
The French Ministry of the Economic system and Finance has disclosed a knowledge breach after an attacker accessed the Basic Directorate of Public Funds (DGFiP) methods and stole knowledge belonging to 678,000 people.
This incident was found after a risk actor utilizing the “ZeroBytes” deal with claimed the assault and listed a stolen database on the market on August 12 on the PwnForums hacking discussion board.
“The in-depth investigations carried out since August 12, 2026, have established that, previous to their interruption, these entry factors had been used to seek the advice of and extract knowledge regarding a complete of 678,000 people and professionals, together with tax knowledge comparable to reference tax revenue, household quotient, and withholding tax charge, and, for companies, knowledge comparable to their firm identify and SIREN quantity,” the French Finance Ministry said.
“Cadastral knowledge referring to addresses and property sizes have been additionally accessed. As quickly as these knowledge breaches have been recognized, the French Public Funds Directorate (DGFIP) notified the French Information Safety Authority (CNIL). The net accounts of particular person {and professional} customers weren’t compromised. Consumer IDs and passwords weren’t compromised.”
After detecting the assault, the French tax administration shut down entry to delicate data methods and continues investigating the incident with the assistance of the Nationwide Cybersecurity Company of France (ANSSI) to evaluate the breach’s full influence.
In a put up on the hacking discussion board, ZeroBytes additionally claimed they gained entry to the Serveur Professionnel de Données Cadastrales (SPDC), an on-line platform operated by the French tax authority that gives entry to the nation’s central land registry and property possession data.
Whereas the portal gave them entry to knowledge on roughly 20 million French residents, the risk actor claims they solely managed to steal 252,149 data containing knowledge on over 2 million individuals.
“We could not end the extraction as a result of truthfully, it is simply horrible to scrape and would have taken months. I am nonetheless logged into the panel, so if you’d like, you should purchase it together with the database,” they mentioned. “I am not going to promote this one for very a lot anyway. And as at all times, no point out from France about this incident.”
The French Finance Ministry added on Friday that it’s going to contact all affected people beginning subsequent week by way of e mail or letter, with particulars on what knowledge could have been accessed or stolen and the mandatory precautions to take.
That is simply the newest in a spree of cyberattacks and knowledge breaches which have impacted a number of French authorities companies in current months.
In January, the French knowledge safety authority fined the national employment agency France Travail €5 million after hackers stole the private data of 43 million individuals. One month later, the French Ministry of Finance disclosed another data breach affecting over 1.2 million consumer accounts after hackers stole a database from the nationwide checking account registry (FICOBA) methods.
Extra not too long ago, France Titres, the federal government company in France for issuing and managing administrative paperwork, additionally disclosed a data breach after a risk actor put up on the market a database containing 19 million data allegedly stolen from the Nationwide Company for Safe Paperwork (ANTS).
Total prevention scores can cover what occurs after preliminary entry. As soon as attackers are utilizing legitimate credentials, prevention drops sharply.
The Blue Report 2026 measures defenses approach by approach throughout 338 million simulations run in buyer manufacturing environments.

