agency’s internal information systems, leading to the exfiltration of sensitive tax-related data.
Table Of Content
Details released in an August 14, 2026, press statement reveal that the breach originated from stolen or impersonated credentials belonging to both a DGFiP employee and an authorized third-party vendor. The unauthorized access occurred over a period spanning June and July 2026.
The DGFiP initiated a deeper forensic investigation after a malicious actor publicly claimed responsibility for the intrusion on August 12 and 13. While initial reviews after detecting unauthorized logins did not immediately reveal data theft due to the sophistication of the attack, further analysis confirmed that attackers had viewed and extracted sensitive tax and property information before the compromised accounts were disabled.
Scope of Exposed Data
The compromised data is extensive, encompassing personal tax information such as reference tax income, family quotient details, and withholding tax rates for individuals. For businesses, the breach exposed company names and SIREN registration identifiers. Cadastral information, including property addresses and the surface area of real estate assets, was also compromised.
Crucially, the DGFiP has emphasized that taxpayers’ online “Finances publiques” accounts remain secure, and no personal or business usernames or passwords were exposed in this incident. This mitigates the immediate threat of direct account takeovers; however, the stolen data presents a substantial risk for other forms of cybercrime.
The highly sensitive nature of tax records makes them exceptionally valuable to cybercriminals. Access to an individual’s tax status, income details, company identity, or property address can enable highly convincing and effective targeted phishing campaigns, identity fraud, tax scams, and social engineering attacks. Threat actors can leverage this information to impersonate government agencies, financial institutions, or tax advisors, making fraudulent communications appear legitimate.
Response and Mitigation Efforts
Upon confirming the data theft, the DGFiP promptly notified France’s data protection authority, the Commission Nationale de l’Informatique et des Libertés (CNIL). In response to the breach, the agency has implemented additional security protocols, including preventative disconnections from critical information systems.
DGFiP’s IT teams are actively collaborating with the Ministry of Economy and Finance, the High Official for Defense and Security, and France’s national cybersecurity agency, ANSSI, to manage the incident. Investigators are still working to ascertain the precise volume and nature of the stolen data, as well as the final count of affected users.
The DGFiP plans to directly contact every impacted individual and organization via email or post, starting the following week. These notifications will specify the data that may have been accessed or extracted and provide relevant precautions. The authority said it will also file a criminal complaint and publish further details as the investigation progresses.
What You Should Do
- Exercise extreme caution with all unsolicited tax-related communications, regardless of how legitimate they appear.
- Avoid clicking on links or opening attachments in unexpected emails or messages pertaining to your taxes or property.
- Independently verify any requests for personal or financial information by contacting official government agencies or financial institutions directly through their verified channels, not through contact details provided in suspicious messages.
- Monitor your credit reports and financial statements for any unusual activity.
- Be aware of potential social engineering attempts that leverage your tax or property information to gain your trust or extract further details.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.