CyberSecurityNews

French Tax Authority Data Breach Exposes 600,000+ Users Personal Tax-Related Data


France’s tax authority has confirmed a data breach affecting approximately 678,000 individuals and businesses after threat actors gained unauthorized access to internal information systems.

The incident involved stolen or impersonated credentials belonging to a Directorate General of Public Finances (DGFiP) employee and an authorized third party. The breach was disclosed in a press release issued on August 14, 2026.

According to DGFiP, the unauthorized access occurred during June and July 2026. A malicious actor later claimed responsibility for the intrusion on August 12 and 13, prompting a deeper forensic investigation.

DGFiP said it immediately disabled all accounts associated with the identified incidents after detecting unauthorized logins. However, initial access reviews did not reveal the data theft because of the attack’s sophistication.

Further investigations established that the attackers had used the compromised access to view and extract tax-related and property data before the accounts were disabled.

French Tax Authority Data Breach

The exposed information includes personal tax data, such as reference tax income, family quotient details, and withholding tax rates. For affected businesses, the attackers may have accessed company names and SIREN registration identifiers.

The incident also involved cadastral information, including property addresses and the surface area of real estate assets. The authority stressed that taxpayers’ online “Finances publiques” accounts were not compromised. It also said that personal and business usernames and passwords were not exposed in the incident.

This reduces the immediate risk of direct account takeover. However, the stolen data could still be used to support targeted phishing, identity fraud, tax scams, and social engineering attacks.

Tax-related records are particularly valuable to cybercriminals because they can help make fraudulent messages appear legitimate. Threat actors could use knowledge of a victim’s tax status, income-related information, company identity, or property address to impersonate government agencies, financial institutions, or tax advisers.

Following confirmation of the data theft, DGFiP notified France’s data protection authority, the Commission Nationale de l’Informatique et des Libertés, or CNIL.

The agency also implemented additional security measures, including preventive disconnections from sensitive information systems. Its IT teams are working with the Ministry of Economy and Finance, the High Official for Defense and Security, and France’s national cybersecurity agency, ANSSI.

Investigators are still determining the exact volume and nature of the stolen data, as well as the final number of affected users. DGFiP plans to contact every impacted individual and organization directly beginning the following week.

Notifications will be sent by email or post. They will identify the data that may have been accessed or extracted, along with relevant precautions. The authority said it will file a criminal complaint and publish further details as the investigation progresses.

Affected users should treat unsolicited tax-related communications with caution, avoid clicking links in unexpected messages, and independently verify requests through official government channels.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.



Source link