678,000 Taxpayers Exposed: France's DGFiP Breach and the ZeroBytes Leak
Hackers used a stolen identity to reach inside France's tax authority through an internal VPN, extracting data on 678,000 taxpayers now for sale by a threat actor called ZeroBytes.
On August 13, France’s Economy Ministry confirmed that the country’s tax authority — the Direction Générale des Finances Publiques (DGFiP) — fell victim to a cyberattack that exposed sensitive personal and financial data belonging to individuals and businesses. A threat actor using the alias ZeroBytes subsequently put a database of roughly 678,000 taxpayer records up for sale on a hacking forum. The intrusion was detected in late June during an internal audit; the attacker had been quietly extracting data before access was cut off.
This is not just another breach headline. The DGFiP sits at the core of the French state’s financial machinery, and the stolen dataset is unusually rich: names, tax identification numbers, income and revenue details, family circumstances, contact information, and correspondence with tax officials. Unlike a leaked password, none of this information can be rotated. It will fuel phishing, identity theft, and targeted fraud against French citizens for years — and it lands on top of an already brutal year for French government cybersecurity.
What happened
According to the Economy Ministry’s statement, cited by BFMTV and Reuters, the attacker gained unauthorized access to DGFiP systems in late June “after stealing or misusing someone’s identity.” Reporting from Anadolu Agency, citing the ministry, adds a crucial technical detail: the intrusion involved a compromised internal virtual private network. Once inside, the attacker used an internal taxpayer search tool — software meant for authorized civil servants — to look up and extract records on individuals and businesses.
The unauthorized access was detected and blocked at the end of June during an internal audit. For six weeks, the incident remained undisclosed while investigations proceeded. The breach became public only after a hacker posted a claim of responsibility earlier this week, advertising the stolen data for sale. That disclosure forced the DGFiP’s hand: the ministry confirmed the intrusion late on Thursday, August 13, and the tax authority imposed additional access restrictions to prevent repeat intrusion.
FrenchBreaches, a website that tracks data leaks in France, attributed the claim to a hacker operating under the alias ZeroBytes. The actor claimed more than 600,000 victims; Reuters and other outlets now cite approximately 678,000 affected users, a figure that includes both individuals and professionals. Le Monde reported that the file offered for sale contained just over 600,000 entries, each corresponding to a taxpayer or a business, and that a sample posted by the seller appeared consistent with a genuine extract.
Notably, French officials have not independently confirmed the hacker’s claims or attributed the operation to a specific actor. What is confirmed is the intrusion itself: the ministry’s investigations “verified the intrusion, which enabled the consultation and extraction of personal and professional data.”
What was stolen
The inventory of exposed data, reported by multiple outlets, reads like an identity-theft starter kit:
- Names and family circumstances (marital status, dependents)
- Postal addresses, phone numbers, and email addresses
- Tax identification numbers
- Income and revenue details, including withholding tax rates
- Records of correspondence with tax officials
- Business registration numbers for professional taxpayers
Authorities have not confirmed the full list of exposed fields, and some reports suggested the potential scope could reach into the millions before the audit narrowed the count. One important mitigating fact: according to BFMTV’s reporting, no usernames or passwords were included in the breach, and the impots.gouv.fr portal itself was not directly compromised. The attacker came in through the back office, not the front door.
The response
The DGFiP has laid out a fairly standard post-breach playbook, but with unusual directness:
- Individual notification. People whose data was compromised will be contacted individually and told what information may have been exposed and what precautions to take — rather than learning about it from a hacking forum.
- CNIL notification. France’s data protection authority has been formally notified, opening the path to regulatory scrutiny and potential sanctions under the GDPR.
- Criminal complaint. The agency will file a formal complaint, triggering a judicial investigation.
- Access hardening. Additional restrictions have been imposed on internal access pathways following the public disclosure.
Whether that response satisfies the CNIL — which has grown increasingly willing to fine public institutions — is an open question. Under the GDPR, data breaches affecting fundamental rights at scale can attract penalties proportional to the agency’s budget, and the delay between detection (late June) and public confirmation (August 13) will likely draw attention from regulators and parliament alike.
A pattern, not an outlier
The DGFiP breach is the latest in an alarming series of attacks on French government systems this year:
- April 2026 — ANTS: The National Agency for Secure Documents, which handles passport, national ID card, residence permit, and driver’s license applications, was breached. A hacker claimed up to 19 million records and put them up for sale; France Titres later confirmed at least 18 million records from the national ID document database.
- April 2026 — Education Ministry: An attack on a system used to manage student accounts exposed students’ personal information.
- February 2026 — National Bank Accounts File: Hackers breached part of the database containing records of bank accounts held in France, exposing information linked to roughly 1.2 million accounts out of more than 300 million entries.
- 2026 — arrests: French police arrested a 20-year-old man suspected of carrying out dozens of data breaches involving government bodies, sports federations, and private companies.
Four major incidents in seven months — identity documents, student records, bank accounts, and now tax files — suggest a systemic problem rather than a run of bad luck. The common thread in several of these cases is that attackers are finding ways through internal tools and trusted access pathways rather than breaking encryption or exploiting exotic zero-days. In the DGFiP case, the initial vector was identity theft: the attacker impersonated or stole credentials from someone who already had legitimate access.
Why tax data is uniquely dangerous
Tax records occupy a special position on the spectrum of breached data. A stolen credit card can be cancelled in minutes. A leaked password can be rotated. But the combination of name, address, tax ID, income level, and family situation is permanent, verifiable, and highly contextual. Security researchers quickly flagged the follow-on risks:
- Targeted phishing with perfect context. Attackers who know your income bracket, marital status, and history of correspondence with tax authorities can craft messages that are nearly indistinguishable from genuine administration contact.
- Wealth-targeting. Cryptopolitan noted that the leak puts wealthy individuals — including visible Bitcoin holders who declared crypto gains — at elevated risk of targeted attacks, extortion, and physical burglary.
- Long-tail fraud. Unlike a payment-card dump whose value decays in weeks, tax data retains criminal utility for years, since the underlying facts it describes don’t change.
There is also a national-security dimension. A foreign intelligence service with access to 678,000 French tax records — or to the full internal search tool, before access was cut — could map the financial footprint of officials, executives, journalists, and military personnel. French authorities have not ruled on motivation, and the forum-sale framing suggests financial rather than espionage intent, but the capability existed regardless of the buyer.
The bigger picture: governments are the new frontline
The DGFiP incident lands in a year when government agencies worldwide have become preferred targets. The identity-theft entry vector is particularly sobering for AI-era security teams: as agentic systems increasingly authenticate with long-lived credentials and API keys to act on citizens’ behalf, the “steal one identity, reach everything” attack pattern scales far beyond what a single VPN hop once allowed.
For France, the political timing is delicate. The breach became public the same week the EU’s AI Act transparency obligations took effect (August 2) and amid a national debate over data-center expansion and digital sovereignty. Each incident erodes public trust in exactly the digital-state infrastructure — impots.gouv.fr, France Identité, France Titres — that France has spent a decade building. The DGFiP is one of Europe’s most sophisticated tax administrations, with aggressive digital filing adoption; this breach shows that maturity on the service side does not automatically translate to resilience against insider-pathway attacks.
The investigation now turns on two questions: exactly how many records ZeroBytes actually extracted versus claimed, and whether the stolen identity used for entry can be traced to a phishing operation, an infostealer log, or something closer to home. French prosecutors, the CNIL, and Parquet national anti-cybercriminalité will each have a version of that answer. For the 678,000 taxpayers now waiting for an individual notice, the practical advice is the same as after any rich-data breach: expect convincing phishing in French, verify any tax correspondence through the official portal rather than links, and treat any unexpected contact referencing your income or family situation with suspicion.
Sources
- [1] https://www.reuters.com/legal/litigation/french-taxpayers-data-stolen-cyber-attack-french-finance-ministry-says-2026-08-14/
- [2] https://therecord.media/french-tax-authority-dgfip-confirms-data-breach
- [3] https://www.lemonde.fr/en/pixels/article/2026/08/14/french-taxpayers-data-stolen-in-hack-of-finance-ministry_6756510_13.html
- [4] https://www.aa.com.tr/en/europe/cyberattack-targets-france-s-public-finance-system-economy-ministry/4026917
- [5] https://brusselssignal.eu/2026/08/nearly-700000-french-taxpayers-data-stolen-in-cyberattack-on-tax-authority/
- [6] https://darkwebinformer.com/french-tax-administration-allegedly-breached-via-internal-vpn-678-000-taxpayer-records-offered/