← Back to Feed

French tax authority data breach affects 678,000 individuals

August 17, 2026 · BleepingComputer · Severity: CRITICAL

The French Ministry of the Economy and Finance disclosed a data breach affecting 678,000 individuals and professionals after an attacker, using the handle “ZeroBytes,” gained unauthorized access to the General Directorate of Public Finances (DGFiP) systems. The breach was discovered on August 12, 2026, when the threat actor listed the stolen database for sale on the PwnForums hacking forum. Investigations revealed that the attacker accessed and exfiltrated tax data (reference tax income, family quotient, withholding tax rate), business data (company name, SIREN number), and cadastral data (addresses, property sizes). The attacker specifically targeted the Serveur Professionnel de Données Cadastrales (SPDC), an online land registry platform, claiming they could access data on roughly 20 million citizens but only extracted 252,149 records covering over 2 million people due to the difficulty of scraping. The French tax administration shut down access to sensitive systems upon detection and is collaborating with the National Cybersecurity Agency of France (ANSSI) to assess the full impact. User online accounts and credentials were not compromised. The French Data Protection Authority (CNIL) has been notified, and affected individuals will be contacted via email or letter with details and precautions. This incident is part of a broader wave of cyberattacks on French government agencies, including a €5 million fine against France Travail for a breach of 43 million records, a breach of the national bank account registry (FICOBA) affecting over 1.2 million accounts, and a recent sale of 19 million records allegedly stolen from the National Agency for Secure Documents (ANTS).

Key Takeaways

  • Immediately isolate and audit any externally facing administrative portals (e.g., cadastral data platforms) that contain sensitive citizen or business records. The attacker gained access via the SPDC land registry portal, which was poorly secured and allowed prolonged data extraction. Organizations should enforce strict access controls, multi-factor authentication, and rate limiting on such systems.
  • Implement continuous monitoring and automated alerts for unusual data extraction patterns. The threat actor admitted the scraping process was slow and would take months, yet the breach went undetected until the attacker publicly listed the data for sale. Deploying behavioral analytics to flag bulk downloads or anomalous query volumes can shorten detection time.
  • Prepare and rehearse a breach notification plan that includes direct outreach to affected individuals within regulatory timelines. The French Finance Ministry will contact victims via email or letter. Organizations should have templates, contact channels, and legal review processes ready to comply with data protection authorities (e.g., CNIL) and minimize reputational harm.
☕ Buy a Coffee