ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

France’s Public Finance Agency Reports Major Data Security Incident

France’s tax administration, the Directorate General of Public Finances, has reported a significant data security incident that compromised the sensitive personal information of approximately 678,000 individuals and professionals.

Linked InXFacebook
bookmark_borderSave to Library

France’s public revenue agency, the Directorate General of Public Finances, has disclosed a major data security incident affecting the sensitive personal information of around 678,000 individuals and professionals.

 

The Directorate General of Public Finances (DGFiP) is France’s tax and public finance administration, responsible for collecting taxes, combating tax fraud, managing public accounts and overseeing government financial operations. It operates under France’s Ministry of Economy, Finance and Industrial, Energy and Digital Sovereignty and plays a key role in managing the country’s public finances.

 

In a data security incident notice on its website, France’s DGFiP said that on August 12 and 13, a malicious actor claimed to have illegally accessed its Internal systems in June and July 2026 using the stolen credentials of a DGFiP employee and an authorised third party. Once the intrusions were detected, DGFiP immediately blocked access to all accounts linked to the incidents.

 

“The in-depth investigations conducted since August 12, 2026 have established that, prior to their interruption, these accesses had been used to consult and extract certain data concerning a total of 678,000 individuals and professionals, including tax data such as reference tax income, family quotient or withholding tax rate, and for companies, data such as their company name or their SIREN. Cadastral data relating to addresses and areas of real estate were also consulted,” DGFiP said.

 

Once the data theft was confirmed, DGFiP reported the incident to France’s data protection authority, CNIL. The agency said that the personal tax accounts of individuals and businesses were not affected, and their usernames and passwords remained secure.

 

Following new findings, DGFiP implemented additional security measures, including temporary restrictions on access to sensitive systems. Investigations are ongoing to determine the data involved and the number of affected users, with DGFiP working closely with France’s economic and financial authorities, SHFDS and ANSSI.

 

The disclosure follows claims by a threat actor using the name “ZeroBytes”, who claimed that it breached DGFiP’s internal network and stole 252,149 records reportedly linked to more than 2 million people. According to FrenchBreaches, the attacker claimed to have accessed internal servers, connected to the agency’s VPN and used an internal tool to search for information on individuals and businesses before their access was blocked.

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543