Violazione alla DGFiP francese: dati fiscali di oltre 600.000 persone forse nelle mani di un hacker
Data Breaches

Illustrative image generated with AI

French DGFiP Breach: Tax Data of More Than 600,000 People May Be in a Hacker’s Hands

Hackers compromised France's DGFiP, exposing tax data of 600k+ individuals. Details on the breach, affected data, and what to do.

Text generated by artificial intelligence, published without human review. AI transparency

Unauthorized Access at the End of June

France’s Ministry of the Economy has confirmed a compromise of the information systems of the Direction Générale des Finances Publiques (DGFiP), the agency responsible for managing the country’s tax administration.

The unauthorized access allegedly occurred at the end of June, following the theft or misuse of another person’s digital identity. The intrusion was detected and blocked around the same time. The DGFiP subsequently introduced additional restrictions to prevent further unauthorized access.

The incident became public at the beginning of the week, when a hacker claimed responsibility for the operation. The Ministry of the Economy formally confirmed the breach in a statement issued on Thursday evening.

The attack may have allowed the perpetrators to view and extract information relating to both individuals and businesses. However, it is not yet known how many entities were actually affected, which data was viewed, or what information was copied from the administration’s systems.

ZeroBytes’ Claim and the Potentially Exposed Data

According to FrenchBreaches, the attack was claimed by a hacker operating under the alias ZeroBytes. The threat actor claims to have obtained information relating to more than 600,000 people.

The claimed data includes:

  • names;
  • other personal information;
  • tax identification numbers;
  • email addresses;
  • family circumstances;
  • information relating to tax status.

The claim has not been independently verified. The authenticity and completeness of the allegedly stolen data also remain unconfirmed.

FrenchBreaches also reports that the attacker may have compromised internal servers, gained the ability to connect to the DGFiP’s VPN, and used an internal tool to search for information about individuals and companies. According to this account, data exfiltration continued until access was revoked.

The DGFiP has not publicly attributed the operation to a specific group and has not confirmed ZeroBytes’ claims. The versions of the affected systems, the precise technical entry point, and the name of any internal tool used have also not been disclosed.

What Remains to Be Clarified

The investigation will need to determine whether the attacker merely accessed the data or also exported it on a large scale. The distinction is significant: simply exposing personal information can create risks, but a copied and reusable database increases the likelihood of targeted campaigns.

Tax data is particularly valuable to fraudsters and social engineering operators. A tax identification number associated with a name, email address, and family information can make fraudulent messages impersonating government agencies, banks, or advisors appear more credible.

No formal assessment of the incident’s severity has been published so far. The figure of more than 600,000 people comes from the attacker and has not been confirmed by the authorities.

The DGFiP has said it will contact affected individuals directly. Notifications should specify which categories of data may have been involved and what precautions should be taken. The administration has also announced that it will notify France’s data protection authority and file a criminal complaint.

What Potentially Affected Individuals Can Do

Anyone who receives a message from the DGFiP should carefully verify its authenticity and avoid using links or phone numbers included in suspicious communications. Exposed tax information can be used to create highly personalized phishing emails, not merely generic spam.

It is advisable to:

  • be wary of urgent requests for payment or tax documents;
  • never share passwords, one-time codes, or banking details by email or phone;
  • access public services by manually entering the official website address;
  • pay closer attention to notices concerning taxes, refunds, and administrative procedures;
  • change passwords reused across multiple services;
  • enable multi-factor authentication where available;
  • retain communications received from the DGFiP and compare them with any subsequent contacts.

It is not known whether authentication data or user credentials were exposed. As a result, based on the available information, it is not possible to determine whether all recipients should change their passwords or take specific measures. The administration’s individual notifications will be decisive.

Businesses should inform staff responsible for tax matters and payments. An attacker with access to legitimate data may attempt to alter bank details, forge refund requests, or impersonate a known contact.

A New Incident in the Series of Attacks on French Public Authorities

The DGFiP compromise adds to a series of incidents that have affected French public institutions this year.

In April, attackers targeted the website of the Agence Nationale des Titres Sécurisés (ANTS), the agency responsible for procedures involving passports, identity cards, residence permits, and driving licences. That same month, the Ministry of Education reported an attack against a system used to manage student accounts, resulting in the exposure of personal information.

In February, a breach affected part of the National Bank Accounts File, the database of bank accounts held in France. The incident involved information linked to approximately 1.2 million accounts, within an archive containing more than 300 million records.

Earlier this year, police also arrested a 20-year-old man suspected of carrying out dozens of breaches targeting government agencies, sports federations, and private companies. No public link has been established between that arrest and the DGFiP compromise.

The current case once again highlights the risks associated with privileged accounts and compromised digital identities. Even without a publicly disclosed software vulnerability, the theft or misuse of an identity can provide access to internal systems, VPNs, and search tools containing highly sensitive information.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsDGFiPdata breachtax dataFrancehackingcybersecuritypersonal information
Back to home