France's Tax Authority Hacked: 678,000 Taxpayers' Financial Data Stolen
A hacker stole income and property records from France's tax authority using one stolen password — exposing 678,000 people's financial lives.
One Stolen Password. 678,000 Tax Records on a Crime Forum.
Last month, a hacker walked into one of France's most sensitive government databases — not by breaking through walls of code, but by using a single stolen password. By the time France's tax authority, the DGFiP (Directorate General of Public Finances), noticed something was wrong, the attacker had already copied the financial records of hundreds of thousands of people and put them up for sale.
This wasn't a sophisticated nation-state attack. It was a credential theft — and that's exactly what makes it terrifying.
What Actually Happened
In late June 2026, an attacker used stolen VPN credentials to log into DGFiP's internal systems. A VPN — a virtual private network — is the tunnel government employees use to access sensitive databases from outside the office. It's meant to be secure. But if someone steals your username and password, that tunnel opens right up for them.
The attacker browsed freely. Then they took what they wanted.
On August 12, 2026, a hacker going by 'ZeroBytes' posted the stolen database for sale on PwnForums, a well-known cybercrime marketplace. ZeroBytes claimed to have records on up to 2 million people. The DGFiP officially confirmed that at least 678,000 individuals and professionals were affected.
France's Public Accounts Minister David Amiel announced that victim notifications would begin on August 17, 2026. France's data protection authority, the CNIL, opened an enforcement review.
What Was Actually Stolen
This is where it gets personal. The breach didn't expose passwords or bank account numbers — but what it did expose is arguably more dangerous in the hands of a scammer.
The stolen records include:
- Reference tax income — your reported annual earnings on file with the government
- Family quotient — the tax formula that reveals household size and dependents
- Withholding tax rates — the exact percentage deducted from your paycheck
- Business names and SIREN numbers — France's equivalent of a business registration ID
- Property addresses and sizes — where you live and what your home looks like on paper
Put this together and a criminal knows roughly how much money you make, how many people are in your household, what business you run, and where you live. Passwords and login credentials were not part of the breach — but scammers don't need your password when they already know your life.
Why This Data Fuels Hyper-Targeted Fraud
Generic phishing emails are easy to spot. "Dear Customer, please verify your account" — you've seen it a thousand times.
This breach is different. With your exact withholding rate and reference income on hand, a criminal can write you an email that reads like it came straight from the DGFiP:
"Monsieur Dupont, our records show your 2025 withholding rate is 12.3%. A calculation error has resulted in a €487 overpayment. Please confirm your bank details to receive your refund."
That email will feel real — because it references information only the government is supposed to know. This is called spear phishing, and it converts at far higher rates than generic scams.
Business owners face a separate risk. With SIREN numbers exposed, attackers can pose as suppliers, government auditors, or banks and send fraudulent invoices or requests for payment to companies whose financial profile they already know.
What You Should Do Right Now
Whether you're based in France or a founder with French operations, these steps reduce your risk:
If you're an affected French taxpayer:
- Wait for official notification — the DGFiP will contact confirmed victims. Do not act on any email or text claiming to be the DGFiP until you've verified it through the official impots.gouv.fr website directly (type the address yourself — don't click links).
- Treat any tax-related communication as suspect for the next 12–18 months. Scammers will ride this breach for a long time.
- Report suspicious contacts to signal-spam.fr or France's cybermalveillance.gouv.fr reporting platform.
For everyone — affected or not:
Secure your accounts before the next breach catches you off guard.
- Enable two-factor authentication (2FA) on your email, banking, and tax accounts. Passkeys are even better — they're phishing-resistant by design and can't be stolen the way passwords can.
- Never verify sensitive requests over email alone. If someone claiming to be your tax authority, bank, or accountant asks for payment or personal details, call them back on a number you look up yourself.
- Check whether your email appears in past breaches using haveibeenpwned.com — free, no account needed. If it does, change that password everywhere you reused it.
- Freeze your credit if you're in the US or a country with credit bureaus. French residents: contact your bank directly about fraud alerts on your accounts.
- Remove your personal data from data brokers. Services like DeleteMe (paid) or manual opt-outs at the major brokers (Whitepages, Spokeo, BeenVerified) reduce what scammers can find about you elsewhere to cross-reference with stolen records.
If you run a business with French operations:
- Audit who has VPN access to your own internal systems. Every credential that isn't actively needed is a door that shouldn't be open.
- Require multi-factor authentication on all VPN logins — this single step would likely have prevented this entire breach.
- Brief your finance and accounts-payable teams on invoice fraud. With SIREN numbers in the wild, expect targeted business email compromise attempts.
The Bigger Picture
A single stolen work credential unlocked the financial records of 678,000 people. No sophisticated exploit. No elaborate hack. Just a username and password that someone shouldn't have had.
This is the most common way organizations get breached in 2026 — not through Hollywood-style attacks, but through basic credential theft and the absence of multi-factor authentication on sensitive access points.
Governments hold extraordinary amounts of financial data on ordinary people. When that data leaks, it doesn't just stay with one attacker — it gets sold, reshared, and weaponized for years.
Do This Now
- Watch for an official notification from the DGFiP — don't trust unofficial ones
- Enable 2FA or passkeys on your email and any financial accounts
- Never act on a tax refund or payment request sent by email — always verify directly
- Check haveibeenpwned.com for your email address
- If you manage a team: audit VPN credentials and enforce MFA today, not next quarter
Sources
Common Questions About Breach
What should I do immediately after a data breach?
Change your password for the affected account and any other account where you reused that password. Enable two-factor authentication. Monitor your bank and credit card statements. Place a free credit freeze at Equifax, Experian, and TransUnion. If your Social Security number was exposed, file an identity theft report at IdentityTheft.gov.
How long do companies have to notify me after a data breach?
In the US, notification timelines vary by state — typically 30 to 90 days after a breach is confirmed. Under GDPR in Europe, companies must notify regulators within 72 hours. Many states require individual notification "in the most expedient time possible." Companies often delay notification while investigating.
Should I freeze my credit after a data breach?
Yes. A credit freeze prevents new accounts being opened in your name without your explicit unfreeze. It is completely free at all three major bureaus, does not affect your credit score, and does not impact existing accounts. Unfreeze temporarily when you need to apply for credit, then refreeze immediately.
More in breach
Stay invisible. Follow @hack_decoded