France's tax office admits hackers walked off with data on 678,000 people

A criminal listed the stolen database for sale on a hacking forum in August. The French finance ministry now says property records and tax figures were among the files taken.

ThreatVectr Newsdesk· 4 min read
Photoreal editorial photograph of a large empty industrial tractor assembly hall at dusk, warm overhead lights on green paint bays, no visible logos or text, wi
Share

Key points

  • France's tax authority, the DGFiP, says an attacker stole data on 678,000 individuals and businesses.
  • The breach was uncovered after a user calling themselves "ZeroBytes" listed the database for sale on the PwnForums hacking forum on 12 August 2026.
  • Stolen fields include reference tax income, family quotient, withholding rates, company names and SIREN business IDs, plus property addresses and sizes from the national land registry.
  • The ministry says login usernames and passwords were not taken, and online accounts stayed intact.
  • Affected people will be contacted by email or letter starting next week.

The French Ministry of the Economy and Finance has confirmed that criminals broke into systems at the General Directorate of Public Finances, the country's tax authority known as the DGFiP, and made off with records on 678,000 individuals and businesses.

The ministry disclosed the breach after a user on a hacking forum did it for them. First reported by BleepingComputer, someone using the handle "ZeroBytes" advertised the stolen data for sale on PwnForums on 12 August 2026.

Only then did the tax office start digging.

What did the hackers actually take?

Tax and property information, but not passwords. The ministry says the attackers used working access points inside the DGFiP to pull records on 678,000 people and companies before those doors were shut.

For individuals, that included reference tax income (the figure French benefits and thresholds are based on), family quotient (the household size used to calculate tax), and withholding tax rates. For businesses, it included company names and SIREN numbers, the nine-digit ID every French company gets when it registers.

Cadastral data was also accessed. In plain terms, that is the national land registry: home addresses and property sizes.

The ministry stresses that online tax accounts themselves were not broken into, and that user IDs and passwords were not stolen. So no one needs to reset a tax-portal password over this. What was taken is the underlying data those staff-side systems hold.

How big could it get?

Potentially much bigger than the 678,000 figure. In their sales post, ZeroBytes claimed they also got into the Serveur Professionnel de Données Cadastrales, or SPDC, an internal portal that fronts France's central land and property ownership registry.

That portal reportedly exposes data on roughly 20 million French citizens. The attacker says they only managed to pull 252,149 records covering over 2 million people before giving up, complaining that scraping the system was, in their words, "just horrible" and would have taken months.

They also claimed they were still logged in to the panel at the time of posting.

In practice, that is the failure mode here: a valid session into a sensitive back-office system that stayed valid long enough for a stranger on a forum to brag about it.

What should people in France do?

Wait for the letter or email, then read it carefully. The finance ministry says it will contact every affected person starting next week, spelling out which fields were exposed and what to watch for.

Until then, the sensible moves are the ordinary ones: be suspicious of unexpected messages that claim to be from the tax office, especially anything urgent about refunds or overdue payments. Criminals holding real tax figures can craft very convincing phishing emails, meaning fake messages designed to trick you into handing over money or logins.

Detail Figure
Individuals and businesses confirmed affected 678,000
Records claimed stolen from land registry portal 252,149
People covered by those records Over 2 million
Date listing appeared on PwnForums 12 August 2026

Is this a one-off for the French government?

No, and that is the uncomfortable part. In January, French regulator CNIL fined national employment agency France Travail 5 million euros after a breach exposed 43 million people. A month later, the finance ministry disclosed a separate incident at the national bank account registry FICOBA affecting 1.2 million accounts. France Titres, which handles official documents, later reported a listing of 19 million records tied to the National Agency for Secure Documents.

One thing the post-mortem will say: the perimeter held, the sessions did not.

Operational takeaway: if a back-office panel can quietly export millions of citizen records over weeks, the control that matters is not the login page, it is what happens after login.

© 2026 Threat Vectr