French Tax Authority Data Breach: What Was Stolen and What Remains Secure
A breakdown of the DGFiP cyberattack affecting 678,000 users, distinguishing between compromised personal data and secure account access, while analyzing conflicting claims regarding the scope of the intrusion.
The short version
A significant data leak occurred at France’s Direction générale des Finances publiques (DGFiP) in late June, impacting approximately 678,000 users. The incident involves the extraction of sensitive personal and business information but, according to the administration, does not grant access to the secure login portals on impots.gouv.fr. While the tax authority asserts that account credentials remain safe, the hacker group ZeroBytes claims to have secured broader access than officially acknowledged. This briefing separates the confirmed data types from the disputed scope of the intrusion.
The scope of the breach: What was taken
The incident, reported in late June 2026, targeted the information systems of the French tax authority. According to official updates and media reports, the compromised dataset encompasses 678,000 users, a figure that includes both private individuals and corporate entities.
For individual taxpayers, the stolen records are detailed and sensitive. The data reportedly includes:
- Full names and addresses;
- Taxable income (revenu fiscal);
- Withholding tax rates (taux de prélèvement à la source);
- Family quotient details.
For businesses, the nature of the compromised information differs. The administration notes that the data regarding companies is less sensitive than that of private citizens. The records for corporate users primarily consist of public identifiers such as SIREN numbers and company addresses. While still a privacy concern regarding corporate profiling, these elements do not carry the same immediate financial risk as individual income and tax rate data.
Crucially, the administration has stated that the stolen information does not allow an attacker to log into the secure accounts on the impots.gouv.fr platform. The breach concerns the extraction of stored data, not the compromise of the authentication keys required to access the live portal.
Conflicting claims: Administration vs. Hacker
A divergence exists between the official narrative and the assertions made by the perpetrator. The tax authority maintains that the breach was limited to the specific datasets mentioned above and that the integrity of the secure login system was not breached.
Conversely, the hacker known as ZeroBytes, who claimed responsibility for the theft on the day the investigation was announced, disputes this limitation. Speaking to French Breaches, ZeroBytes asserted that they had gained access far broader than what the administration suggests. The hacker also stated that financial gain was the primary motivation for the operation.
This creates a layer of uncertainty regarding the full extent of the intrusion. While the administration can confirm the data they know was extracted, the hacker’s claim of "broader access" implies the possibility of additional, unconfirmed data points or system vulnerabilities that have not yet been disclosed or detected by the authorities. At this stage, the 678,000 figure represents the confirmed impact, but the hacker’s testimony suggests the operational scope may have been wider.
Legal response and investigation
The French judicial system has moved quickly to address the incident. The Paris prosecutor's office has opened a formal investigation into the cyberattack. The inquiry is framed around the charge of participation in a criminal organization aimed at preparing a felony punishable by at least five years of imprisonment.
The investigation has been entrusted to the Office anticybercriminalité (Ofac), the specialized unit within the Paris prosecutor's office dedicated to fighting cybercrime. The probe focuses on the fraudulent extraction of data from an automated processing system implemented by the State. While the prosecutor has not yet publicly named the suspect in the formal charge, the attribution to ZeroBytes by the hacker group itself has been noted in the media coverage surrounding the opening of the case.
The administration has also indicated that the operation was more sophisticated than previous attacks on the fiscal system, suggesting a high level of technical capability on the part of the attackers. Users affected by the breach are expected to be contacted by the administration in the coming weeks regarding the incident.
Going further
- French Tax Authority Data Breach: Threats to Individuals and Businesses - Le Figaro: The original report detailing the types of data stolen and the administration's response regarding account security.
- ZeroBytes Claims Responsibility for 678,000 Stolen Tax Records - BFM TV: Coverage of the hacker's claims regarding broader access and the opening of the judicial investigation by the Paris prosecutor.
- Cyberattack on impots.gouv.fr: Prosecutor Opens Investigation - Yahoo Finance: Details on the distinction between individual and business data sensitivity and the role of the Office anticybercriminalité (Ofac).
- Cyberattack on a Public Health Provider: 80,000 Contacts Compromised - Le Figaro: Context on a separate but concurrent cyberattack targeting a public health service provider, illustrating the broader landscape of French public sector vulnerabilities.
Sources
- Piratage des données du fisc : ces menaces qui pèsent désormais sur les particuliers et les entreprises - Le Figaro
- Cyberattaque contre impots.gouv.fr : le parquet ouvre une enquête
- Mode opératoire des pirates, risques d'usurpation d'identité... Les questions qui se posent après la cyberattaque contre le fisc
- "L'argent est la principale motivation": le hacker ZeroBytes revendique le vol de données de 678.00 comptes sur la plateforme des impôts (le parquet de Paris a ouvert une enquête)
- Une arnaque cible les propriétaires de chats, chiens et furets après la cyberattaque du fichier I-Cad - Le Figaro
- Cyberattaque d'un prestataire de Santé publique France : près de 80.000 données de contact ciblées - Le Figaro
- Familles nombreuses, retraite, APL des étudiants... Les propositions chocs des services de Bercy - Le Figaro
Found an error? Email us — we correct factual mistakes and note significant updates on the article. Contact us
Keep exploring
Password managers: free vs paid, what actually matters
A Monday-morning scenario, security model, sync, recovery, free options (browser, Bitwarden, Apple, Google) and paid ones (1Password, Dashlane, Proton Pass, KeePass): an honest comparison to choose — and migrate in about an hour.
Read the article →Public Wi‑Fi: what’s true and what’s myth
Café, airport, hotel: what public Wi‑Fi can actually expose in 2026, what’s overhyped, and the simple habits that matter.
Read the article →What a VPN is actually for (and what it isn’t)
Encryption, IP address (your device’s network identifier), streaming, public Wi‑Fi: what a VPN really changes for your privacy — and which marketing promises to ignore.
Read the article →