France’s Tax System Hacked As Data On 678,000 People And Businesses Is Stolen

France Scrambles After Massive Tax Hack Exposes Income, Property And Business Data

France Confronts Major Government Data Breach

The Data France Failed To Protect

France is confronting an extraordinary cybersecurity failure after attackers extracted tax, business and property information relating to 678,000 individuals and professionals from systems operated by the Direction Générale des Finances Publiques, the country's tax authority. The information includes some of the financial details citizens would normally expect to remain among the most closely protected records held by the state.

The immediate danger is not that hackers can simply log into the victims' online tax accounts. French authorities say taxpayer usernames and passwords were not compromised. The greater problem is that criminals may now possess enough genuine information about people's income, families, businesses and property to make future fraud attempts frighteningly convincing.

How Did Hackers Get Inside France’s Tax System?

The intrusion did not appear to begin with attackers simply breaking through the public-facing tax website. French authorities say illegitimate access occurred during June and July 2026 through the usurpation of credentials associated with a DGFiP employee and an authorised third party.

That distinction matters. Compromising a trusted identity can allow an attacker to appear, at least initially, like someone who is supposed to be inside the system.

Authorities disabled the affected accounts after detecting the suspicious access. Yet the initial checks failed to establish that information had already been stolen. The Finance Ministry said the theft was not detected at that stage because of the sophistication of the attack.

That is arguably the most troubling part of the incident.

France succeeded in shutting down the access but failed to realise that the attackers had already extracted data. It was only after a hacker publicly claimed responsibility in August that deeper investigations established the scale of the theft.

The attackers therefore did not merely penetrate a sensitive state network. They appear to have left with valuable information without the administration immediately understanding what had happened.

Exactly What Information Was Stolen?

For individuals, the officially confirmed compromised information includes reference taxable income, family quotient and withholding-tax rates. These details can reveal a considerable amount about someone's financial circumstances and household.

For businesses, exposed information includes company names and SIREN identification numbers. Cadastral information involving addresses and the surface areas of properties was also accessed.

French authorities have stressed that individuals' and companies' online public-finance accounts themselves were not compromised and that their login credentials and passwords were not taken.

That is important reassurance, but it does not make the stolen information harmless.

A criminal who knows someone's financial profile, property details and tax circumstances can construct a much more credible impersonation than a conventional spammer working from nothing more than an email address.

The breach therefore creates what may prove to be a long-term fraud problem rather than a single cybersecurity event.

Who Is Suspected Of Carrying Out The Attack?

The clearest public lead is an online identity using the name ZeroBytes.

The name appeared after stolen DGFiP information was advertised on a cybercrime forum on August 12. The attacker claimed responsibility for penetrating the tax authority and offered data for sale.

There is an important distinction between attribution and a claim of responsibility. French authorities have not publicly attributed the attack to a named individual, criminal organisation or foreign government, and the real identities behind ZeroBytes have not been established publicly.

ZeroBytes has reportedly described itself as a two-person operation motivated by money rather than ideology. The hackers have also made significantly larger claims about their access to French cadastral information, but these claims have not been fully confirmed by the authorities.

The group has also claimed that stolen information was sold to two buyers for thousands of euros. That assertion remains unverified, and the identities or intentions of any alleged buyers are unknown.

This uncertainty matters enormously. The original hackers may represent only the first stage of the threat.

Once a database has been sold, duplicated or shared, control over it effectively disappears.

What Could Criminals Do With The Data?

The most obvious danger is highly personalised phishing.

Imagine receiving an email apparently from the French tax authorities that knows roughly how much you earn, where you live, details about your household and information connected with your property.

A message containing accurate private information immediately looks more believable.

A criminal could then claim that a refund is waiting, that a tax discrepancy must be corrected, that an account needs verification or that a payment is overdue. The genuine stolen information becomes the bait used to obtain information that was not included in the original breach, such as passwords, card numbers or banking credentials.

This danger is particularly acute because DGFiP has begun contacting affected taxpayers individually. Victims therefore have a legitimate reason to expect communications about the breach, creating an unusually convincing environment for criminals seeking to impersonate the administration.

Identity fraud is another concern.

Different databases can also be combined. A tax record that is insufficient for fraud on its own can become much more powerful when matched against information obtained from another breach.

That is why stolen personal information rarely loses all of its value when the initial headlines disappear.

Could Wealthier Households Be Particularly Exposed?

Potentially.

Reference taxable income and property information can help differentiate between households rather than leaving criminals to attack victims indiscriminately.

That creates the possibility of what could be called victim selection.

Instead of sending one million generic fraudulent messages and hoping someone responds, criminals could identify individuals who appear to possess greater financial resources and construct more sophisticated approaches around them.

There is also a physical-security dimension. Property addresses combined with information that provides clues about wealth could potentially assist criminals selecting targets for offline crime, although there is currently no evidence that the DGFiP breach itself has resulted in such attacks.

This is another reason the consequences cannot be measured simply by whether passwords were stolen.

Why France’s Delayed Discovery Matters

The timeline is politically uncomfortable.

The unauthorised access had already been interrupted by the end of June, but checks at the time did not detect that data had been extracted. The scale of the problem only became clear after the attackers publicly claimed responsibility in August.

That creates an obvious question: How can a government know that an intruder entered a highly sensitive system yet fail to establish that hundreds of thousands of records had left it?

France is now carrying out a deeper examination of DGFiP's systems with help from the country's national cybersecurity authorities. An audit of the tax authority's technology and resulting operational measures is expected to be presented to Parliament in September.

The government has also accelerated a broader public-sector cybersecurity programme involving €200 million for interministerial cybersecurity, artificial intelligence and ministry security.

The affair has consequently evolved beyond a technical investigation into a political argument about whether the French state has accumulated too much technological debt while storing increasingly valuable concentrations of citizen data.

Is A Foreign Government Behind The Attack?

There is currently no public evidence that Russia, China, Iran, North Korea or another state directed this breach.

That point should not be blurred.

The available information instead points toward an apparently financially motivated criminal operation. ZeroBytes has reportedly presented money as the motivation, while the stolen information was advertised for sale.

But the absence of evidence for state sponsorship does not remove the geopolitical significance of the incident.

Data has value beyond the person who originally stole it.

A criminal database containing information on government workers, company directors, financially significant individuals or people connected with sensitive industries could theoretically be acquired by intelligence-linked intermediaries later.

That does not mean this has happened. There is currently no evidence establishing it.

It means that once highly detailed government information enters illicit markets, France can no longer guarantee who ultimately possesses it.

Why Tax Information Can Have Intelligence Value

Tax databases are unusually useful because money reveals relationships.

Income can indicate seniority. Company records identify commercial links. Addresses reveal locations. Property ownership reveals assets. Household details reveal relationships.

Individually, each piece of information may appear mundane. Combined, they can build a detailed picture of a person.

For foreign intelligence services, that type of information can help identify individuals worth targeting, establish plausible cover stories for social engineering or enrich datasets gathered from other sources.

Government employees and contractors become particularly interesting where a hostile actor can combine publicly available professional information with private financial information.

Again, there is no indication that this is what ZeroBytes intended.

The geopolitical significance lies in the secondary market for stolen information, not necessarily the motives of the original intruder.

France’s Wider Cybersecurity Problem

The DGFiP attack does not exist in isolation.

French state bodies have faced a series of cybersecurity incidents, increasing pressure on Paris to demonstrate that central government systems can protect the large quantities of personal data they increasingly hold.

France had already experienced an intrusion involving the national register of bank accounts earlier in 2026, while other public institutions have reported significant compromises.

That pattern matters internationally.

France is one of Europe's largest economies, a nuclear-armed state, a permanent member of the UN Security Council and a central actor within both NATO and the European Union.

Its resilience therefore has consequences beyond its borders.

A weakness in government cybersecurity can become a weakness in national-security infrastructure, defence supply chains, strategic companies or public confidence even when the initial intrusion begins as ordinary cybercrime.

The European Implications

The incident strengthens the argument that Europe's cybersecurity challenge is no longer simply about defending military networks or intelligence systems.

Civilian administrative databases can also become strategic targets.

Tax authorities, healthcare systems, transport networks, municipal databases and identity platforms contain enormous amounts of information about populations.

As governments digitise more services, successful compromise potentially gives criminals or hostile intelligence services something previous generations of spies would have required years to assemble.

The challenge for governments is therefore changing.

Protecting the state increasingly means protecting the data infrastructure that describes its citizens.

What Should Affected Citizens Do?

The most immediate threat is likely to come through fraud attempts rather than somebody directly entering a taxpayer's online account.

Anyone receiving a notification should therefore pay particular attention to unexpected communications that claim to know private financial details.

A convincing email should not automatically be considered genuine simply because it contains correct information.

That principle becomes especially important after a breach because the criminal may know the correct information precisely because it was stolen.

Passwords should not be disclosed in response to unsolicited messages, login pages should be reached independently rather than through unexpected links, and unusual financial requests deserve additional verification.

Businesses face similar risks. A company name, registration number and address can help attackers impersonate suppliers, government departments or company representatives.

The potential consequences therefore extend from consumer phishing to business-email compromise and corporate impersonation.

What Happens Next?

France has notified its data-protection authority, strengthened restrictions around sensitive systems and brought national cybersecurity specialists into the investigation. Affected individuals and professionals are being contacted directly while investigators continue trying to establish exactly how far the intruders travelled through government systems.

Investigators must also determine who is actually behind ZeroBytes, whether the stolen information has genuinely been sold, who might have purchased it and whether additional datasets were removed beyond the 678,000 victims already confirmed.

The attacker's larger claims should remain treated as claims until independently established.

The confirmed breach alone is serious enough.

France placed some of its citizens' most sensitive financial information behind government systems designed to protect it. Someone found a way inside, extracted hundreds of thousands of records and disappeared before the state understood what had been taken.

The next phase will determine whether this was primarily a costly criminal theft or the beginning of a much broader security problem.

Previous
Previous

Ship Hit Leaving Strait of Hormuz as Crew Casualty Raises New Fears Over World’s Oil Chokepoint

Next
Next

Iran Declares ‘Fully Offensive’ Posture as Hormuz Attack Raises Fears the War Is Escalating Again