French Tax Agency Confirms Breach Following Hacker's Sale of 2M Taxpayer Records
The General Directorate of Public Finances disputes claims of ongoing access while investigators assess the scope of the June network intrusion.

The General Directorate of Public Finances (DGFiP), France's primary tax administration agency, has formally confirmed that an intruder successfully breached its internal information networks and exfiltrated organizational and individual records. The official admission follows public claims made on an online cybercrime marketplace by an alleged attacker who put up for sale a database containing records of more than 2 million French taxpayers.
The malicious actor, operating under the pseudonym "ZeroBytes," listed the compromised tax dataset for purchase on an illicit forum. As first reported by The Register, the hacker claimed to have breached DGFiP's IT environment in late June 2026 by utilizing compromised credentials alongside a method to bypass multi-factor authentication (MFA) safeguards. In addition to advertising the database, ZeroBytes claimed to still possess active access to the tax authority's internal systems, offering to sell both the exfiltrated records and live network entry to prospective buyers.
Responding through a formal statement, DGFiP disputed the intruder's claim regarding ongoing network compromise while validating that an intrusion had occurred. The tax authority stated that a malicious actor managed to secure unauthorized access to its information systems towards the end of June 2026 by leveraging stolen identity credentials. However, the agency emphasized that this access had already been detected and completely severed in late June during a technical audit.
Despite denying that the perpetrator retains active access to its digital infrastructure, DGFiP admitted that the initial breach allowed the attacker to consult and extract records related to both private individuals and corporate entities. Following the forum post, the tax directorate immediately enacted additional restrictions across its systems to block unauthorized entry points and prevent any further misuse of compromised access privileges.
Detailed forensic investigations remain underway to analyze the exact scope of the breach and accurately assess which specific data fields were accessed during the incident. DGFiP indicated that it is working to determine the precise number of affected account holders and taxpayers before formally submitting an incident report to the Commission Nationale de l'Informatique et des Libertés (CNIL), France's national data privacy authority. The agency stated that it will contact affected individuals directly once their identities are confirmed through ongoing forensic work.
The DGFiP breach represents the latest in a series of severe digital intrusions targeting French public sector IT systems and partner technology suppliers throughout 2026. In February, the Ministry of Finance disclosed that malicious actors used stolen credentials to compromise an internal database, stealing 1.2 million records containing citizens' banking information. Although the ministry reported revoking access shortly after detection, the sensitive data had already been extracted.
The security vulnerabilities spread to healthcare and identity management systems shortly thereafter. In the weeks following the Ministry of Finance incident, France's Health Ministry confirmed a major cyberattack targeting Cegedim Santé, a key healthtech technology supplier. That breach compromised approximately 15.8 million administrative records, of which roughly 165,000 contained notes written by medical doctors that revealed patient histories in a limited number of instances.
The cyber wave continued in April, when the Interior Ministry confirmed an attack on France Titres, the official agency managing driver's licenses and passports. A 15-year-old alleged perpetrator subsequently posted the stolen records online, claiming the breach impacted between 18 million and 19 million people—representing over 25 percent of the French population. By June, officials were investigating another intrusion into Tchap, France's state-encrypted messaging platform, where bad actors claimed access to over 73,000 accounts, 643,000 messages, nearly 60,000 media attachments, and hundreds of secure chat groups.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



