French Tax Authority Data Breach Exposes 678,000 Individuals
French tax authority data breach impacts 678,000 individuals
Overview of the Breach
The French Ministry of the Economy and Finance reported a security incident involving unauthorized access to systems managed by the General Directorate of Public Finances (DGFiP), resulting in the exposure of data for 678,000 individuals. The breach was identified following a threat actor using the alias “ZeroBytes” who advertised a stolen database on the PwnForums hacking platform on August 12.
Details of the Compromised Data
Investigations revealed that the intruder accessed systems to retrieve information including tax-related details such as reference tax income, family quotient, and withholding tax rates for individuals. Business data, such as company names and SIREN numbers, was also compromised. Additional details encompassed cadastral records, including property addresses and dimensions.
Impact on User Accounts
The French Public Finances Directorate (DGFIP) confirmed that online user accounts for both individuals and professionals remained unaffected, with no evidence of compromised login credentials.
Response and Investigation
The breach prompted immediate action from the French tax administration, which suspended access to sensitive information systems. Collaborative efforts with the National Cybersecurity Agency of France (ANSSI) are ongoing to evaluate the full scope of the incident.
Threat Actor’s Claims
The threat actor claimed to have accessed the Serveur Professionnel de Données Cadastrales (SPDC), a platform managed by the DGFiP that provides access to France’s central land registry. According to the attacker’s post on PwnForums, the SPDC portal contained data for approximately 20 million citizens, though only 252,149 records—representing over 2 million individuals—were reportedly extracted.
The actor stated that the data extraction process was excessively time-consuming, estimating it would require months to complete. They also mentioned remaining logged into the system and offered the database for sale, emphasizing minimal pricing and requesting no public acknowledgment of the breach.
Notification and Protective Measures
The French Finance Ministry announced plans to notify affected individuals starting the following week via postal mail, providing details about the compromised data and recommended protective measures.
Context of Recent Cyberattacks
This incident adds to a series of cyberattacks targeting French government entities in recent months. In January, the national employment agency France Travail faced a 5 million fine after a breach exposed data from 43 million people. A separate breach in February affected 1.2 million user accounts following a database compromise at the national bank account registry (FICOBA). More recently, France Titres disclosed a breach involving 19 million records allegedly stolen from the National Agency for Secure Documents (ANTS).
Systemic Cybersecurity Challenges
The incident highlights vulnerabilities in credential-based access controls, as noted in a recent analysis showing that 37% of malicious activities are blocked when valid credentials are used. The report, titled *The Blue Report 2026*, evaluated defensive measures across 338 million simulations in production environments. French authorities continue to address systemic cybersecurity challenges, with multiple government agencies experiencing data exposure events in 2026.
Conclusion
The breach underscores the need for enhanced safeguards to protect sensitive financial and personal information.
