France's Tax Authority Breach: 600,000 Affected, Private Messages Included
France's tax authority has confirmed that a recent cyberattack exposed the data of around 600,000 taxpayers and businesses, with some victims having their private messages with the authority stolen outright.
The General Directorate of Public Finances (DGFiP) published a fuller account of the damage this week. Message logs were compromised for a significant portion of those affected, and for roughly 250 people, the actual content of those messages was taken. That is a meaningful distinction. Metadata is bad enough; the messages themselves are worse.
For the 350,000-odd individuals caught up in the breach, the stolen data includes tax identification numbers, contact details, marital status, household composition, number of dependents, and withholding rates. In other words, a fairly comprehensive financial and personal profile. Around 250,000 businesses and professionals had less to worry about, with exposure largely limited to company names and SIREN registration numbers. Property-related data was also caught up in the incident, though DGFiP pointed out that cadastral information such as addresses and dimensions is publicly available anyway.
The authority is notifying those affected by email or post, and has warned that the stolen details could make phishing attempts uncomfortably convincing. DGFiP specifically flagged impersonation scams, CEO fraud, and fake bank adviser calls as likely follow-on threats. The standard reminder followed: DGFiP will never ask for PINs or identity documents over the phone or by email, and will only request sensitive material through its secure portal.
The numbers have shifted slightly since last week, when DGFiP cited 678,000 affected parties. The updated figure sits at roughly 600,000. No explanation was offered for the gap. Meanwhile, the alleged attacker, operating under the handle 'ZeroBytes', had claimed to have stolen data on more than 2 million people. That claim has not been corroborated, but the discrepancy between the authority's own figures is awkward enough without needing to factor in criminal boasting.
Separately, DGFiP disclosed a vulnerability in the government's Vacant Successions Portal, a service used to search for estates without known heirs. The portal has been taken offline while the investigation runs. So far there is no confirmed data leak from that incident, but the inquiry is ongoing.
This is not happening in isolation. France's public sector has had a rough year on the cybersecurity front. In February, the finance ministry acknowledged a breach affecting 1.2 million people's bank details. In March, an attack on healthtech firm Cegedim Santé resulted in 15.8 million administrative files being stolen, including 165,000 containing doctors' notes. April brought reports that a 15-year-old had attacked France Titres, the body responsible for the country's identity documents, with the attacker claiming access to between 18 and 19 million records.
France has a problem. Whether it is a resourcing problem, an architecture problem, or just extraordinarily bad luck is not yet clear. But at this rate, the question is not whether another breach will hit a French government system, but when.