France's tax office admits hackers walked off with data on 678,000 people
A criminal listed the stolen database for sale on a hacking forum in August. The French finance ministry now says property records and tax figures were among the files taken.

Key points
- France's tax authority, the DGFiP, confirmed an attacker stole data on 678,000 individuals and businesses.
- The breach surfaced after a user calling themselves "ZeroBytes" listed the database for sale on the PwnForums hacking forum on 12 August 2026.
- Stolen fields include reference tax income, family quotient, withholding rates, company names, SIREN business IDs, plus property addresses and sizes from the national land registry.
- Login usernames and passwords were not taken, and online tax accounts stayed intact.
- Every affected person will be contacted by email or letter starting next week.
The French Ministry of the Economy and Finance confirmed that criminals broke into systems at the General Directorate of Public Finances, the country's tax authority known as the DGFiP, and walked off with records on 678,000 individuals and businesses. The ministry disclosed the breach only after someone else did it first: a user on PwnForums going by "ZeroBytes" advertised the stolen data for sale on 12 August 2026, first reported by BleepingComputer.
Only then did the tax office start digging.
What did the hackers actually take?
Tax and property information, not passwords. Attackers used working access points inside the DGFiP to pull records before those doors were shut. For individuals, that meant reference tax income (the figure French benefits and thresholds are based on), family quotient (the household size used to calculate tax) and withholding rates. For companies, it included names and SIREN numbers, the nine-digit ID every French business gets at registration.
Cadastral data was also accessed. That's the national land registry: home addresses and property sizes. The ministry stressed that online tax accounts weren't broken into and that user IDs and passwords weren't stolen, so nobody needs to reset a tax-portal password over this.
How big could it get?
Potentially much bigger than 678,000. ZeroBytes also claimed access to the Serveur Professionnel de Données Cadastrales, or SPDC, an internal portal fronting France's central land and property ownership registry. That portal reportedly exposes data on roughly 20 million French citizens. The attacker says they pulled only 252,149 records covering over 2 million people before giving up, complaining that scraping the system was, in their words, "just horrible" and would have taken months.
They also claimed they were still logged into the panel at the time of posting.
That's the real failure mode here: a valid session into a sensitive back-office system that stayed valid long enough for a stranger on a forum to brag about it. The ANSSI, France's national cybersecurity agency, is now helping assess the full extent of the breach.
What should people in France do?
Wait for the letter or email, then read it carefully. The ministry says it will contact every affected person starting next week, detailing which fields were exposed and what to watch for.
Until then, treat unexpected messages claiming to be from the tax office with suspicion, especially anything urgent about refunds or overdue payments. Criminals holding real tax figures can craft convincing phishing emails, meaning fake messages designed to trick you into handing over money or logins.
| Detail | Figure |
|---|---|
| Individuals and businesses confirmed affected | 678,000 |
| Records claimed stolen from land registry portal | 252,149 |
| People covered by those records | Over 2 million |
| Date listing appeared on PwnForums | 12 August 2026 |
Is this a one-off for the French government?
No, and that's the uncomfortable part. In January, French regulator CNIL fined national employment agency France Travail 5 million euros after a breach exposed 43 million people. A month later, the finance ministry disclosed a separate incident at the national bank account registry FICOBA affecting 1.2 million accounts. France Titres, which handles official documents, later reported a listing of 19 million records tied to the National Agency for Secure Documents.
The pattern the post-mortem will confirm: the perimeter held, the sessions didn't.
The control that matters here isn't the login page. It's what a system quietly allows after login, and for how long it keeps allowing it while nobody's watching.



