France Investigates Data Breach at Tax Authority After Hacker Claims 600,000 Victims
France's tax authority, DGFiP, confirmed a data breach in late June, with a hacker claiming to have accessed data belonging to 600,000 individuals and businesses.

France’s Directorate General of Public Finances (DGFiP) has confirmed a significant data breach impacting its information systems, leading to the extraction of sensitive data on individuals and businesses. The intrusion, which occurred in late June, was detected and contained by the agency, but not before an attacker gained unauthorized access. The incident came to light after a hacker, using the alias ZeroBytes, claimed responsibility and asserted access to data on over 600,000 people.
According to a statement from France’s Economy Ministry, the attacker gained access through the theft or misuse of an individual's identity. This allowed them to view and subsequently extract data. While the DGFiP has not confirmed the exact scope or authenticity of the hacker's claims, they are actively investigating to determine precisely what information was compromised and the number of affected parties. The ministry stated that individuals whose data was impacted will be contacted directly with information on the exposed data and necessary precautions.
The hacker, ZeroBytes, reportedly claimed to have accessed internal servers, enabling them to connect to the agency’s VPN and utilize an internal tool to search for and exfiltrate personal information. The purported data includes names, tax identification numbers, email addresses, family circumstances, and tax status details. The DGFiP has initiated a criminal complaint and will notify France's data protection authority as its investigation progresses.
This breach marks the latest in a series of cyber incidents affecting French government agencies this year. In April, the National Agency for Secure Documents (ANTS), responsible for passports and driver's licenses, was targeted. The Education Ministry also disclosed a breach exposing student personal information in the same month. Furthermore, in February, a part of the National Bank Accounts File was compromised, affecting approximately 1.2 million accounts.
Authorities have been actively pursuing cybercriminals targeting public institutions. Earlier this year, a 20-year-old man was arrested on suspicion of conducting numerous data breaches against government bodies, sports federations, and private companies. The DGFiP has not yet attributed the current breach to a specific threat actor or confirmed the hacker's specific claims about the method of access or the extent of data exfiltration.
The incident underscores the persistent threat posed by identity-based attacks and the vulnerabilities within government IT infrastructure. The DGFiP's confirmation and ongoing investigation highlight the critical need for robust identity management and continuous monitoring to detect and prevent such intrusions, especially when sensitive personal and financial data is at stake.
France's tax authority (DGFiP) has confirmed that a data breach occurred in late June, with an attacker advertising over 2 million taxpayer records. The agency stated that the intrusion was severed in June and is currently investigating the full scope of affected data and users, disputing claims that the attacker still has access. This incident follows a pattern of recent breaches affecting French public sector entities, including the Ministry of Finance and France Titres.
The French Directorate General of Public Finances (DGFiP) has confirmed that the breach, which occurred in June and July, impacted approximately 678,000 users. Attackers gained access using compromised credentials belonging to an employee and a third-party account, exfiltrating sensitive tax data including income, withholding tax rates, company identifiers, and real estate information. The DGFiP is directly contacting all affected individuals and continues to investigate the full scope of the incident.
The French tax authority, DGFiP, has confirmed that a data breach has impacted 678,000 individuals and professionals, a slight increase from the initial claims of 600,000 victims. The attacker, known as "ZeroBytes," claimed to have accessed data on approximately 20 million citizens, though the DGFiP's investigation established that data concerning 678,000 individuals and professionals was consulted and extracted. This compromised data includes tax details such as reference tax income and withholding tax rates, as well as business information like company names and SIREN numbers.
The French tax authority (DGFiP) has confirmed that the data breach, initially reported following a hacker's claim, affected approximately 678,000 individuals and businesses. The attackers gained access between June and July 2026 using compromised employee and third-party credentials, viewing and extracting sensitive tax and property data. While online accounts were not compromised, the stolen information, including income details and cadastral information, could be used for phishing and identity fraud.
The French tax authority, DGFiP, has provided an update on the recent data breach, confirming that attackers may have accessed the contents of messages exchanged with taxpayers. For approximately 250 individuals, the compromised data includes the actual messages themselves, in addition to tax identification numbers, addresses, and other personal details. The authority is now notifying affected parties and warning of potential phishing and impersonation attacks, including CEO fraud and scams involving bogus bank advisors.