← BACK TO FEED
data breachFranceDGFiPgovernment securitycredential theft

French Tax Authority Breach Exposes Financial Data on 680,000 Citizens

France's tax authority (DGFiP) has disclosed a data breach affecting approximately 680,000 individuals, after a threat actor used compromised employee and third-party credentials to access its systems in June and July. Stolen data includes reference tax income, withholding tax rates, company identifiers, and real estate cadastral data, though no passwords or usernames were compromised. The breach was reported to France's data protection authority CNIL, and DGFiP is contacting all affected individuals while continuing to investigate the full scope of the incident.

France's tax collection body, the Directorate General of Public Finances (DGFiP), has confirmed a data breach affecting around 680,000 people. The agency only went public after a threat actor showed up on a hacking forum claiming they'd walked off with data from DGFiP's internal systems.

The intrusion itself happened back in June and July. DGFiP says it shut down the unauthorised access as soon as it was detected, but here's the awkward part: at the time, investigators found no evidence that data had actually left the building. Clearly, they were wrong.

Last week the agency confirmed that attackers used stolen credentials belonging to an employee and a third-party account to get in. The haul includes reference tax income figures, withholding tax rates, company names, unique identifiers, and cadastral data covering real estate addresses and property dimensions. Roughly 678,000 individuals are affected.

Passwords and usernames were not compromised, according to DGFiP. The breach has been reported to France's data protection watchdog, CNIL, and the agency says it will write to each affected person directly. The investigation into the full scope is still ongoing.

The timing is notable. Just a month earlier, Romania's National Agency for Cadastre and Property Registration (ANCPI) got hit by a threat actor going by the name ByteToBreach. That attack followed a familiar playbook: breach the network, steal credentials and internal documents, demand money. When ANCPI refused to pay, the attacker wiped the encrypted data out of spite, knocking out official websites, applications, and email systems, and effectively grinding Romania's real estate market to a halt.

The core cadastral database survived, but ANCPI spent roughly three weeks rebuilding servers and restoring services. Not a great look for any government agency sitting on sensitive property records.

Two European public bodies managing real estate and financial data, both breached within a month of each other. Whether that's coincidence or something more coordinated, nobody's saying yet.

WATCH THE SHORT
READ NEXT
France's Tax Authority Confirms Data Breach After Hacker Hawks 2 Million Taxpayer Records OnlineShinyHunters Turns Up the Heat on Ernst & Young After Tax Data BreachMadera Community Hospital Took a Year to Tell 150,000 People Their Data Was Stolen