France has confirmed a France tax authority breach involving taxpayer information, but officials still do not know which records were taken or how many people and businesses were affected. The Economy Ministry said an intruder accessed systems run by the Directorate General of Public Finances, known as DGFiP, in late June and was able to consult and extract data.
The access was identified and shut down during the same period, according to the ministry. The incident reached public view only after someone later claimed responsibility. DGFiP subsequently added restrictions intended to block further unauthorized access.
That sequence matters: the breach itself is confirmed, while the public account of its scale is not. A hacker using the name ZeroBytes claimed responsibility, FrenchBreaches, a site that tracks reported French data leaks, said. DGFiP has not named an attacker or validated that claim.
What is known about the France tax authority breach?
The ministry said the attacker gained access after stealing or improperly using another person’s identity. It confirmed that information relating to both individual and business taxpayers was viewed and extracted. Reuters reported that the ministry described the incident as a cyberattack involving the consultation and extraction of taxpayer data.
Officials are still investigating the categories of information involved and the number of affected taxpayers. That leaves open whether particular tax records, contact details or other data fields were exposed in any given case.
FrenchBreaches reported, based on the alleged attacker’s account, that more than 600,000 people could be involved. Reuters separately reported a claim involving close to 700,000 taxpayers, while another report cited 678,438 purported data entries. These are variations of an unverified claim, not competing government totals. The ministry has not confirmed the number, the alleged dataset, or its authenticity.
What will DGFiP do for affected taxpayers?
DGFiP says it will contact affected users individually. Those notices are expected to identify data that may have been consulted or extracted and outline any precautions the agency considers appropriate. Until that work is complete, there is no confirmed public count of people or businesses caught in the incident.
The authority also said it would notify France’s data-protection regulator, file a criminal complaint and release more information as investigators establish the breach’s scope. The ministry statement was issued late that week, after the access had already been cut off.
The incident follows another French public-sector data exposure reported in February, when part of the National Bank Accounts File was breached and information tied to roughly 1.2 million accounts was exposed, according to therecord.media. The available reporting does not establish a connection between that case and the DGFiP intrusion.
This story draws on original reporting from The Record.