An attacker used stolen login credentials belonging to staff at France's General Directorate of Public Finances (DGFiP) and to an authorised outside party to take tax data on hundreds of thousands of taxpayers and businesses in June and July 2026. Nobody noticed the theft until the actor, using the alias "ZeroBytes", advertised the data on a cybercrime forum on 12 August, about seven weeks after the first batch left DGFiP systems. Accounts of the scale differ. DGFiP first put the total at 678,000 individuals and professionals (Help Net Security, The Next Web). Its later FAQ gives roughly 600,000 (The Register). The breakdown cited in the ANSSI incident report and in DGFiP's updated figures is about 353,000 individuals and 252,000 businesses (The Hacker News, Mac4Ever). ZeroBytes claimed data on more than 2 million people. That claim has not been verified. A 20-page report from France's national cybersecurity agency ANSSI, published on 29 September, found the intrusion "was not the consequence of a sophisticated attack". That contradicts the ministry's explanation in August.
This incident is separate from the FICOBA bank-account registry breach covered earlier. DGFiP runs both systems, but none of the reporting here links the two. The systems affected here are the E-Contact messaging tool on impots.gouv.fr and cadastral (land registry) records. The timeframe is June to August 2026, and the actor claiming the theft is ZeroBytes.
What Happened
According to reporting on the ANSSI report, the investigation covered malicious activity on DGFiP systems between May and August 2026. It centred on two data thefts that ZeroBytes claimed on 12 and 13 August (Mac4Ever).
- Early May: ANSSI found suspicious logins beginning in early May. This was the first of two separate routes the attacker used, and it eventually led to E-Contact (The Hacker News).
- Over about three months: The attacker collected several dozen username and password pairs belonging to DGFiP agents (01net, Mac4Ever).
- Late June: The E-Contact data was taken after several weeks of exploring DGFiP systems, about seven weeks before the August claim (Mac4Ever, The Hacker News). A Senate note dated 4 September, as reported by bdor.fr, says the stolen credentials of a National Education (Éducation nationale) employee were used between 23 and 25 June to get into the State Interministerial Network (RIE), the shared network connecting several government systems. That account comes from a single OTHER-tier outlet summarising the Senate note, and it describes three separate attacks between June and August.
- 27 July to 8 August: A second theft hit cadastral data. It started from a compromised computer belonging to a surveyor (géomètre-expert) at a private firm (Mac4Ever).
- 12 to 13 August: ZeroBytes claimed the thefts publicly and offered the database for sale. The actor wrote that they were "still logged into the panel" and would sell that access too (Help Net Security).
- Mid-August: DGFiP said it had suspended every account involved as soon as it detected the intrusions. It added that its access checks at the time "did not reveal that these intrusions had led to data theft, due to the sophistication of the attack" (Help Net Security). Prime Minister Sébastien Lecornu then ordered ANSSI to carry out an in-depth audit (The Hacker News, 01net).
- Week of 17 August: DGFiP began notifying affected taxpayers by email and post (The Register).
- 24 and 29 September: ANSSI delivered its report on 24 September, and it was published on 29 September (Mac4Ever).
The ANSSI findings directly contradict the ministry's August account. The agency concluded that the compromise came from "the exploitation of weaknesses in three areas": identity, architecture and detection (01net).
What Was Taken
The figures have changed over time, and DGFiP has not explained why.
| Source | Figure |
|---|---|
| DGFiP, 14 August statement (via Help Net Security, The Next Web) | 678,000 individuals and professionals |
| FrenchBreaches monitoring platform (via TechRepublic) | ~678,000 records: ~393,000 individuals, ~286,000 professionals (Reuters noted the ministry had not confirmed these) |
| DGFiP FAQ, later in August (via The Register) | ~600,000 total |
| DGFiP and ANSSI report (via The Hacker News, Mac4Ever) | ~353,000 individuals and ~252,000 businesses |
| ZeroBytes claim (via Help Net Security) | 252,149 records covering "more than 2 million people", taken from a portal the actor said held ~20 million citizens |
Individuals: tax ID number, email and postal addresses, phone numbers, marital status, household composition and number of dependents, family quotient, reference taxable income, withholding tax rate, and a list of messages exchanged with DGFiP. For fewer than about 250 people, the content of those messages may also have been taken (The Hacker News, The Register). TechRepublic, citing Brussels Signal, also lists dates of birth. Other sources do not confirm that.
Businesses: company name, SIREN number, address and basic message metadata. For fewer than 2,076 businesses, message content may have been seen (The Hacker News).
Cadastral data: property addresses and floor areas. DGFiP says this information was already public (The Register, The Next Web).
Not affected: DGFiP says taxpayers' personal and professional impots.gouv.fr accounts were not compromised, and no taxpayer usernames or passwords were taken (The Hacker News, The Next Web).
Why It Matters
- Single-factor logins can still reach national tax data. A few dozen stolen passwords were enough to get into a system holding income, household and withholding data on millions of citizens. ANSSI found no brute force and no credential stuffing. The attacker simply had working passwords (01net).
- Third-party access widens the attack surface. Surveyors, notaries, bailiffs and local authorities all have legitimate access to DGFiP systems. Each of those logins is another way in, and at least one of them was abused here (The Next Web, Mac4Ever).
- Monitoring failed, not just prevention. DGFiP saw and cut off the suspicious access but did not work out that data had been exfiltrated. It learned the scale only when the attacker advertised the data. An organisation whose breach disclosure depends on the attacker posting about it has a detection gap.
- "Sophisticated attack" framing collapsed under audit. The ministry blamed sophistication in August, and ANSSI rejected that in September. Defenders and regulators should treat early "sophisticated actor" claims with caution until an independent review is done.
- Follow-on fraud is likely. DGFiP itself warned that the data could make phishing, impersonation, CEO fraud and fake bank-detail scams more convincing (The Register). Tax ID, income and withholding rate together give criminals a strong pretext for fraud.
The Attack Technique
Initial access: ANSSI says the credentials were "probably" stolen by infostealer malware on computers DGFiP did not manage, including agents' personal devices (01net). The Senate note, as reported by bdor.fr, also points to an infostealer as the likely source for the credentials used to enter the RIE.
MFA weaknesses: Mac4Ever reports that ANSSI found no strong authentication on some access paths. In the cadastral theft, the compromised surveyor's workstation allowed the attacker to get around two-factor authentication delivered by email. ZeroBytes separately claimed an "MFA bypass technique" (Help Net Security). That fits a scenario in which an infostealer on the endpoint captures both the password and the email-delivered code, or the session itself.
Lateral movement: ANSSI criticised weak separation between networks and applications (The Hacker News, Mac4Ever). Once in, the attacker could explore DGFiP systems for weeks before reaching E-Contact.
Exfiltration: The data was pulled through legitimate application interfaces using valid accounts. ZeroBytes complained that the portal was "horrible to scrape" and that a full extraction would have taken months (Help Net Security). That suggests slow, application-level harvesting rather than bulk database dumps, and this kind of activity blends in with normal agent use unless query volume is being monitored.
Detection: ANSSI says suspicious signals went unnoticed (Mac4Ever). DGFiP's own access review after the accounts were suspended failed to show that data had been taken.
What Organizations Should Do
- Require phishing-resistant MFA for every staff and third-party account that reaches sensitive data. Email and SMS codes do not protect you if the endpoint is compromised. Use FIDO2 or certificate-based authentication, especially for external partners.
- Block sensitive applications from unmanaged devices. Use device posture checks or conditional access so that a password taken from an agent's home PC cannot open citizen or customer records.
- Monitor infostealer log markets for your domains. Check stealer-log feeds for staff and contractor credentials, and rotate credentials and revoke sessions as soon as a hit appears.
- Separate networks and applications. Access to a shared government or corporate network should not give a path to high-value applications. Put identity-aware controls in front of each sensitive system.
- Alert on how much data an account pulls, not just on logins. Set baselines for each user's record lookups and exports in applications like E-Contact. Flag sustained high-volume lookups and access to many unrelated taxpayers or customers.
- Treat account suspension as the start of an investigation. When you cut off suspicious access, reconstruct everything the accounts did from application logs before you conclude that no data was taken.
Sources: French Tax Data Theft Using Stolen Staff Passwords Went Undetected... | France’s tax authority admits hackers made off with data on 678,000... | French tax authority says break-in exposed data of 600K, including... | Piratage des impôts : l'ANSSI révèle ce qu'il s'est vraiment passé... | France’s tax agency lost data on 678,000 people to a stolen login | Piratage des impôts : l’ANSSI détaille les failles qui ont permis l... | French Tax Authority Breach Exposes Sensitive Taxpayer Data | Piratage du fisc : le Sénat révèle comment les données des Français...