French Tax Authority Data Breach: What Was Stolen and What Remains Secure

A breakdown of the DGFiP cyberattack affecting 678,000 users, distinguishing between compromised personal data and secure account access, while analyzing conflicting claims regarding the scope of the intrusion.

The short version

A significant data leak occurred at France’s Direction générale des Finances publiques (DGFiP) in late June, impacting approximately 678,000 users. The incident involves the extraction of sensitive personal and business information but, according to the administration, does not grant access to the secure login portals on impots.gouv.fr. While the tax authority asserts that account credentials remain safe, the hacker group ZeroBytes claims to have secured broader access than officially acknowledged. This briefing separates the confirmed data types from the disputed scope of the intrusion.

The scope of the breach: What was taken

The incident, reported in late June 2026, targeted the information systems of the French tax authority. According to official updates and media reports, the compromised dataset encompasses 678,000 users, a figure that includes both private individuals and corporate entities.

For individual taxpayers, the stolen records are detailed and sensitive. The data reportedly includes:

  • Full names and addresses;
  • Taxable income (revenu fiscal);
  • Withholding tax rates (taux de prélèvement à la source);
  • Family quotient details.

For businesses, the nature of the compromised information differs. The administration notes that the data regarding companies is less sensitive than that of private citizens. The records for corporate users primarily consist of public identifiers such as SIREN numbers and company addresses. While still a privacy concern regarding corporate profiling, these elements do not carry the same immediate financial risk as individual income and tax rate data.

Crucially, the administration has stated that the stolen information does not allow an attacker to log into the secure accounts on the impots.gouv.fr platform. The breach concerns the extraction of stored data, not the compromise of the authentication keys required to access the live portal.

Conflicting claims: Administration vs. Hacker

A divergence exists between the official narrative and the assertions made by the perpetrator. The tax authority maintains that the breach was limited to the specific datasets mentioned above and that the integrity of the secure login system was not breached.

Conversely, the hacker known as ZeroBytes, who claimed responsibility for the theft on the day the investigation was announced, disputes this limitation. Speaking to French Breaches, ZeroBytes asserted that they had gained access far broader than what the administration suggests. The hacker also stated that financial gain was the primary motivation for the operation.

This creates a layer of uncertainty regarding the full extent of the intrusion. While the administration can confirm the data they know was extracted, the hacker’s claim of "broader access" implies the possibility of additional, unconfirmed data points or system vulnerabilities that have not yet been disclosed or detected by the authorities. At this stage, the 678,000 figure represents the confirmed impact, but the hacker’s testimony suggests the operational scope may have been wider.

Legal response and investigation

The French judicial system has moved quickly to address the incident. The Paris prosecutor's office has opened a formal investigation into the cyberattack. The inquiry is framed around the charge of participation in a criminal organization aimed at preparing a felony punishable by at least five years of imprisonment.

The investigation has been entrusted to the Office anticybercriminalité (Ofac), the specialized unit within the Paris prosecutor's office dedicated to fighting cybercrime. The probe focuses on the fraudulent extraction of data from an automated processing system implemented by the State. While the prosecutor has not yet publicly named the suspect in the formal charge, the attribution to ZeroBytes by the hacker group itself has been noted in the media coverage surrounding the opening of the case.

The administration has also indicated that the operation was more sophisticated than previous attacks on the fiscal system, suggesting a high level of technical capability on the part of the attackers. Users affected by the breach are expected to be contacted by the administration in the coming weeks regarding the incident.

Going further

Sources

Found an error? Email us — we correct factual mistakes and note significant updates on the article. Contact us

Keep exploring