Skip to content
live markets
S&P 5007,785.76▲ 3.21%NASDAQ26,729.16▲ 2.38%DOW53,732.41▲ 2.33%GOLD4,437.30▲ 11.33%WTI82.40▲ 4.37%BRENT88.52▲ 5.09%EUR/USD1.1573▲ 1.66%USD/JPY159.31▼ 1.92%DXY99.64▼ 1.09%BTC$63,008▼ 0.10%ETH$1,879▲ 0.00%SOL$75.36▲ 0.10%TOTAL CRYPTO$2.25T▲ 0.11%
pulseofnations.
UTC --:--NYC --:--LON --:--WAW --:-- telegram ↗ bluesky ↗ Join the wire

France Tax Authority Confirms Breach Affecting 680,000 Taxpayers

France’s DGFiP confirmed hackers breached its systems and extracted data on 680,000 taxpayers after a threat actor claimed access to records on two million people.

Partner Surfshark VPN

France’s tax authority confirmed on August 13 that an attacker breached its information systems and extracted data belonging to individuals and businesses, two months after the intrusion was first detected. The Direction generale des Finances publiques (DGFiP) said in a statement that the attacker gained access through identity impersonation in late June, and the connection was severed during security controls at the end of that month. However, the unauthorized session had already allowed the attacker to view and extract data concerning private individuals and professional users.

Hacker Claims Millions of Records

A threat actor using the alias “ZeroBytes” claimed on a cybercrime forum on August 12 to have obtained cadastral records linked to more than two million property owners from the DGFiP’s Serveur Professionnel de Donnees Cadastrales (SPDC). According to CyberInsider, the hacker also claimed to have extracted 678,438 records from systems associated with impots.gouv.fr. The stolen data reportedly includes names, dates of birth, addresses, mailing addresses, MAJIC property identifiers, municipalities, cadastral sections and parcel numbers, and property rights information. ZeroBytes claimed they gained access to internal servers, connected to the agency’s VPN, and used an internal tool to search for information on individuals and businesses before their access was cut. Passwords and banking details were not among the data reportedly taken.

France’s Ongoing Public Sector Security Crisis

The DGFiP breach is the latest in a string of security incidents affecting France’s public sector this year. In February, the Ministry of Finance admitted that miscreants accessed a database containing French citizens’ bank details, stealing 1.2 million records. In March, a cyberattack on healthtech supplier Cegedim Sante resulted in approximately 15.8 million administrative files being stolen, with around 165,000 containing doctors’ notes. In April, France Titres, the government agency responsible for identity documents, was breached in an attack attributed to a 15-year-old that reportedly affected up to 19 million people. The French government is now working with ANSSI, the national cybersecurity agency, and the Haut fonctionnaire de defense et de securite to investigate the full scope of the DGFiP incident.

Investigation Underway, CNIL to Be Notified

The DGFiP said it would report the attack to France’s data protection regulator, the CNIL, and file a criminal complaint. Affected users will be contacted individually once investigators determine what information was exposed. The attacker’s claims about the scope of the breach remain unverified. DGFiP disputed the assertion that ZeroBytes retains access to its systems, stating that new restrictions were implemented immediately to stop unauthorized activity and prevent further intrusions. Security researchers have warned that stolen identity and cadastral data could be used to power convincing phishing, impersonation, and social engineering campaigns targeting affected individuals and businesses.

Sources: CyberInsider; The Register; FrenchBreaches; DGFiP official statement

React to this dispatch
Share this dispatch Telegram X WhatsApp Report an error

discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Next dispatch Dysphoria Botnet Compromises 296K IoT Devices Read →