Massive Data Breach Hits French Tax Authority, Exposing 678,000 Records

The French tax authority, the Directorate General of Public Finances (DGFiP), has suffered a significant data breach, compromising the personal and financial information of approximately 678,000 individuals and businesses. The breach was publicly acknowledged on August 14, 2026, following unauthorized access to internal systems during June and July of the same year.

Attackers exploited stolen or impersonated credentials belonging to a DGFiP employee and an authorized third party to infiltrate the system. The breach came to light when a hacker claimed responsibility on August 12 and 13, prompting a comprehensive forensic investigation. Initial security reviews failed to detect the data theft due to the sophisticated nature of the attack.

The compromised data includes sensitive personal tax information such as reference tax income, family quotient details, and withholding tax rates. For businesses, exposed data encompasses company names and SIREN registration identifiers. Additionally, cadastral information, including property addresses and real estate surface areas, was accessed. Notably, taxpayers’ online “Finances publiques” accounts and their associated usernames and passwords were not compromised, mitigating the immediate risk of direct account takeovers.

Despite this, the stolen data poses significant risks, as cybercriminals can leverage it for targeted phishing, identity fraud, tax scams, and social engineering attacks. Knowledge of a victim’s tax status, income, company identity, or property address can make fraudulent communications appear more credible.

In response, DGFiP has notified France’s data protection authority, the Commission Nationale de l’Informatique et des Libertés (CNIL), and implemented additional security measures, including preventive disconnections from sensitive information systems. Collaborations are underway with the Ministry of Economy and Finance, the High Official for Defense and Security, and France’s national cybersecurity agency, ANSSI, to assess the full extent of the breach.

DGFiP plans to contact all affected individuals and organizations directly, providing details about the compromised data and recommended precautions. Notifications will be sent via email or post. The authority also intends to file a criminal complaint and will release further information as the investigation progresses.

This incident underscores the critical importance of robust cybersecurity measures within governmental institutions. The breach not only exposes sensitive taxpayer information but also erodes public trust in the security of state-managed data. It highlights the urgent need for comprehensive security protocols, regular audits, and prompt incident response strategies to safeguard against increasingly sophisticated cyber threats.