A massive data breach at France’s tax authority, the Directorate General of Public Finances (DGFiP), has left over 680,000 individuals’ sensitive information exposed to potential misuse. The incident was revealed after a hacker boasted about accessing DGFiP’s internal systems and stealing valuable data on French citizens.
The threat actor gained access to DGFiP’s systems in June and July using compromised credentials for an employee and a third-party account. Although the public tax authority detected the unauthorized access immediately, it didn’t find evidence of data exfiltration at the time. However, last week, DGFiP confirmed that the attackers had indeed stolen sensitive information from 678,000 users.
The compromised data includes reference tax income, withholding tax rates, company names and unique identifiers, as well as cadastral data on real estate addresses and surfaces. Notably, usernames and passwords were not affected in the attack. The incident was promptly reported to France’s data protection authority, CNIL, and DGFiP continues to investigate the nature and scope of the breach.
This is the second high-profile cyberattack in Europe in recent months. In July, Romania’s National Agency for Cadastre and Property Registration (ANCPI) fell victim to a disruptive cyberattack by a threat actor known as ByteToBreach. The attacker stole sensitive information, including employee credentials and internal documents, and attempted to extort the agency. When the extortion attempt failed, the hacker wiped the encrypted data, disrupting official applications, sites, and email services.
The DGFiP breach highlights the importance of robust security measures in protecting sensitive government data. With an estimated 680,000 individuals affected, this incident serves as a stark reminder that even seemingly secure systems can be vulnerable to attacks. As governments and organizations continue to collect and store vast amounts of personal data, it’s essential that they prioritize cybersecurity and implement robust safeguards against unauthorized access.
While the exact number of potentially affected individuals is still unknown, DGFiP has pledged to contact each affected individual directly to inform them about the breach. This proactive approach demonstrates a commitment to transparency and accountability in handling sensitive data.
In light of this incident, it’s crucial for citizens to remain vigilant and take steps to protect their personal data. If you’re among those affected by the DGFiP breach, be cautious when receiving unsolicited communications or requests for information. Verify the authenticity of any messages or notifications from government agencies or financial institutions before taking action.
In addition to individual vigilance, organizations handling sensitive data must prioritize robust security measures, including multi-factor authentication, regular system updates, and employee education on cybersecurity best practices. By working together, we can mitigate the risks associated with data breaches and protect sensitive information from falling into the wrong hands.
Source: SecurityWeek — 2026-08-17