Data Breaches

French Tax Authority Confirms Breach Exposing 678,000 Taxpayer Records

French Tax Authority Confirms Breach Exposing 678,000 Taxpayer Records

France’s tax authority, the Direction Générale des Finances Publiques confirmed on 14 August 2026 that attackers had breached its information systems and stolen data belonging to 678,000 taxpayers. The compromised records include personal and business information. The DGFIP stated that the breach did not grant attackers access to secure taxpayer accounts though that distinction offers limited comfort, the stolen data is detailed enough to support targeted phishing campaigns and business identity fraud.

Reuters confirmed the breach via a Finance Ministry statement. Le Monde reported that a criminal actor had advertised the dataset for sale before the DGFIP acknowledged the incident publicly which is consistent with a pattern the agency would have preferred to control. The Record from Recorded Future News reported that the hacker initially claimed 600,000 victims, the DGFIP’s confirmed figure of 678,000 is higher. The Register noted the attacker advertised up to 2 million records which the DGFIP has not confirmed. Treat the 2 million figure as unverified until the ministry provides a fuller accounting.

French prosecutors opened a formal investigation on 15 August 2026 according to RFI. No arrest has been announced.

What Was Taken and What Was Not

The DGFIP confirmed that personal and business data was exfiltrated. The ministry has not published a full field-by-field breakdown of the stolen records which makes precise risk assessment difficult for affected individuals. Based on the categories of data the DGFIP holds for taxpayers, exposure likely includes names, addresses, tax identification numbers and financial declarations, though the ministry has not confirmed this specifically.

The DGFIP was explicit on one point, the attackers did not gain access to secure taxpayer accounts. That means passwords and direct account credentials are not in scope. It does not mean the stolen data is harmless. Tax records contain enough verified personal and financial detail to make fraud attempts highly convincing particularly against business owners and self-employed individuals whose information combines personal identity with company financials.

No CVEs have been disclosed. The attack vector has not been confirmed publicly by the DGFIP or French prosecutors.

The Gap Between the Hacker’s Claim and the Official Count

The discrepancy between 600,000, 678,000 and 2 million records is worth scrutinising. Attackers advertising stolen datasets routinely inflate volumes to increase sale value. The DGFIP’s confirmed figure of 678,000 is presumably based on its own forensic review of what was accessed and that is the number that should be reported. The Register’s 2 million figure sourced from the attacker’s own advertisement, has not been corroborated by any government source. Repeating it as fact would be inaccurate.

The investigation is at an early stage. The confirmed victim count may change as forensics progresses.

No Attribution Has Been Established

French prosecutors have opened an investigation but have not publicly identified a suspect or attributed the attack to any group or state. The source material describes this as a sophisticated attack. That framing, without a technical basis, is not useful. No security researcher or government agency has published technical indicators connecting this breach to a known threat actor. Attribution claims that emerge in the coming days should be treated with caution until they are grounded in forensic evidence rather than speculation about who attacks French government infrastructure.

For Individuals and Businesses in the Affected Dataset

The DGFIP has not yet published formal guidance for affected individuals beyond confirming the breach. Until it does, the immediate steps are practical ones.

  • Any communication claiming to be from the French tax authority in the coming weeks should be verified directly via impots.gouv.fr before acting on it. The stolen data makes spear-phishing attempts straightforward to construct.
  • Businesses with French tax registrations should alert their finance teams that fraudulent correspondence impersonating the DGFIP is a credible near-term risk.
  • Individuals should check French credit reporting services for anomalous activity particularly if their data includes business registration details.

The DGFIP’s official breach communications will be published at impots.gouv.fr. Check there for updates rather than relying on third-party summaries.

Nordic Companies with French Operations

The source material suggests Nordic companies operating in France may be affected. That is plausible but cannot be stated as confirmed fact: the DGFIP has not published a breakdown by nationality or company jurisdiction and no named Nordic firm has been identified in the breached dataset. If your company files tax declarations in France and holds a DGFIP account, your records may be in scope. The same phishing and fraud risks that apply to French domestic businesses apply equally to foreign entities registered with the DGFIP.

Any Nordic company that receives correspondence from French tax authorities in the coming months should verify its authenticity through official channels before transferring funds or disclosing additional information.

References

  1. French Taxpayers’ Data Stolen in Cyber Attack, French Finance Ministry Says
  2. French Taxpayers’ Data Stolen in Hack of Finance Ministry
  3. France Investigates Tax Authority Breach After Hacker Claims 600,000 Victims
  4. French Tax Authority Admits Data Heist After Crook Touts 2M Records
  5. France Probes Unprecedented Cyberattack After Tax Data of 678,000 Users Stolen
  6. Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers

This post is also available in: Svenska

Erik Berg

Erik Berg is CTO and Principal Security Architect at eBuilder Security, with more than a decade in blue team security operations across the private and public sectors, and a focus on emerging threats including the security risks that come with AI.