France's Ministry of the Economy and Finance has confirmed that intruders reached the systems of the Direction générale des Finances publiques (DGFiP), the national tax administration, and extracted income and property data belonging to individuals and businesses. The ministry's own statement puts the confirmed figure at 678,000 individuals and professionals from an intrusion at the end of June 2026. Reporting on the total scale varies widely: The Register notes the attacker, using the handle "ZeroBytes," advertised a database of more than 2 million taxpayers, The Record's coverage of the initial disclosure was headlined around a 600,000 victim claim, and The Local reports "at least 1 million people" once a second July intrusion into the land registry is counted. What is not in dispute is the timeline. The June access was cut off in June, DGFiP's own audit found no evidence data had left, and the theft only became known when the file went up for sale roughly six weeks later. The Paris Public Prosecutor's cybercrime unit has opened an investigation.
What Happened
Accounts across the sources converge on a two-incident picture, though not all outlets describe both. IMI Daily and The Local both report that DGFiP confirmed two separate thefts: one at the end of June 2026 against the tax system, and a second at the end of July against the land registry platform. The Register's earlier coverage, published on 14 August, describes only the June intrusion, consistent with what the ministry had disclosed at that point.
The June access was obtained through what the ministry originally characterised as "identity theft" (usurpation d'identité). Per the ministry statement quoted by The Register, the access "had been severed at the end of June as part of an audit" but had nevertheless permitted consultation and extraction of data. That is the uncomfortable core of this incident: DGFiP detected and closed the accounts in June, ran access checks that showed no sign of exfiltration, and concluded the matter was contained. The Next Web reports that the agency did not establish that anything had actually left its systems until the attacker said so in August, and that DGFiP attributes the miss to the sophistication of the intrusion.
Public disclosure was forced by the criminal, not the victim. On Wednesday 12 August 2026, ZeroBytes claimed the intrusion and listed the database for sale on a cybercrime forum, identified by BleepingComputer as PwnForums. The ministry issued its first statement the following day, then a fuller accounting on Thursday 14 August, and BleepingComputer quotes the DGFiP saying investigations "conducted since August 12, 2026" established the 678,000 figure. ZeroBytes additionally claimed to retain live access to DGFiP systems and offered that access for sale alongside the data. The ministry publicly disputes this, saying the access was severed in June and that new restrictions were imposed immediately after the forum post.
ZeroBytes separately claimed access to the Serveur Professionnel de Données Cadastrales (SPDC), the DGFiP-operated platform fronting France's central land registry and property ownership records. BleepingComputer reports the actor claimed the portal exposed data on roughly 20 million French citizens but that they extracted only 252,149 records. DGFiP's own count for the second theft, as reported by IMI Daily and The Local, is 200,000 accounts. Those two numbers describe the same event and do not reconcile; treat both as provisional.
The Paris Public Prosecutor's Office opened its inquiry over the weekend, with RFI reporting the case handed to France's Office for the Fight against Cybercrime (Ofac). Prosecutors are investigating fraudulent extraction of data from a state personal information system and suspected participation in a criminal conspiracy to prepare an offence carrying at least five years' imprisonment. Prime Minister Sébastien Lecornu was set to chair an emergency meeting on the incident on Monday, per The Local. CNIL, the French data protection authority, has been notified, and ANSSI is assisting the investigation.
What Was Taken
For individual taxpayers, the confirmed data set is narrow but financially revealing. Per the ministry statement and RFI's account of remarks by Director-General of Public Finances Amélie Verdier, it covers full names, quotient familial (household tax-unit count), revenu fiscal de référence (reference taxable income), and taux de prélèvement à la source (withholding tax rate). For businesses, the exposure is thinner: registered company name, SIREN number, and in most cases publicly available company addresses. Cadastral data covering property addresses and floor areas was also accessed.
DGFiP is emphatic about what did not fall. Online accounts on impots.gouv.fr were not compromised for either individual or professional users, and no usernames or passwords were taken. The stolen records do not, on the agency's account, provide a route into taxpayers' secure accounts.
The composition of the affected population is itself disputed. IMI Daily reports that FrenchBreaches, the monitoring outlet that first surfaced the claim, counted 392,867 individuals and 285,570 businesses in the June file, and that its review of a sample identified 26,805 individuals with a reference income at or above €100,000, 386 above €1 million, and eight above €10 million. DGFiP contests that split, telling reporters that slightly more businesses than individuals appear in the affected population, reversing the ratio FrenchBreaches published. Neither figure should be treated as settled; IMI Daily itself notes investigators are still working with ANSSI to establish what was taken and whose records it covers.
The reference income figure matters more in France than a raw income number would elsewhere. IMI Daily notes it sets the entry threshold for the contribution différentielle sur les hauts revenus, which tops household tax up to a minimum 20% rate, crossing at €250,000 for single filers and €500,000 for couples. A verified, government-sourced list of high earners with their household composition and property footprint attached is a targeting data set, not merely a privacy loss.
On total scale, the honest position is a range. DGFiP confirms 678,000 for June and 200,000 accounts for July. The Local reports at least 1 million people across both. ZeroBytes claimed more than 2 million. BleepingComputer's account of the SPDC claim (252,149 records extracted out of roughly 20 million citizens' worth of accessible data) sits between the official and criminal figures. The Local also states that around one fifth of tax accounts were affected in total, a proportion that is difficult to square with the confirmed counts and should be read as an early estimate.
Why It Matters
This is a credential and trust-boundary failure at a national revenue agency, and the sequence of events is more instructive than the headline count.
First, the detection worked and the response still failed. DGFiP found the anomalous access in June, cut the accounts, and audited. The audit's conclusion (no evidence of exfiltration) was wrong, and the agency did not learn it was wrong for six weeks, until a criminal marketplace listing corrected it. Access revocation is not incident closure. If your exfiltration telemetry cannot distinguish "no data left" from "we cannot see whether data left," those are different findings and should be reported differently.
Second, the six-week gap is the entire window of victim exposure. Between late June and 12 August, 678,000 people whose reference income and household composition were in criminal hands had no notification, no reason to elevate scepticism toward inbound contact, and no fraud-monitoring posture. RFI reports that affected parties were to be contacted from early the following week, meaning notification trails the actual compromise by roughly seven weeks for the June set.
Third, the exposed fields are precision-fraud fuel. Name plus verified household income plus withholding rate plus property address and floor area lets an attacker construct a tax or benefits pretext that survives a suspicious recipient's first three questions. French taxpayers should expect impersonation of DGFiP itself, with refund and arrears lures that cite genuine figures the target knows to be correct.
Fourth, this lands in a pattern. The Register's own related coverage catalogues 15.8 million medical records taken from a French health ministry body, a French identity agency breach with claims of 19 million records, and a €42 million fine levied against French telcos over security failings preceding a 24 million customer breach. RFI reports tax officials described this attack as more complex than incidents they had faced previously. A sustained campaign against French public-sector data holdings is the reasonable working assumption, and organisations holding French citizen data should assume their identity providers are being probed now.
The Attack Technique
There is no zero-day in this story. Per The Next Web's account of the Bercy statement, the attacker used the stolen identifiers of a DGFiP employee together with those of an authorised third party. That second category is the structurally important one. An authorised third party here means an external body granted a route into DGFiP systems: notaries, bailiffs, and local authorities all hold such access. Every one of those relationships adds credentials outside the agency's own identity governance, on endpoints the agency does not patch, protected by MFA the agency does not enforce.
ZeroBytes claimed to have bypassed multi-factor authentication. The Register reports the actor said they gained access using stolen credentials plus an MFA bypass technique; The Next Web attributes the same MFA-bypass claim via Help Net Security. This remains an attacker claim rather than a government confirmation, and the specific technique (phishing-proxy session theft, push fatigue, fallback-factor abuse, or enrolment of a new factor) has not been disclosed by any source. The Local adds a further unconfirmed criminal claim: that the actors had access to a VPN used by tax officials. Given that only The Local carries this, treat it as reported-not-confirmed.
The SPDC angle shows the second technique at work: abuse of legitimate query capability. If BleepingComputer's account is accurate, the actor sat behind a portal that legitimately exposed data on roughly 20 million citizens and simply queried it, extracting a quarter of a million records before the pattern registered. That is not exploitation; that is a valid session used at abnormal volume, and it is invisible to any control that only asks "is this user authorised?"
The Next Web draws the connection defenders should take away, citing 75,000 Fortinet firewalls reached in June through old passwords rather than any vulnerability: the login is the perimeter now.
What Organizations Should Do
1. Treat third-party and partner logins as your largest unmanaged attack surface. Inventory every external body with a route into your systems (professional intermediaries, local government partners, contractors) and confirm what MFA, device posture, and session controls actually apply to those identities. Federated and delegated access frequently sits outside the policy baseline applied to employees. Where you cannot enforce your standard, apply compensating controls: scoped permissions, per-partner rate limits, and separate monitoring.
2. Assume MFA can be bypassed and instrument for it. Phishing-resistant factors (FIDO2/WebAuthn, certificate-bound sessions) should be the target state for any account touching bulk citizen or customer data. In the interim, alert on the signals that precede bypass: new factor enrolment, fallback-method use, impossible-travel token replay, and session-token reuse from a different network or user agent.
3. Add volumetric detection on legitimate query paths. The SPDC-style abuse case is a valid user pulling far more records than their role requires. Baseline per-user, per-role query and export volume against every interface that fronts a large data set, and alert on deviation rather than on authorisation failures. Consider hard export ceilings with break-glass approval for genuine bulk needs.
4. Never close an incident on absence of evidence. DGFiP's June audit concluded no data had left, and that conclusion was overturned by a forum listing six weeks later. Require incident reports to state explicitly whether exfiltration was ruled out or merely unobserved, and to record whether logging retention and coverage were sufficient to answer the question at all. Where the answer is "we could not tell," keep the incident open and notify on that basis.
5. Verify your data-loss telemetry can survive a credentialed adversary. Retain and centralise access, query, and egress logs for the systems holding your most sensitive records, for a window measured in months rather than days. Confirm that a legitimate account performing legitimate reads at illegitimate scale would leave a durable, searchable trace on the day it happened, not just at the time of alert.
6. Monitor criminal marketplaces as a detection channel, and plan for that discovery path. In this case the earliest reliable indicator of exfiltration was a sale listing. Feed dark web and forum monitoring into your detection pipeline as a first-class source, and pre-build the process for the scenario where a criminal advertisement, not your SIEM, tells you what left.
7. For French taxpayers and businesses specifically: DGFiP states that impots.gouv.fr accounts, usernames, and passwords were not compromised, so there is no forced credential reset. The realistic risk is highly convincing impersonation of the tax administration using accurate income and property figures. Treat any unexpected contact citing your reference tax income, family quotient, or property details as hostile until independently verified through impots.gouv.fr directly, and never through a link or number supplied in the message.
Sources: French tax authority data breach affects 678,000 individuals | French tax authority admits data heist after crook touts 2M records | France investigates tax authority breach after hacker claims 600,00... | France’s tax authority admits hackers made off with data on 678,000... | France probes unprecedented cyberattack after tax data of 678,000 u... | France’s tax agency lost data on 678,000 people to a stolen login | French Tax Authority Confirms Two Data Thefts, 678,000 Income Recor... | Explained: Are you affected by the cyberattack on French tax office