French tax authority data breach affects 678,000 individuals

A massive data breach has struck the French tax authority, exposing sensitive information belonging to nearly 700,000 individuals. The attack, which was only recently disclosed by the authorities, raises serious concerns about the security of government databases and the potential consequences for those affected.

According to a statement from the French Finance Ministry, an attacker using the handle “ZeroBytes” claimed responsibility for the breach on August 12, listing a stolen database containing sensitive tax information for sale on a hacking forum. The ministry confirmed that the attacker had accessed the General Directorate of Public Finances (DGFiP) systems, stealing data including tax income, family quotient, and withholding tax rates.

The breach also compromised cadastral data, which includes addresses and property sizes, affecting both individuals and businesses. However, the French tax administration was quick to reassure users that their online accounts were not compromised, and user IDs and passwords remained secure.

But the scope of the attack is broader than initially reported. ZeroBytes claimed to have gained access to the Serveur Professionnel de DonnĂ©es Cadastrales (SPDC), an online platform operated by the French tax authority that provides access to the country’s central land registry and property ownership records. While they only managed to steal 252,149 records containing data on over 2 million people, the full extent of the breach remains unclear.

The incident is just the latest in a series of high-profile cyberattacks targeting French government agencies. In recent months, multiple institutions have been hit, including the national employment agency and the Ministry of Finance. These breaches highlight the need for robust cybersecurity measures to protect sensitive information and prevent further attacks.

In response to the breach, the French Finance Ministry has promised to contact all affected individuals via email or letter next week, providing details on what data may have been accessed or stolen and advising them on necessary precautions to take. The incident serves as a stark reminder of the importance of cybersecurity and the need for governments and institutions to prioritize data protection.

In practical terms, this breach should serve as a wake-up call for individuals and businesses alike to review their online security measures and ensure they are taking adequate steps to protect sensitive information. This includes using strong, unique passwords, enabling two-factor authentication, and regularly monitoring accounts for suspicious activity. By being vigilant and proactive in our cybersecurity efforts, we can mitigate the risks associated with such breaches and prevent further attacks from succeeding.


Source: Bleeping Computer — 2026-08-17