← BACK TO FEED
data breachFranceDGFiPcybercrimegovernment security

France's Tax Authority Confirms Data Breach After Hacker Hawks 2 Million Taxpayer Records Online

France's tax authority (DGFiP) has confirmed a data breach that occurred in late June 2026, in which an attacker using stolen credentials and an MFA bypass technique accessed and extracted data on approximately 2 million taxpayers. The alleged criminal, known as "ZeroBytes," advertised the stolen database on a cybercrime forum and claimed to still have access to DGFiP's systems, though the agency disputes this and says access was severed during a routine audit. The incident is one of several significant cyberattacks targeting French public sector organisations in 2026, following earlier breaches affecting the Finance Ministry, Health Ministry, and the passport and driver's licence agency France Titres.

France's General Directorate of Public Finances (DGFiP) has confirmed a data breach after someone going by the alias "ZeroBytes" turned up on a cybercrime forum this week advertising what they claimed was a database of over 2 million French taxpayers.

According to the seller, the intrusion happened by way of stolen credentials combined with an MFA bypass technique. They also claimed to still have active access to DGFiP systems, helpfully offering to throw that in alongside the database purchase.

DGFiP pushed back on the persistent access claim. In a statement issued Thursday, the directorate said the breach occurred at the end of June and that access had already been cut as part of a routine audit before ZeroBytes made their forum debut. So either the attacker is bluffing about still being inside, or the audit missed something. Neither option is particularly reassuring.

The directorate confirmed that during the intrusion, data relating to both individuals and businesses was browsed and extracted. It says it has filed a complaint, imposed additional access restrictions, and will notify France's data protection authority CNIL once it has a clearer picture of exactly who and how many people were affected.

This would be easy to dismiss as an isolated incident if France's public sector hadn't been haemorrhaging data all year.

In February, the Ministry of Finance admitted attackers had walked off with 1.2 million records containing French citizens' bank details, again via stolen credentials. The ministry said access was revoked quickly, which presumably still counts as a win in the current climate.

A few weeks after that, the Health Ministry confirmed a cyberattack on healthtech provider Cegedim Santé. Around 15.8 million administrative files were taken, with roughly 165,000 containing doctors' notes that in some cases revealed patients' medical histories.

April brought news of a breach at France Titres, the agency that handles passports and driving licences. The alleged perpetrator, reportedly aged 15, posted the stolen data online and claimed it covered somewhere between 18 and 19 million people. That is more than a quarter of metropolitan France's population, lifted apparently by a teenager.

At this rate, France's public sector isn't so much experiencing a cybersecurity problem as conducting an extended stress test of its citizens' tolerance for data exposure.

READ NEXT
Snowflake Breach Hacker Pleads Guilty: 100 Million Records, Stale Passwords, and No MFARiver Bank Paid Ransomware Crew to Delete Stolen Data. Trust Them on That.ExfilSquad Claims Police Database Scalp as UK Public Sector Breach Spree Continues