Overview
French authorities have confirmed a data breach at the Directorate General of Public Finances (DGFiP) — France's national tax authority — after a threat actor claimed to have accessed records belonging to approximately 600,000 victims. The unauthorized access occurred in late June 2026 and was reportedly facilitated through identity theft or credential misuse.
The DGFiP manages tax collection, public accounting, and fiscal policy enforcement across France, making any breach of its systems a matter of significant national concern.
What Happened
According to official confirmation from French authorities, an attacker gained unauthorized access to DGFiP systems by stealing or misusing someone's identity — likely through compromised credentials belonging to an employee or authorized user. This type of initial access vector, sometimes called credential-based intrusion or identity fraud, bypasses technical controls by appearing as a legitimate user.
The breach was detected and reported to investigators, triggering a formal inquiry. A threat actor subsequently claimed responsibility and alleged that data from 600,000 individuals was exposed or exfiltrated during the compromise window.
Data at Risk
While French authorities have not officially confirmed the precise volume or nature of records accessed, DGFiP systems routinely hold:
- Full legal names and addresses
- Tax identification numbers (numéro fiscal)
- Income and employment data
- Bank account information (for tax refunds and direct debits)
- Family composition data
If the hacker's claims are accurate, the exposure of tax records at this scale would represent one of the more significant government data breaches in French history.
Government Response
French authorities have launched a formal investigation into the incident. The DGFiP has acknowledged the breach and is cooperating with investigators. The Agence nationale de la sécurité des systèmes d'information (ANSSI), France's cybersecurity agency, is likely involved in the technical response and attribution efforts.
Citizens potentially affected by the breach may receive notifications in accordance with France's obligations under GDPR, which requires notification to supervisory authorities within 72 hours of becoming aware of a breach and, where feasible, notification to affected individuals when the breach poses high risk to their rights and freedoms.
Broader Context
Government tax authorities have become increasingly attractive targets for cybercriminals and nation-state actors due to the breadth of sensitive financial and identity data they hold. In recent years, similar breaches have impacted tax agencies in multiple countries, often resulting in large-scale identity fraud campaigns against affected citizens.
France's DGFiP breach follows a broader European trend of credential-based attacks against public sector organizations, highlighting the need for phishing-resistant multi-factor authentication, privileged access management, and zero-trust architectures within government environments.
What Affected Individuals Should Do
If you are a French taxpayer and believe you may be affected:
- Monitor financial accounts for unauthorized transactions
- Check your impots.gouv.fr account for any unusual activity or changes
- Be alert for phishing attempts — attackers frequently use stolen government data to craft convincing follow-on lures
- Report suspicious contact claiming to be from DGFiP to the official channels