News Hub

French tax authority breach exposes data on 678,000 people

Written by Tue 18 Aug 2026

French flag flying beside a statue symbolising justice, with digital security icons and network graphics overlaid, representing cybersecurity, law, and digital regulation in France.

France’s Directorate-General of Public Finances (DGFiP) has said a malicious actor gained illegitimate access to its information system in June and July 2026, leading to the theft of tax, business, and cadastral data relating to 678,000 individuals and professionals.

According to the Ministry of the Economy and Finance, the attacker used credentials belonging to a DGFiP employee and an authorised third party. The affected access was subsequently interrupted, with further investigations establishing that data had been consulted and extracted before access was removed.

The ministry said the public finance accounts of individuals and professionals had not been compromised and that usernames and passwords were not stolen.

Tax and Property Data Was Extracted

DGFiP said the compromised information varied depending on the affected user.

For individuals, the data included reference tax income, family quotient, and withholding tax rates. Business information included company names and SIREN identification numbers, while cadastral information included addresses and the surface areas of real estate.

DGFiP explicitly distinguished the incident from a compromise of taxpayers’ online accounts.

“The public finance spaces of private and professional users have not been compromised. The usernames and passwords of individuals and professionals were not compromised,” said the authority.

That narrows the immediate account-access risk, but it does not remove the possibility that the stolen information could be used elsewhere.

“The information stolen from DGFiP includes details like reference tax income, family quotient, withholding rate and property details, all of which are gold to social engineers as it helps them make a scam sound more legitimate,” said Anna Collard, CISO Advisor and SVP Content Strategist at KnowBe4.

She added that “Human identity remains one of the softest edges in government systems, and third-party access is part of that perimeter.”

Collard said accurate personal information should therefore not be treated as proof that a message is genuine, particularly when recipients are already expecting contact from the tax authority.

Her advice for those affected is:

  • Treat any unexpected email, text, or call about this breach as hostile until proven otherwise, however official it looks.
  • Accurate details are no longer proof of anything. Your correct address, income, or family situation in a message confirms the sender read the stolen file, not that they’re legitimate.
  • Never follow the link. Type impots.gouv.fr into your browser yourself, or use the number on official correspondence you already had.
  • DGFiP will not ask for passwords or bank details. Any request for them is fraud, full stop.
  • Watch for pressure and deadlines. Urgency, such as a refund expiring or a penalty pending is a very common manipulation tactic, not an administrative one.
  • Slow down on unusual payment requests at work. Business names and SIREN numbers were also taken, so expect invoice and supplier impersonation attempts too

DGFiP will contact each affected individual and professional directly, which creates a clear subject for fraudulent messages to imitate.

DGFiP Continues Its Response

DGFiP said the illegitimate access was detected on 12 and 13 August, after the activity had taken place during June and July. It added that earlier access controls had not identified the theft.

Following further investigation, the ministry asserted that additional preventive interruptions had been made to sensitive information systems.

Investigations are continuing with the ministry’s security service and France’s National Cybersecurity Agency (ANSSI). The incident was also reported to the data protection authority CNIL, and DGFiP said it intended to file a complaint.

The Stolen Data Carries a Longer-term Risk

Simon Pamplin, CTO at Certes, asserted that tax data “carries a distinct and durable risk profile”.

“Reference income figures, family composition details, withholding rates, and cadastral property records combine to create a detailed financial portrait of an individual,” said Pamplin.

Unlike passwords, much of that information cannot be reset after a breach. Household circumstances, property records, and historical financial information may remain useful for constructing convincing approaches long after the immediate incident has been contained.

That makes the response phase particularly important. With 678,000 affected individuals and professionals due to be contacted directly by DGFiP, recipients will need to distinguish legitimate correspondence from messages attempting to exploit awareness of the breach.

The breach therefore leaves a risk that extends beyond the initial unauthorised access. Even without stolen passwords, the financial, household, business, and property information that was extracted could still be useful for fraud and social engineering.

Join Cloud & Cyber Security Expo Paris

18 - 19 November 2026, Porte de Versailles, Paris

Prove control. Strengthen resilience. Govern cyber risk.

Join CISOs, risk leaders and IT decision-makers exploring identity security, threat detection, incident response, and compliance across cloud, hybrid and distributed environments.

Written by Tue 18 Aug 2026

Tags:

data breach France phishing social engineering tax
Send us a correction Send us a news tip


Subscribe for News in Your Inbox