French Tax Authority Confirms Data Breach Affecting 678,000 Individuals and Businesses
France’s General Directorate of Public Finances (DGFiP) has disclosed a data breach after an attacker accessed its systems, exposing sensitive information on 678,000 individuals and professionals. The incident was first revealed when a threat actor using the alias ZeroBytes claimed responsibility on a cybercrime forum, offering a stolen database for sale.
According to ZeroBytes, the compromised portal contained data on approximately 20 million French citizens, though only 252,149 records covering over 2 million people were successfully extracted. The attacker cited difficulties in scraping the full dataset, stating the process would have taken months. They claimed to have gained access using stolen login credentials and an MFA bypass technique, though they remained logged into the system at the time of their post.
The DGFiP confirmed the breach, stating that while access was immediately suspended upon detection, initial investigations did not reveal data theft due to the attack’s sophistication. Further analysis, conducted since August 12, 2026, determined that the attacker accessed and extracted tax-related data, including reference tax income, family quotient, withholding tax rates for individuals, and company names and SIREN numbers for businesses.
The agency clarified that online tax portals for individuals and businesses were not compromised, nor were user credentials. The DGFiP has notified France’s data protection authority (CNIL) and implemented additional security measures, including temporary shutdowns of sensitive systems. The finance ministry’s security office (SHFDS) and the national cybersecurity agency (ANSSI) are assisting in the response.
This breach follows a series of recent cybersecurity incidents targeting French government agencies.
Source: https://www.helpnetsecurity.com/2026/08/17/france-tax-authority-data-breach/
General Tax Authority cybersecurity rating report: https://www.rankiteo.com/company/general-tax-authority
"id": "GEN1786984338",
"linkid": "general-tax-authority",
"type": "Breach",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '678,000 individuals and '
'businesses',
'industry': 'Taxation/Finance',
'location': 'France',
'name': 'General Directorate of Public Finances '
'(DGFiP)',
'type': 'Government Agency'}],
'attack_vector': 'Stolen login credentials, MFA bypass',
'customer_advisories': 'Public disclosure by DGFiP',
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': '252,149 records (covering ~2 '
'million people, but only '
'678,000 confirmed affected)',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High (personally identifiable and '
'financial information)',
'type_of_data_compromised': 'Tax-related data (reference tax '
'income, family quotient, '
'withholding tax rates, company '
'names, SIREN numbers)'},
'description': 'France’s General Directorate of Public Finances (DGFiP) '
'disclosed a data breach after an attacker accessed its '
'systems, exposing sensitive tax-related information on '
'678,000 individuals and professionals. The breach was first '
'revealed by a threat actor known as *ZeroBytes*, who claimed '
'to have extracted data using stolen credentials and an MFA '
'bypass technique. The DGFiP confirmed the breach and stated '
'that while access was suspended, further analysis revealed '
'data exfiltration.',
'impact': {'brand_reputation_impact': 'Yes',
'data_compromised': 'Tax-related data (reference tax income, '
'family quotient, withholding tax rates, '
'company names, SIREN numbers)',
'identity_theft_risk': 'Yes',
'operational_impact': 'Temporary shutdown of sensitive systems',
'systems_affected': 'Internal tax portal (non-public facing)'},
'initial_access_broker': {'data_sold_on_dark_web': 'Yes (offered for sale by '
'ZeroBytes)',
'entry_point': 'Stolen login credentials, MFA '
'bypass'},
'investigation_status': 'Ongoing',
'motivation': 'Financial gain (data sold on cybercrime forum)',
'post_incident_analysis': {'corrective_actions': 'Enhanced security measures, '
'temporary system shutdowns',
'root_causes': 'Stolen credentials, MFA bypass '
'vulnerability'},
'references': [{'source': 'Cybercrime forum post by ZeroBytes'}],
'regulatory_compliance': {'regulatory_notifications': 'Notified France’s data '
'protection authority '
'(CNIL)'},
'response': {'communication_strategy': 'Public disclosure, notification to '
'CNIL',
'containment_measures': 'Immediate suspension of attacker '
'access, temporary shutdown of sensitive '
'systems',
'incident_response_plan_activated': 'Yes',
'remediation_measures': 'Enhanced security measures, further '
'investigation',
'third_party_assistance': 'France’s national cybersecurity '
'agency (ANSSI), finance ministry’s '
'security office (SHFDS)'},
'threat_actor': 'ZeroBytes',
'title': 'French Tax Authority Data Breach Affecting 678,000 Individuals and '
'Businesses',
'type': 'Data Breach'}