French Tax Authority Breach Exposes Data of 678,000 Individuals and Businesses
Attackers used stolen credentials to infiltrate the DGFiP, extracting sensitive income and property records.
The French Ministry of the Economy and Finance has confirmed a significant data breach at the General Directorate of Public Finances (DGFiP), exposing the records of approximately 678,000 individuals and businesses. The incident highlights a critical vulnerability in administrative access controls within one of France's most sensitive government departments.
According to official reports, the breach occurred during June and July when attackers gained unauthorized access to internal systems. The intruders utilized stolen credentials belonging to both a DGFiP employee and an authorized third party. Because the attackers used legitimate credentials, their activity initially mimicked standard administrative workflows, allowing them to bypass detection systems for a period before the access was eventually interrupted. While a hacker known as ZeroBytes claimed that 2 million victims were affected, the French government maintains the official count at 678,000.
Scope of Compromised Data
The extracted data varies by the type of entity affected. For individual taxpayers, the compromised information included reference taxable income, withholding-tax rates, and the family quotient. For businesses, the breach exposed company names and SIREN identifiers. Additionally, the attackers accessed cadastral data, which includes specific property addresses and surface areas.
Government officials emphasized that the breach did not extend to the primary authentication layers of the public-facing infrastructure. Usernames and passwords for taxpayers and businesses were not stolen, and the secure online tax spaces remained uncompromised throughout the incident.
The Risk of Targeted Fraud
Despite the fact that passwords were not leaked, the nature of the stolen data presents a severe security risk. The extraction of precise taxable income and property details provides criminals with the raw material needed for highly sophisticated spear-phishing campaigns. By referencing accurate financial or property data, attackers can craft convincing impersonation frauds, posing as government officials to trick victims into revealing passwords or making fraudulent payments.
This breach underscores a growing trend where attackers target the "administrative middleman"—third-party partners or employees with broad access—rather than attempting to crack encrypted user databases. When legitimate credentials are used, the perimeter defense becomes effectively invisible.
Next Steps and Monitoring
Investigators continue to analyze the full extent of the data extraction and the methods used to acquire the initial credentials. While the immediate access has been severed, the permanent nature of the leaked data means that affected individuals and businesses remain at risk of targeted social engineering for the foreseeable future. Authorities are expected to monitor for the appearance of this specific dataset on dark web forums to determine if it is being sold or traded among cybercriminal groups.