France’s Ministry of the Economy and Finance confirmed a cyber intrusion into the Direction générale des Finances publiques (DGFiP) that exposed data linked to roughly 680,000 individuals and businesses after unauthorized access in late June 2026. Reporting indicates the compromise involved impersonation or misuse of identity and access privileges, with at least 678,437 affected records later advertised for sale on the dark web by an actor calling itself ZeroBytes. The exposed population reportedly included both private taxpayers and professionals, and the intrusion was detected during a routine check before access restrictions were tightened.
Separate dark-web reporting tied to the same actor alleges a broader compromise of DGFiP-linked cadastral systems affecting 2,041,778 property holders, including land-registry data associating named individuals with fixed addresses and ownership information. Those claims say the attackers used valid credentials and an alleged multi-factor authentication bypass, and that they offered both the stolen data and continued access for sale, although that second breach had not been publicly verified or acknowledged by DGFiP at the time of reporting. The incident raises immediate risk of phishing, business email fraud, and other social-engineering attacks using tax, cadastral, and civil-status data.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
On 13 August 2026, a second ZeroBytes claim was observed alleging compromise of DGFiP's professional cadastral data server and offering both extracted data and ongoing access for sale. The report said the claim was unverified and that the actor asserted access was still active.
On 12 August 2026, a listing was observed in which ZeroBytes claimed to be selling a partial database of 678,438 French taxpayer records allegedly taken from the tax administration. The report said the claim was unverified and that a sample of 1,126 records was said to be publicly hosted.
ZeroBytes claimed it breached DGFiP's professional cadastral data server on 29 July 2026, extracting 252,149 rows said to cover 2,041,778 individuals. The actor said access used valid credentials with a multi-factor authentication bypass and did not require a VPN.
A dataset allegedly taken from the French tax administration was described as containing 678,438 taxpayer records dated June 2026. The claim said the actors accessed internal taxpayer search tools using VPN credentials obtained from internal servers before being disconnected.
The French Ministry of the Economy and Finance said unauthorized access to the DGFiP information system occurred in late June 2026 through identity impersonation and abuse of access privileges, allowing consultation and extraction of sensitive data on individuals and companies.
France’s Ministry of National Education published a notice about a security incident affecting the data of certain students. This is a separate incident from the DGFiP breach and identifies a new affected public-sector victim.
A crisis meeting involving multiple ministries was convened by Prime Minister Sébastien Lecornu in response to the DGFiP intrusion. The move marked an escalation of the French government's response beyond DGFiP's public statement and the prosecutor's investigation.
French authorities opened a criminal investigation into the DGFiP breach through the Paris Public Prosecutor’s cybercrime unit and assigned the case to OFAC, France’s cybercrime office. The move followed confirmation that data on about 678,000 taxpayers had been exposed.
DGFiP said individuals whose data was compromised would be contacted directly, France’s data protection authority would be notified, and a criminal complaint would be filed over the breach. The statement was made as the agency responded publicly to the incident.
The French Ministry of the Economy and Finance publicly confirmed a cyberattack affecting DGFiP, with data tied to roughly 680,000 individuals and businesses exposed and later offered for sale on the dark web. Reporting also noted the attacker had claimed a second exfiltration involving nearly two million land and property owners.
According to the Ministry of the Economy and Finance, the illegitimate access was discovered during a routine check and immediately cut off. DGFiP then implemented new restriction measures to stop the access and prevent further unauthorized use, while ANSSI and SHFDS were mobilized.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
19 references tracked. Mallory keeps watching after this page renders.
zdnet.fr
Open sourcehelpnetsecurity.com
Open sourcesecurityweek.com
Open sourceheise.de
Open sourcedarkwebinformer.com
Open sourcepresse.economie.gouv.fr
Open sourcedarkwebinformer.com
Open sourceeducation.gouv.fr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.