Skip to content
Beveiligingsnieuws

680,000 Affected in French Tax Data Breach

DGFiP datalek

A major breach has been disclosed by France’s Directorate General of Public Finances (DGFiP), affecting an estimated 680,000 affected individuals. The incident came to light after investigators confirmed that attackers accessed DGFiP systems and stole specific information related to taxpayers and property records.

According to DGFiP, the intrusion began in June and July, and unauthorized access was stopped soon after it was detected. At that time, however, the public tax authority did not find evidence that data was actually exfiltrated.

How DGFiP says the attackers got in

DGFiP later determined that the attackers used compromised credentials belonging to an employee and a third-party account. With those credentials, the threat actors were able to access internal systems and take information belonging to 680,000 affected users.

DGFiP also states that the breach was reported promptly to France’s data protection authority, CNIL. The agency says it continues investigating the nature and full scope of the incident, including the precise number of people potentially impacted.

What data was compromised

DGFiP reports that the stolen dataset included several categories of information tied to tax situations and real estate. The compromised details include:

  • Reference tax income
  • Withholding tax rate
  • Company names
  • Unique identifiers
  • Cadastral data linked to real estate addresses and surfaces

Importantly, DGFiP says that no other types of information were compromised. In particular, it reports that usernames and passwords were not accessed or taken during this attack.

Timeline: intrusion stopped, exfiltration confirmed later

DGFiP’s initial disclosure focused on discovery of unauthorized access during June and July, with immediate suspension following detection. Only later did the authority confirm that attackers had actually stolen information.

In its follow-up confirmation, DGFiP states that attackers obtained and exfiltrated data belonging to 678,000 users—an update that aligns with the approximate scale of 680,000 affected people referenced in the public disclosure.

The tax authority says it will contact each affected individual directly, once the investigation and identification steps are complete.

What makes the breach stand out

While many breaches focus on stolen credentials and system access, this case highlights the particular combination of taxpayer and property-related data. DGFiP indicates that the compromised information extends beyond purely financial details, reaching cadastral elements tied to real estate addresses and measurements.

That broader data mix matters because it can be used to support targeted fraud, identity enrichment, or more convincing social engineering attempts. Even when passwords are not stolen, the disclosure of sensitive attributes can still create risk for affected individuals and organizations.

Broader context: cyber incidents affecting European registries

This announcement arrives about a month after a disruptive cyberattack impacted another European government agency: Romania’s National Agency for Cadastre and Property Registration (ANCPI).

Reports related to the ANCPI incident described an attacker known as ByteToBreach. That intrusion reportedly involved theft of information including employee credentials and internal documents, as well as an attempted extortion. When the extortion effort failed, the attacker reportedly wiped encrypted data, disrupting official applications, websites, and email services and halting parts of the real estate market.

DGFiP’s disclosure does not link the two events directly, but it underscores a broader trend: government-held data systems—especially those related to finance, property, and civil records—remain attractive targets for threat actors.

What happens next for affected people

DGFiP says it will reach out to people believed to be affected. For individuals, the practical takeaway is to stay alert for communications that reference personal tax details or property information, especially if they arrive through unexpected channels.

Although DGFiP reports that usernames and passwords were not compromised, the fact that specific tax and cadastral elements were stolen increases the need for caution. If contacted by parties claiming to verify account issues or request “urgent” information, individuals should verify legitimacy using official DGFiP channels rather than following links from unsolicited messages.

DGFiP’s investigation and scope verification

Beyond confirming what was stolen, DGFiP emphasizes that it is still investigating the nature and reach of the breach. That includes determining the exact number of potentially affected individuals.

For cybersecurity response teams, this stage typically involves reviewing logs, reconstructing attacker actions, and validating the extent of exfiltration. The agency’s public posture suggests the breach assessment is ongoing, even though key points—like the credential source and the general categories of compromised data—have already been clarified.

Conclusion

France’s DGFiP has disclosed a data breach affecting roughly 680,000 affected individuals, with DGFiP reporting that attackers used compromised credentials to access internal systems and steal taxpayer and cadastral-related information. The authority says it notified CNIL, suspended unauthorized access soon after detection, and later confirmed that exfiltration occurred.

As DGFiP continues investigating the incident’s scope, affected individuals can expect direct outreach and should remain cautious about communications that appear tied to their tax and property data.

Source: https://www.securityweek.com/680000-impacted-by-french-tax-authority-data-breach/