France’s tax authority, the Direction générale des Finances publiques (DGFiP), has disclosed a data breach affecting approximately 678,000 individuals and businesses after attackers gained unauthorized access to its information systems using impersonated credentials.
The French Ministry of Economy and Finance announced on August 14 that the intrusions occurred in June and July 2026. A malicious actor claimed responsibility for the access on August 12 and 13, prompting a deeper investigation into the incident’s scope and consequences.
According to DGFiP, the attackers accessed internal systems by impersonating the credentials of both a DGFiP employee and an authorized third party. The authority said it immediately disabled all accounts associated with the identified incidents after detecting the intrusions.
French Tax Authority Data Breach
Initial access-control reviews did not identify evidence of data theft. However, subsequent investigations determined that the compromised accounts had been used to consult and extract data before they were terminated.
DGFiP attributed the failure to initially detect exfiltration to the sophistication of the attack. The agency has not disclosed the technical method used to obtain or impersonate the credentials, whether multi-factor authentication was bypassed, or the identity of the threat actor behind the activity.
The breach involved tax-related and cadastral information belonging to private individuals and professional entities. For individuals, the exposed records may include reference taxable income, family quotient information, withholding tax rates, and property-related addresses and surface area data.
Information associated with businesses may include company names and SIREN identifiers, France’s business registration number used to identify legal entities.
Press said the exact number of affected users and the final volume of data extracted remain subject to the ongoing investigation.
DGFiP stressed that the online Finances publiques spaces used by individual and business taxpayers were not compromised. It also said that user login credentials and passwords were not exposed during the incident.
DGFiP has notified France’s data protection regulator, the Commission nationale de l’informatique et des libertés (CNIL), after confirming the data theft.
The tax authority is also coordinating with the Ministry of Economy and Finance’s High Official for Defense and Security service and the French National Agency for the Security of Information Systems (ANSSI).
Following new findings from the investigation, DGFiP said it implemented additional security measures, including precautionary shutdowns of access to sensitive information systems.
The decision indicates that officials are assessing whether the credential abuse could have posed a broader risk to government systems that hold financial and cadastral data.
The authority intends to file a criminal complaint and said it will release further details as investigators establish the full scope of the incident.
DGFiP will begin directly contacting affected individuals and businesses next week. The notifications, delivered by email or postal mail, will identify the data that may have been viewed or extracted and provide relevant security guidance.
Affected users should remain alert to targeted phishing, fraudulent tax notifications, identity fraud, and social engineering attempts.
Tax, business, and property information can make malicious communications appear credible, even when the attackers do not possess taxpayer portal usernames or passwords.
The incident highlights the security impact of compromised privileged identities in government environments, where a single authenticated account can provide access to extensive repositories of financial and property information.
Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN. Gain complete phishing visibility to strengthen your SOC and reduce MTTR