France's tax authority, the DGFiP, has confirmed that hackers gained unauthorised access to its systems and extracted taxpayer data — in what has now emerged as two separate incidents.
On 13 August 2026, the Direction Générale des Finances Publiques (DGFiP) confirmed that unauthorised access to its systems had taken place. The confirmation followed a claim posted the previous day on a cybercrime forum by an attacker using the alias "ZeroBytes."
What Happened
According to DGFiP's own statement, the intrusion occurred in late June 2026 and was detected and cut off during a routine audit at the time. The attacker had used a stolen identity and a technique to bypass multi-factor authentication to gain internal access, which allowed data on individuals and businesses to be viewed and extracted before the access was severed.
The attacker claims to have extracted 678,438 lines of data, including names, addresses, tax identification numbers, dates and places of birth, family situation, revenu fiscal de référence (RFR) figures, and withholding tax rates. DGFiP has not independently confirmed the exact scope or volume of what was taken, and the investigation is ongoing.
A Second, Separate Incident
Hours after DGFiP's confirmation, the same attacker claimed a second, distinct breach — this time of the Serveur Professionnel de Données Cadastrales (SPDC), the system holding French land registry and property ownership records. This intrusion is claimed to have taken place on 29 July 2026, roughly a month after the first.
The attacker claims around 252,000 lines were extracted from this second system, potentially linking identities to specific property holdings, and claims the underlying database covers a far larger number of records. As of this writing, DGFiP has not issued an official confirmation of this second incident specifically.
What DGFiP Says It Will Do
DGFiP has stated that it has:
- Cut off the unauthorised access and applied additional security restrictions
- Notified the CNIL (France's data protection authority)
- Committed to contacting affected individuals directly once the scope of exposure has been determined, and advising them on what precautions to take
What This Means for You
If you're a French taxpayer, there is currently no confirmed action required unless DGFiP contacts you directly. Based on the categories of data reportedly involved, this looks like a data exposure rather than a case affecting your tax return or payments directly — no indication has emerged that filings, refunds, or amounts owed have been altered.
As a general precaution while this is investigated:
- Be wary of any email, SMS, or phone call claiming to be from DGFiP or impots.gouv.fr that asks you to click a link, confirm personal details, or make a payment — this is a common follow-up tactic after data leaks, and DGFiP will not ask for payment details this way
- If you do receive a genuine notification from DGFiP about this breach, follow the specific guidance it provides
- If in doubt about a message's authenticity, log into your Espace Particulier directly at impots.gouv.fr rather than clicking any link in the message itself
We'll update this page if DGFiP releases further confirmed details.
Sources: French tax authority admits data heist after crook touts 2M records (The Register) · France investigates tax authority breach after hacker claims 600,000 victims (The Record, Recorded Future News) · DGFiP: une 2ème cyberattaque revendiquée, plus de 2 millions de personnes concernées (details on the second, unconfirmed SPDC incident)