France’s DGFiP Data Breach Exposes Tax Information of 678,000 People
France’s Ministry of Economy and Finance has disclosed a data breach affecting the Directorate General for Public Finances (DGFiP). Attackers accessed a DGFiP information system and extracted personal and tax-related data belonging to approximately 678,000 individuals and professionals.
The incident was discovered after a threat actor using the alias “ZeroBytes” claimed responsibility and offered the stolen database for sale on the PwnForums hacking forum on August 12, 2026.
According to an investigation conducted after the breach was identified, the compromised access points were used to view and extract information on 678,000 individuals and businesses. The exposed information may include reference tax income, family-related tax information, withholding tax rates, company names, and SIREN business identification numbers. The French Ministry of Finance confirmed the incident.
The breach also involved cadastral information, including property addresses and property sizes. The DGFiP said that online accounts belonging to personal and professional users were not compromised, and that usernames and passwords were not exposed.
After detecting the unauthorized activity, French tax authorities blocked access to the affected information systems. The investigation is continuing in cooperation with France’s National Cybersecurity Agency, ANSSI, to determine the full scope and impact of the DGFiP data breach.
In a post on a hacking forum, ZeroBytes also claimed to have accessed the Serveur Professionnel de Données Cadastrales (SPDC), an online platform operated by French tax authorities. The platform provides access to land registry and real estate ownership information.
The threat actor claimed that the portal contained information on approximately 20 million French citizens. However, they said they were only able to extract 252,149 records containing information on more than 2 million people.
“I couldn’t complete the extraction because, honestly, scraping is horrible and takes months. I’m still logged into the panel, so I can buy it along with the database if I want,” the attacker claimed. “In any case, we are not going to sell this for a lot of money. And as always, there has been no mention from France about this incident.”
The French Ministry of Finance said it will begin contacting affected individuals by email or letter next week. The notifications will explain what information may have been accessed or stolen and outline the precautions recipients should take.
The DGFiP incident is the latest in a series of cyberattacks and data breaches targeting French government agencies.
In January, France’s data protection authority fined France Travail, the country’s employment agency, €5 million after hackers stole the personal information of 43 million people. One month later, the French Ministry of Finance disclosed another breach affecting more than 1.2 million user accounts after attackers stole data from the National Bank Account Registration System, known as FICOBA.
More recently, France Titres, the government agency responsible for issuing and managing administrative documents, disclosed a breach after threat actors offered a database containing 19 million records for sale. The data was allegedly stolen from the National Agency for Secure Documents (ANTS).
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




