Cyber & AI intelligence
Wasteland.
Briefs indexed2441
Issues26
Published Mondays07:30 CT
▣ Breach DGFIP-FRENCH-TAX 2026-09-06

DGFiP: Credential Abuse Breach Claimed by ZeroBytes

"France's Ministry of Economy and Finance has confirmed that an attacker gained illegitimate access to information systems at the Direction générale des Finances publiques (DGFiP), the national tax and public finance…"

France's Ministry of Economy and Finance has confirmed that an attacker gained illegitimate access to information systems at the Direction générale des Finances publiques (DGFiP), the national tax and public finance administration, and viewed and extracted data on individuals and businesses. The ministry's own accounting puts the confirmed figure at 678,000 individuals and professionals, with the intrusions occurring in June and July 2026 and going undetected as data theft until the attacker advertised the material publicly on 12 and 13 August. Public reporting of the scale varies considerably: the ministry states 678,000 (per VATupdate's citation of economie.gouv.fr and the DGFiP press service, and per EUToday and The Next Web), SecurityWeek reports "approximately 680,000," TechShots reports that cyber-tracking platforms put the potentially affected population at "nearly 700,000," while the actor behind the claim asserted figures ranging from more than 600,000 (per The Record) to over two million property owners in a separate cadastral dataset (per CyberInsider). No count is final. DGFiP has said repeatedly that it is still working to establish the exact scope.

What Happened

The sequence is unusual and worth reading carefully, because the detection story is the story.

According to The Record, citing the Economy Ministry's statement issued late on Thursday 13 August, an attacker obtained unauthorized access to DGFiP systems in late June after "stealing or misusing someone's identity," and that access was detected and cut off in late June. CyberInsider dates the public disclosure to 13 August, one day after the threat actor publicly claimed the intrusion.

The critical detail, reported consistently by EUToday, The Next Web and VATupdate: when DGFiP severed the access in June, the access checks it ran at that point showed no evidence that data had left the environment. The agency believed it had interrupted an intrusion, not suffered a theft. Only after the actor's public claims on 12 and 13 August did subsequent investigation establish that data had in fact been consulted and extracted. The ministry attributes that initial miss to the sophistication of the attack.

Accounts differ on whether this was one incident or two. SecurityWeek and VATupdate describe access spanning "June and July." IMI Daily is more explicit, reporting two separate intrusions, one at the end of June and a second at the end of July, with the second hitting land registry records and covering what DGFiP counts as 200,000 accounts. The Record's earlier reporting, published before the fuller ministry assessment, describes only the late-June event. Readers should treat the two-incident framing as the more complete picture, consistent with the ministry's June-and-July language, while noting that the 200,000 land-registry figure comes from a single OTHER-tier source.

FrenchBreaches, a French data-leak monitoring site, first surfaced the claim and attributed it to an actor using the alias ZeroBytes. Both The Record and IMI Daily identify the same handle; IMI Daily reports the material was offered on a darkweb data resale forum, and SecurityWeek describes the actor boasting on a hacking forum.

DGFiP has notified France's data protection authority CNIL, said it would file a criminal complaint, imposed additional access restrictions, and committed to contacting each affected individual directly to explain what was exposed and what precautions to take. IMI Daily reports that investigators are working with ANSSI, the French national cybersecurity agency, to establish the true scope.

What Was Taken

The ministry has been specific about the categories, which matters more than the headline count.

For individuals: name and personal identifying information, revenu fiscal de référence (reference taxable income), quotient familial (family quotient, a proxy for household composition and dependents), and withholding tax rate. For businesses: registered company name and SIREN identifier. Separately, cadastral records covering property addresses and floor areas were consulted.

The Record reports the hacker additionally claimed tax identification numbers, email addresses, family circumstances and tax status details for more than 600,000 people, a claim whose authenticity has not been independently verified.

The ministry has been equally specific about what was not taken, and this is a meaningful limitation. Personal and professional accounts on impots.gouv.fr were not compromised. No taxpayer usernames and no passwords were exfiltrated. SecurityWeek confirms the same.

On composition, the sources conflict directly. FrenchBreaches, per IMI Daily, counted 392,867 individuals and 285,570 businesses in the June file, and its review of a sample identified 26,805 individuals with a revenu fiscal de référence at or above €100,000, 386 above €1 million, and eight above €10 million. DGFiP disputes that split, telling IMI Daily that slightly more businesses than individuals appear in the affected population, reversing the ratio. That disagreement is unresolved.

The largest claimed dataset is also the least corroborated. CyberInsider reports that ZeroBytes claimed access to DGFiP's Serveur Professionnel de Données Cadastrales (SPDC), a professional cadastral data system, reachable via apexappliext.dgfip.finances.gouv.fr, and claimed 252,149 extracted records corresponding to 2,041,778 people because a single property record can list multiple holders. The claimed sample fields include names, gender, dates and places of birth, mailing addresses, MAJIC property identifiers, municipalities, cadastral sections and parcel numbers, property rights information, and links between co-owners. This is an unverified actor claim reported by a single OTHER-tier source and should not be treated as confirmed. It is, however, the claim that would change the severity of this incident most if it holds.

Why It Matters

Strip out the passwords, and defenders sometimes conclude a breach is low impact. That reasoning fails here.

What the attacker took is a high-fidelity financial profile: verified income, household composition, withholding rate, property address and surface area, company identity. EUToday makes the operational point plainly. A fraudster who can cite a target's real reference income, actual SIREN number, or genuine property characteristics while asking them to verify a refund, correct a declaration, or open an attached government document is operating far above the noise floor of generic phishing. The stolen data does not grant account access. It manufactures the credibility needed to obtain account access later, by asking the victim directly.

The wealth-stratification angle sharpens this. Per IMI Daily, the revenu fiscal de référence sets the entry threshold for France's contribution différentielle sur les hauts revenus, and FrenchBreaches' sampling suggests tens of thousands of high-income individuals sit in the file, with a small tail above €1 million and €10 million. A dataset that lets an adversary sort a national population by verified wealth, then cross-reference it to a physical property address, has obvious value for targeted fraud, extortion, physical crime, and, at the state level, for coercion and recruitment targeting.

There is also a sovereign-trust dimension. This is a tax authority whose data collection is compulsory. Citizens cannot opt out, cannot decline to supply income data, and cannot choose a different provider. Breaches of that class of holder carry a political cost that commercial breaches do not.

SecurityWeek places the incident in a broader pattern, noting it followed roughly a month after Romania's National Agency for Cadastre and Property Registration (ANCPI) was attacked by an actor known as ByteToBreach, who stole employee credentials and internal documents, attempted extortion, and, when that failed, reportedly wiped encrypted data and disrupted the country's real estate market. European land registries and tax administrations are being worked as a category, not as isolated targets.

The Attack Technique

There is no zero-day in this story, and that is the finding.

The ministry states, per VATupdate, EUToday and The Next Web, that the intrusions were carried out using the compromised credentials of a DGFiP employee and of an authorised third party. The Record's initial account describes access obtained after "stealing or misusing someone's identity"; CyberInsider frames it as an identity impersonation scheme. All of these describe the same thing: valid logins, used by the wrong person.

The authorised-third-party leg deserves attention. As The Next Web explains, an authorised third party in this context is an external body granted a route into DGFiP systems. Notaries, bailiffs and local authorities all hold such access. Every one of those relationships extends the set of credentials that will open the door, and every one of them sits outside DGFiP's direct control over endpoint hygiene, credential storage and offboarding.

Two further technical claims come from the actor rather than the government. The Next Web reports, citing Help Net Security, that the attacker described bypassing multi-factor authentication. CyberInsider reports the same claim in the context of authenticating to the SPDC cadastral service. Neither has been confirmed by DGFiP or ANSSI. If accurate, it means MFA was present and was defeated or circumvented, which is a materially different problem from MFA being absent.

Per FrenchBreaches, relayed by The Record, the actor claimed to have reached internal servers, used that foothold to connect to the agency's VPN, and then queried an internal search tool to pull information on individuals. That is a coherent post-authentication path: legitimate credentials, legitimate remote access, legitimate internal application, abused at scale. It also explains the detection failure. Nothing in that chain looks like an exploit. It looks like a busy employee and an approved external partner doing lookups, which is precisely why volumetric and behavioural controls, not signature-based ones, are what would have caught it.

What Organizations Should Do

  1. Treat valid-credential access as the primary intrusion scenario, not the exception. Both legs of this breach used legitimate logins. Audit whether your detection engineering assumes a malicious binary, an exploit signature, or an anomalous process. If it does, you are instrumented for the wrong attack.

  2. Instrument volumetric abuse of internal lookup and search tools. The extraction here appears to have run through an approved internal query tool. Baseline normal query volume per user, per role and per hour, alert on multiples of that baseline, and rate-limit bulk retrieval regardless of who is asking. Hundreds of thousands of record reads by one account should page someone.

  3. Inventory and constrain every authorised third-party access path. Enumerate the external bodies, partners, contractors and delegated authorities holding routes into your environment. For each, verify credential storage practice, MFA enforcement, IP or device binding, session duration, data scope, and offboarding. Scope third-party accounts to the minimum dataset and the minimum query rate their function actually requires.

  4. Assume MFA can be circumvented and layer behind it. The actor claims to have bypassed MFA. Move toward phishing-resistant factors (FIDO2/WebAuthn) for privileged and third-party access, and add device attestation, impossible-travel and session-anomaly checks so that a defeated factor is not a clean path to data.

  5. Rebuild your post-containment forensic playbook around exfiltration proof, not access termination. DGFiP cut the access in June, checked, found nothing, and learned the truth from a criminal forum in August. Killing a session is not the end of an investigation. Require egress volume reconstruction, application-layer query log review and data-flow analysis before any incident is closed as "access interrupted, no loss."

  6. Retain and centralise application query logs long enough to answer the question later. If your retention window is 30 days, an intrusion discovered eight weeks after the fact is unanswerable. Retain authentication, VPN and internal-application query logs for at least a year, in a location the attacker's credentials cannot reach.

  7. Prepare downstream fraud messaging in advance for affected populations. DGFiP has committed to individual notification. Any organisation holding financial or property data should pre-write guidance telling affected users that criminals may quote genuine income, company or property details, and that the organisation will never ask them to verify a refund or open a tax document via an emailed link.

Sources: TECHSHOTS Hackers Breach French Tax Agency, Exposing Data... | France investigates tax authority breach after hacker claims 600,00... | 680,000 Impacted by French Tax Authority Data Breach - SecurityWeek | France’s tax agency lost data on 678,000 people to a stolen login | French Tax Authority Confirms Two Data Thefts, 678,000 Income Recor... | France Says DGFiP Breach Exposed Records of 678,000 People and Busi... | French tax agency confirms breach as hacker claims 2 million victims | France Confirms DGFiP Data Breach Affecting 678,000 Individuals and...