Nearly 700,000 French Taxpayer Records Reportedly Stolen in Government Cyberattack
Nearly 700,000 French Taxpayer Records Reportedly Stolen in Government Cyberattack
France’s Finance Ministry has confirmed that a cyberattack on the country’s tax authority resulted in the theft of personal and professional taxpayer data, potentially putting the information of hundreds of thousands of people at risk.
The ministry said Thursday that a “malicious actor” claimed to have broken into the Directorate General of Public Finances (DGFiP) in late June. An investigation confirmed that attackers had gained access to the agency’s systems and were able to consult and extract taxpayer information.
French officials are still trying to determine what exact information was taken and how many people were affected, with the precise scope of the breach still under investigation. The ministry said people whose information was compromised will be notified directly and informed about which data may have been exposed and what precautions they should take.
The number of potential victims could be substantial. The specialised cyberattack monitoring platform, FrenchBreaches, said that about 678,000 records were stolen, including roughly 393,000 individuals and 286,000 professionals.
Reuters noted that the French Finance Ministry has not confirmed those figures.
What taxpayer information was exposed?
The reported stolen information could give criminals plenty of material for targeted scams and identity theft.
According to reporting by Brussels Signal, the potentially exposed information includes names, addresses, dates of birth, reference tax income, withholding tax rates, family circumstances and some property-related information. The dataset also allegedly contained internal tax identifiers, information about dependents and records of previous interactions with the tax administration.
That combination is particularly concerning because tax records can provide attackers with a detailed profile of an individual or business. Such information could potentially be used to facilitate identity theft, targeted phishing campaigns or other forms of fraud.
FrenchBreaches also reported that the stolen information was being offered for sale for several thousand euros. Those details came from the alleged attackers and have not been independently confirmed by French authorities.
Attack reportedly went undetected
Advertisement
There are also unanswered questions about how the attackers managed to extract data without the data theft being detected.
Le Monde reported that the unauthorized access was identified and cut off at the end of June during a routine security check. However, the agency apparently did not detect that data had already been extracted at the time. The incident only became public after the alleged attacker claimed responsibility on a cybercrime forum and offered stolen data for sale.
The alleged attacker, operating under the name ZeroBytes, claimed to have accessed an internal DGFiP tool through a virtual private network using stolen professional credentials. The DGFiP has not confirmed the account of the attack.
The DGFiP has since strengthened its access controls, while the French Ministry said it will report the incident to France’s data protection regulator, the CNIL, and file a formal complaint. The investigation is being carried out with help from France’s national cybersecurity agency, ANSSI.
Must-read security coverage
Another cybersecurity challenge for France
The incident is the latest in a growing list of cyberattacks targeting French government institutions in recent months.
In February, the French Finance Ministry disclosed that an attacker had gained unauthorized access to information associated with approximately 1.2 million bank accounts in the country’s FICOBA registry by using stolen official credentials. Authorities said there was no known connection between that incident and the latest DGFiP breach.
Later in April, France’s National Agency for Secure Titles (ANTS), which handles documents such as identity cards, passports and driving licenses, disclosed a breach affecting potentially 11.7 million accounts. That incident prompted Prime Minister Sébastien Lecornu to announce a €200 million ($232 million) cybersecurity initiative funded through the France 2030 investment program.
Advertisement
Lecornu said France had been seeing roughly three data theft incidents per day since the beginning of 2026.
French authorities have not yet established the full scope of the DGFiP breach, meaning the reported figure of nearly 700,000 affected records remains unconfirmed.
Until investigators determine exactly what was stolen, taxpayers notified by the agency may need to treat convincing tax-related emails, calls and other requests with additional caution — particularly when they contain personal information that would normally make a message appear legitimate.
Other Security News: Microsoft is pushing Entra ID users toward passkeys as it moves away from SMS and voice-based authentication methods that are more vulnerable to phishing and interception.
