Skip to content
Data breachContained

DGFiP taxpayer data breach (August 2026)

France's tax authority confirmed that attackers using stolen or impersonated credentials accessed its systems during June and July 2026 and stole personal and tax data belonging to about 678,000 individuals and businesses.

Victim
Direction Générale des Finances Publiques
records
678.0K
users
678.0K

On 14 August 2026, France's tax authority — the Direction Générale des Finances Publiques (DGFiP) — confirmed that attackers had breached its information systems and stolen data belonging to roughly 678,000 taxpayers. The authority disclosed the incident after a threat actor advertised a stolen database for sale on a hacking forum.

What happened

According to DGFiP, the intrusion relied on stolen or impersonated credentials belonging to a DGFiP employee and an authorised third party. The unauthorised access took place during June and July 2026. The breach came to light after a threat actor using the handle "ZeroBytes" claimed the attack and, on 12 August, listed the stolen database for sale on the PwnForums forum, touting a far larger record count than DGFiP ultimately confirmed. The authority issued a press release confirming the breach on 14 August.

The stolen data covered approximately 390,000 individuals and 285,000 businesses and included names, dates of birth, addresses and land-registry information, along with tax details such as reference tax income, family-quotient information and withholding-tax rates.

Crucially, DGFiP stressed that taxpayers' online "Finances publiques" accounts were not compromised, and that personal and business usernames and passwords were not exposed in the incident.

Impact

  • Personal and tax data for about 678,000 individuals and businesses was stolen.
  • Exposed fields — identity, address, land-registry and income data — create meaningful fraud and identity-theft risk, and a strong basis for tax-themed phishing against French taxpayers.
  • Online tax accounts and credentials were reported unaffected, limiting the risk of direct account takeover.

Why it matters

The DGFiP breach is a reminder that credential compromise of trusted insiders and third parties — not a headline software exploit — is often enough to reach a government's most sensitive citizen data. It is also the second significant incident to strike France's tax administration in 2026, following an earlier breach of the FICOBA bank-account registry, underscoring the persistent targeting of national tax systems. For a public body holding identity, property and income records on essentially the entire adult population, even a breach limited to descriptive data hands criminals precisely the details needed to make impersonation and tax-fraud lures convincing.

Timeline

  1. Unauthorised access occurs using stolen or impersonated credentials belonging to a DGFiP employee and an authorised third party.

  2. A threat actor using the handle 'ZeroBytes' claims the attack and lists a stolen database for sale on the PwnForums hacking forum.

  3. DGFiP confirms the breach in a press release, putting the number of affected individuals and businesses at about 678,000.

Sources

  1. securityweek.comhttps://www.securityweek.com/680000-impacted-by-french-tax-authority-data-breach/
  2. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/french-tax-authority-data-breach-affects-678-000-individuals/
  3. theregister.comhttps://www.theregister.com/security/2026/08/14/french-tax-authority-admits-data-heist-after-crook-touts-2m-records/5287885

Related incidents

Data breachContained

Leak at Direction Générale des Finances Publiques

France's tax authority (DGFiP) disclosed on 18 Feb 2026 that an attacker who hijacked a civil servant's credentials accessed FICOBA, the national bank-account registry, exposing identity, address, IBAN and in some cases tax-ID data for about 1.2 million account holders.

Victim
Direction Générale des Finances Publiques
Records
1.2M