French tax authority data breach confirmed, scope remains under review
France confirmed taxpayer data was accessed and extracted in a June cyberattack, while alleged record totals remain unverified.
By Dominic Okoye · Staff Writer
· 3 min read
France’s Finance Ministry has confirmed a French tax authority data breach in which an intruder accessed systems at the General Directorate of Public Finances, or DGFiP, and extracted data concerning individual and professional taxpayers. The ministry has not put a number on the people affected or identified the data fields involved, leaving the widely circulated claims about the breach’s size unverified.
The disclosure followed an August 12 public claim by an actor using the name ZeroBytes, who said it had accessed DGFiP systems in late June. DGFiP said its initial investigation established that unauthorized access had taken place at the end of June and had enabled the viewing and removal of taxpayer data, according to the Finance Ministry’s statement reported by Reuters.
DGFiP said it had cut off the access during an audit at the end of June. It also rejected the alleged attacker’s assertion that access to its systems was still active. The agency said it imposed further restrictions after the claim became public and is conducting a more detailed investigation.
How many people were affected by the French tax authority data breach?
There is no confirmed total. ZeroBytes advertised what it described as a database involving more than 2 million French taxpayers, The Register reported, but DGFiP did not validate that figure. Reuters reported that FrenchBreaches, citing information attributed to the alleged hackers, put the number at close to 700,000.
A separate listing tracked by Dark Web Informer named 678,438 purported records. That outlet described the allegation as unverified and said the listing did not provide a field list or visible data sample. The varying counts are claims tied to the alleged intruders or breach trackers, not figures established by French authorities.
The purported attacker also claimed it used stolen credentials and bypassed multi-factor authentication. DGFiP has not confirmed an entry method. It likewise has not authenticated the advertised database or said what categories of taxpayer information were consulted or taken.
What happens next for affected taxpayers?
The ministry said investigators are working to establish the specific data involved and the exact users affected. It said people identified as affected would receive individual notices explaining what information may have been viewed or extracted, along with precautionary steps where relevant. DGFiP also said it would notify France’s data-protection regulator, CNIL.
For operators handling sensitive customer or employee records, the incident illustrates why enterprise security depends on access controls, monitoring and incident response rather than any single tool. In this case, the government has confirmed the consequence, unauthorized consultation and extraction of data, while the breach’s scale and technical path remain unresolved.
The case also adds to a series of reported public-sector cybersecurity incidents in France this year. That broader pattern does not establish the scope of the DGFiP intrusion, which remains under investigation.
This story draws on original reporting from The Register.