The information system of the French Public Finances Directorate General was the victim of a fraudulent access breach at the end of June 2026, allowing the consultation and extraction of personal data. The Ministry of the Economy and Finance confirmed the incident on Thursday, August 13, without specifying the number of victims, while a specialized website suggests that nearly 678,000 people were affected.
In a statement released Thursday evening, the Ministry of the Economy and Finance acknowledged the breach. "On Wednesday, a malicious actor claimed illegitimate access to the information system of the Directorate General of Public Finances (DGFiP), which occurred at the end of June 2026, following identity theft," Bercy stated. Initial investigations confirm that this access, although severed at the end of June during an operational audit, nevertheless allowed "the consultation and extraction of data concerning individuals and professionals."
The ministry did not specify the exact nature of the compromised data or the number of taxpayers affected. The website French Breaches, which specializes in tracking cyberattacks in France, reported Thursday morning that 678,437 people were affected, including 392,867 individuals and 285,570 professionals. On the internet, the same site indicated that "the file is now reportedly for sale for several thousand euros."
Users whose data has been exposed will be contacted individually by the DGFiP, which will specify what information may have been consulted or extracted and, if necessary, the vigilance measures to adopt.
The situation could be even more serious. A representative from French Breaches told AFP on Thursday evening that a second data breach linked to the French tax authority (DGFiP) had been claimed, this time affecting "nearly two million property owners in France." According to the website, the hacker claims to possess names, dates of birth, addresses, property identification numbers, cadastral parcels, and information on owned properties, and maintains that they "still have access to the DGFiP account."
The Ministry of Economy and Finance (Bercy) did not mention this possible second intrusion in its press release. However, the ministry indicated that following the claim of responsibility for the June attack, "the Directorate General of Public Finances (DGFiP) immediately implemented new restrictive measures to stop it and prevent further unauthorized access." Thorough investigations are underway to determine the precise extent of the data and the number of users affected.
The DGFiP teams are working in conjunction with the High Official for Defence and Security Service (SHFDS) and the National Cybersecurity Agency of France (ANSSI). In accordance with the legal obligations applicable to this type of incident, the DGFiP will notify the National Commission for Information Technology and Civil Liberties (CNIL) and file a complaint.
Community
Comments
Write a comment
Be the first to comment on this article.