BlackTree Security · Infrastructure · Automation · AI

France’s Tax Systems Have Been Breached Again. The Bigger Problem Is What Comes After the Data Theft

France has now confirmed that 678,000 individuals and businesses were affected by unauthorised access to its tax systems. The investigation is still establishing the precise nature and volume of data extracted. The longer security problem is what criminals can do when official tax, identity and banking context makes an impersonation attempt feel real.

The Direction générale des Finances publiques, or DGFiP, says an attacker obtained unauthorised access to its information systems in June and July by using the impersonated credentials of a DGFiP agent and an authorised third party. The affected accounts were cut off, but not before data concerning individuals and businesses was consulted and extracted.

The affected-user count is now known, but the precise data taken for each person or business remains under investigation. Tax data has value long after the initial access is closed because it helps an attacker answer the questions that victims, help desks, banks and employers use to decide whether someone is genuine.

What France has confirmed

In its 14 August update, the French Finance Ministry confirmed that the June and July accesses affected a total of 678,000 individuals and businesses. The intrusions relied on the impersonated credentials of a DGFiP agent and an authorised third party. DGFiP interrupted the identified accounts when it detected the access, but its initial controls did not establish that data had already been stolen.

The ministry says the accessed and extracted material includes reference taxable income, household tax quotient and withholding-tax rates. Business records include legal names and SIREN identifiers, while cadastral data concerning property addresses and surface areas was also consulted. It says taxpayers’ online spaces, usernames and passwords were not compromised.

Le Monde reviewed a sample posted by the attacker and found civil-status records, home addresses, personal phone numbers, reference taxable income, tax rates and numbers of dependants. The sample also identified the local public-finance office and the agent who handled each case. That reporting describes the sample, not necessarily every record in the confirmed 678,000-person and business population.

DGFiP says it will contact each affected individual and business with the data that may have been consulted or extracted and the precautions to take. It has notified the French data-protection authority, CNIL, and says it will file a complaint and publish further information as the investigation progresses.

What remains unknown after the 678,000 confirmation

The central victim count is no longer an estimate. The remaining uncertainty concerns the precise nature and volume of data extracted, which fields were present for each affected person or business and how the 678,000 total is divided across the compromised systems.

The useful questions are now narrower: Were complete records taken or selected exports? How widely do the fields seen in the sample appear across the full dataset? Did the extraction include correspondence, payment details or tax identifiers beyond what the ministry has listed? Which applications were used, and how long did each attacker-controlled account retain access before it was interrupted?

Those answers determine the downstream risk. A large list of email addresses creates one kind of problem. A smaller dataset containing verified financial, household or business context creates a much sharper impersonation tool.

This follows a separate FICOBA incident

The June breach is not the same incident as the unauthorised access to FICOBA disclosed in February. FICOBA is France’s national register of bank accounts and is also managed by DGFiP. In that earlier case, a malicious actor used the credentials of a civil servant with inter-ministerial access to consult and extract data associated with around 1.2 million bank accounts.

The official FICOBA notice said the exposed information included bank details, account-holder identity and address. A later update clarified that the users’ tax identifiers had not been consulted in that incident.

The two breaches should not be merged into one technical narrative. Their shared lesson is organisational: a tax authority holds several datasets that other institutions treat as authoritative, and an attacker does not need to alter those records to exploit their value. Reading and extracting them may be enough.

BlackTree made a similar point after Romania’s cadastre attack: national registries are systems of public trust, not ordinary databases. Confidentiality, integrity and availability matter, but so does the ability of other organisations to keep trusting the identity and transaction signals built from those systems.

Stolen tax data becomes an authentication kit

Generic phishing asks a victim to believe a story. Data-informed phishing begins with facts. A caller who knows a tax reference, business status, filing detail, address or recent interaction with the administration sounds less like a stranger and more like someone continuing an existing process.

That context can support several attacks:

  • Tax-payment and refund fraud. Messages can refer to a plausible assessment, correction or repayment and direct the victim to a convincing payment or login page.
  • Business impersonation. Criminals can target finance teams, accountants and directors with requests that fit the company’s tax calendar or declared structure.
  • Bank and creditor scams. Identity and account context from one breach can be combined with tax information from another source to strengthen a false fraud alert or account-recovery request.
  • Help-desk manipulation. Personal facts may help an attacker pass weak knowledge-based checks and reset access to an unrelated service.
  • Long-term profiling. Income, property or business information can identify high-value targets and make later extortion, investment scams or executive impersonation more selective.

No single stolen field needs to be decisive. The danger grows when criminals link datasets. An address from one incident, an IBAN from another and a tax detail from a third can form a convincing identity even when none of the breached systems exposed a password.

The risk moves beyond the tax authority

DGFiP must contain the intrusion and notify the people involved, but many of the attempted frauds will land elsewhere. Banks, payroll teams, accountancy firms, insurers, property professionals and customer-service desks may see the downstream attacks.

Those organisations should not wait for a complete breach report before adjusting fraud controls. They already know that official-looking personal and financial information may be in criminal hands. A caller’s ability to quote accurate data is therefore weaker evidence of identity than it was before.

Knowledge must stop being treated as identity

The durable response is to remove personal facts from the authentication decision. Names, dates, addresses, tax references and account details may be confidential, but they are not secrets that can be safely rotated after a breach.

  • Use phishing-resistant authentication for staff and privileged access, and require step-up verification for changes to payment, refund, address and bank details.
  • Verify sensitive requests out of band. Call a known number from an existing record or require approval through an authenticated portal rather than replying to the message that started the request.
  • Stop relying on knowledge-based questions. Information about income, addresses, accounts or previous transactions may now be attacker knowledge.
  • Detect changes, not only logins. Alert on new beneficiaries, contact-detail changes, account recovery, unusual document exports and sudden access to many taxpayer or customer records.
  • Prepare a cross-channel fraud playbook. Security, finance, customer service, legal and communications teams need a shared route for escalating scams that use stolen government context.
  • Make notices specific. Telling people that “data may have been affected” is less useful than naming the fields, the period of exposure and the types of requests that legitimate staff will never make.

What taxpayers and businesses should do

People should expect impersonation attempts to contain accurate information. Accuracy is not proof that the sender is DGFiP, a bank or an accountant.

  • Open the tax service by typing the official address or using an existing bookmark. Do not use a link in an unexpected email or text message.
  • Do not disclose passwords, one-time codes or full payment-card details to an incoming caller, even when the caller knows personal tax information.
  • Verify payment or refund requests through the authenticated tax portal or a published contact channel.
  • Review bank and tax accounts for changes, new messages and unfamiliar activity, and enable alerts where they are available.
  • Businesses should independently verify any request to change bank details, tax-payment instructions or accountant access.

The French government’s anti-fraud guidance warns that criminals imitate the appearance and language of official messages. The present breach increases the chance that those messages will also contain credible private context.

Disclosure must support downstream defence

The chronology will need explanation. DGFiP says the access was stopped in late June, while public confirmation followed an attacker’s claim on 12 August. Detection, containment, forensic certainty and legal notification do not happen at the same moment, but organisations that depend on the affected data need enough information to adjust their own controls.

The best follow-up disclosure will therefore do more than repeat the 678,000 headline. It should describe which data fields were extracted for which groups, the applications involved, the identity route used, the exposure period, the monitoring available to victims and the fraud scenarios that banks and businesses should expect.

The breach ends later than the incident

DGFiP can close the access path, rebuild systems and rotate credentials. It cannot rotate a taxpayer’s history, address or financial relationships. Once copied, that context can be reused months or years later and combined with information from other breaches.

That is the bigger problem after the data theft. High-trust government data gives low-trust communications an air of authority. France’s response must secure the tax system, but every organisation that verifies people with personal knowledge should treat this incident as another reason to replace “what do you know?” with stronger proof of who is asking.

Sources and further reading

Update, 23 August 2026: France now describes three distinct data leaks

France’s 18 August briefing also separated the incident picture into three data leaks of different scale and severity:

  • Tax correspondence: access to lists of messages exchanged between taxpayers and the administration affected about 350,000 individuals and included data protected by tax secrecy.
  • Cadastral records: access to the professional cadastral-data service affected up to 433,485 individuals and 1,082 professionals.
  • Inheritance-related requests: a separate actor accessed the history of requests made through a public portal used to determine whether a debtor had an heir or whether an estate was unclaimed. The access was detected and blocked on 17 August. Its scope remains under analysis, and officials have not established whether the same actor was responsible.

Officials said none of the three leaks involved entry into an individual or business tax account, and no secure taxpayer-account credentials were recovered. The distinction matters because the confirmed total of 678,000 affected individuals and businesses is not a single clean dataset count. The categories can overlap, while the inheritance-portal scope is still unresolved.

Developments through 19 August materially expand the original account. Prime Minister Sébastien Lecornu convened an interministerial crisis meeting on 17 August, an unusual escalation for a data breach, while affected taxpayers began receiving individual notifications. The government has ordered an audit of the tax authority’s information systems under ANSSI supervision and accelerated a wider programme that includes €200 million for interministerial cybersecurity, artificial intelligence and ministry security.

Budget Minister David Amiel has also acknowledged that the state has accumulated significant technical debt over decades. That matters because the incident is no longer being framed as one isolated credential theft. The government is treating it as evidence about the resilience, detection and governance of public-sector systems. Further reporting and audit findings are expected in September.

The technical sequence is now clearer. According to the tax authority’s director general, the attacker combined a tax official’s credentials with an external-access route. The intruder performed manual tests before automating extraction and kept activity below existing detection thresholds. Access was cut off, but the internal investigation did not establish that data had been removed. The administration recognised the theft only after the attacker publicised it on 12 August.

That chain strengthens the article’s original thesis. Valid credentials plus valid remote access can make extraction look like ordinary use, particularly when the attacker deliberately limits volume and learns the environment before scaling up. Containment of the access path did not answer the separate question of what happened while the path was open.

The group using the name ZeroBytes has claimed that the stolen material was sold. Le Monde reported the claim, but it has not been independently verified. It should not be treated as proof of a completed transaction, a buyer’s identity or the full dataset transferred.

France has also disclosed a distinct intrusion detected and blocked on 17 August against an inheritance-related public portal. The exposed material concerned requests made by people checking possible claims involving deceased persons or unclaimed estates. Officials have described that event as less serious, and it is not known whether the same actor was responsible. It should remain separate from the June and July tax-system compromise unless forensic evidence connects them.

The remediation programme now includes stronger multi-factor authentication, tighter access control and improved detection. Those measures need to be applied to the actual attack chain: the professional identities that can reach sensitive applications, the external gateways that accept them, the queries permitted after login and the alert thresholds that a patient attacker can stay below.

The operational requirement is therefore broader than adding MFA to one portal. France needs to correlate identity, remote-access and application-level activity, reduce standing access, detect unusual historical or bulk queries, and preserve enough telemetry to distinguish successful containment from incomplete scoping. The ANSSI-supervised audit and September reporting will be the first public test of whether the response addresses those control failures rather than only the compromised account.

Additional sources

Leave a Reply

Your email address will not be published. Required fields are marked *