France's tax authority has confirmed that an intruder accessed its systems and extracted taxpayer data in late June after an alleged cybercriminal advertised a purported database of 2 million taxpayers on a cybercrime forum. The confirmation, issued by the Direction Générale des Finances Publiques (DGFiP) on August 14, adds another entry to a rapidly growing list of 2026 breaches inside France's public sector.
Stolen Credentials And An MFA Bypass
Using the alias “ZeroBytes”, the alleged crook claims to have used stolen identity credentials plus an MFA bypass technique to reach DGFiP's systems in late June. FrenchBreaches, a Paris-based breach-tracking service, put the number of affected taxpayers at close to 700,000: roughly 390,000 individuals and 285,000 businesses, with data including names, dates of birth, addresses, and property and land registry information.
Access Severed — Or Not
DGFiP said its audit had already terminated the attacker's access at the end of June and disputes the seller's claim of ongoing intrusion. The agency will notify France's data-protection watchdog CNIL and warn affected users once they are identified. Tax-agency records are especially valuable to attackers because they mix identity, financial, property, and employment data that cannot easily be reset like a password.
A Year Of French Government Breaches
The DGFiP heist is the latest in a string of public-sector incidents in France in 2026: the Ministry of Finance disclosed access to a bank-account database in February; healthtech supplier Cegedim Santé lost 15.8 million medical records in March; France Titres, the ID-documents agency, was breached in April by a suspected 15-year-old; and Tchap, the government messaging platform, disclosed a compromise in June. Related coverage: OpenAI's Daybreak cyber tools and Mindgard's $30M Series A for AI red-teaming.
Reporting based on coverage from The Register, Reuters, and the French Ministry of Economy.
