A massive data breach at France’s tax authority, the Directorate General of Public Finances (DGFiP), has left nearly 680,000 individuals vulnerable to potential identity theft and other malicious activities. The incident came to light after a threat actor boasted about accessing DGFiP’s internal systems and exfiltrating sensitive information on a hacking forum.
According to DGFiP, the attackers used compromised credentials for an employee and a third-party account to gain access to its systems in June and July. Although the unauthorized access was suspended immediately upon detection, it wasn’t until last week that the tax authority confirmed the data breach had occurred. The stolen information includes reference tax income, withholding tax rates, company names, unique identifiers, and cadastral data on real estate addresses and surfaces.
Fortunately, DGFiP assures that no usernames or passwords were compromised in the attack. However, this is little consolation for those affected by the breach, who may now be at risk of having their personal data misused. The tax authority has promised to contact each affected individual directly to provide further information and support.
The incident highlights the ongoing threat posed by sophisticated cyber attackers who continue to exploit weaknesses in even the most secure systems. It also underscores the importance of robust cybersecurity measures, including multi-factor authentication and regular security audits, to prevent such breaches from occurring in the first place.
Interestingly, this data breach is not an isolated incident in Europe. Just last month, Romania’s National Agency for Cadastre and Property Registration (ANCPI) fell victim to a disruptive cyberattack, which disrupted official applications, sites, and email services, and brought the country’s real estate market to a standstill.
While DGFiP continues to investigate the nature and scope of the data breach, it is clear that such incidents will continue to occur unless organizations take proactive steps to strengthen their cybersecurity posture. This includes implementing robust security protocols, conducting regular vulnerability assessments, and educating employees on best practices for online security.
For those affected by the breach, the most important takeaway is to remain vigilant and monitor their personal data closely. This may involve regular checks of their credit reports, notifications from financial institutions, or alerts from identity theft protection services. By taking proactive steps to protect themselves, individuals can mitigate the risks associated with this data breach and reduce their vulnerability to potential malicious activities.
In the meantime, organizations in all sectors must recognize the gravity of these incidents and take immediate action to strengthen their cybersecurity defenses. This includes investing in advanced security technologies, training employees on best practices for online security, and conducting regular security audits to identify vulnerabilities before they can be exploited by attackers. Only through a concerted effort to prioritize cybersecurity can we hope to prevent such breaches from occurring in the future.
Source: SecurityWeek — 2026-08-17