France’s tax authority has confirmed that information belonging to hundreds of thousands of taxpayers and professionals was stolen after attackers gained unauthorized access to its systems. The Direction Générale des Finances Publiques (DGFiP) is continuing to investigate the intrusion after a hacker publicly claimed responsibility and advertised a much larger collection of French tax records.

 

 

The incident came to wider attention after an attacker using the name “ZeroBytes” advertised what was described as a database containing information on more than two million French taxpayers. The hacker claimed the intrusion occurred during June and July and said stolen credentials and a method for bypassing multi-factor authentication were used to enter DGFiP systems. The attacker additionally claimed continued access, but DGFiP says the accounts associated with the identified intrusions were suspended when the unauthorized activity was discovered.

DGFiP’s investigation has established that data was taken during the attacks, even though the theft was not initially detected. According to the authority, the intrusions involved compromised login credentials associated with a DGFiP employee and an authorized third party. When the unauthorized access was first identified, officials disabled the affected accounts, but security checks at the time did not reveal that information had already been removed.

The confirmed number of affected individuals and professionals currently stands at approximately 678,000. This is considerably below the figure promoted by the alleged attacker, and the continuing investigation has not verified the claim that more than two million taxpayer records were obtained. French media reporting indicates that the exposed information includes both personal and tax-related details.

Among the compromised tax information are reference tax income, family quotient, and withholding tax rates. Business-related records include company names and SIREN identification numbers, while cadastral information involving property addresses and property sizes was also accessed. DGFiP has said that taxpayers’ online account credentials, including their IDs and passwords, were not compromised in this incident.

After investigators obtained additional information about the breach, DGFiP introduced further security measures. These included preventative restrictions on access to sensitive information systems while authorities continued determining exactly what the attackers reached and how much information was removed.

People and professionals identified as affected are expected to receive direct notifications from the tax authority explaining which categories of their information may have been exposed and what precautions they should consider. The final scale of the incident remains under investigation, meaning the currently confirmed figure could change as forensic work continues.

The breach follows another security incident involving DGFiP earlier in 2026. Beginning in late January, an attacker who had obtained a government employee’s credentials gained unauthorized access to part of FICOBA, France’s national database of bank accounts. DGFiP said that incident involved approximately 1.2 million accounts, representing less than 1% of the banking details contained in the database.

The earlier FICOBA compromise exposed banking information including RIB and IBAN details, but DGFiP has said there is currently no established connection between that attack and the latest theft of taxpayer information.

The precise scope of the new breach therefore remains unresolved. DGFiP has confirmed unauthorized access and theft involving roughly 678,000 individuals and professionals, while the alleged attacker claims possession of a substantially larger dataset. Investigators are still working to establish the exact volume and nature of the stolen information.

Leave a Reply