You trust your government with your most sensitive financial data. You assume it’s locked away in some high-security digital vault. Think again. The French Directorate General of Public Finances (DGFiP) just confirmed that 678,000 taxpayers—both individuals and professionals—had their records snatched in a sophisticated cyberattack.
It wasn't a sudden, Hollywood-style hack where someone smashed through a firewall in seconds. It was a slow, calculated crawl that started back in June 2026. Criminals used compromised credentials belonging to an official agent and an authorized third party. They didn't need to break the locks; they simply walked through the front door using stolen keys. Also making waves in this space: Why Everyone Is Actually Obsessed With Wispr Flow.
What actually happened to the data
The French government confirmed the intrusion occurred across June and July. Even though officials cut off access as soon as they realized something was wrong, the damage was already done. The attackers managed to siphon off a treasure trove of information.
For the average citizen, the stolen files include: Additional details into this topic are covered by TechCrunch.
- Reference taxable income
- Family quotient data
- Withholding tax rates
- Specific property addresses and property sizes
Businesses didn’t escape either. Company names and their SIREN identification numbers—essential bits of data for anyone wanting to commit corporate fraud—were part of the haul.
The authorities are quick to say that user passwords and personal online tax accounts remain "secure." That’s technical speak for "we didn't lose your login, so you don't need to change it." Don't let that lull you into a false sense of safety. The data that was taken is exactly the kind of "doxing" material scammers use to build hyper-convincing phishing campaigns.
The gap between official reports and hacker claims
If you’ve been following the news, you might see conflicting numbers. Some reports mention 678,000 victims. Others—sourced from the hacker claiming to be "ZeroBytes"—talk about millions of records.
Here is the truth: hackers love to inflate their impact to make their stolen goods more valuable on the dark web. The DGFiP’s figure of 678,000 is based on their own forensic audit. Stick to that number. The "2 million" claims circulating on hacking forums are largely unverified, sensationalized junk designed to drive up prices.
Why you need to act now
The government says they will reach out to those affected via email or postal mail. Do not wait for that letter to decide whether you're at risk.
If your data is out there, you are now a prime target for identity theft. These scammers aren't just sending random "verify your account" emails. They now have your actual tax income and property details. When a scammer calls you or sends a message that accurately references your specific tax status or property address, the likelihood of you falling for it goes up significantly.
Steps to take today
- Be skeptical of all communications. If you receive an email or letter claiming to be from the DGFiP, go to impots.gouv.fr directly. Never click a link in an email you didn't explicitly request. Type the URL into your browser yourself.
- Watch your accounts. Keep a sharp eye on your bank statements and credit reports. Unusual activity shouldn't be ignored.
- Double down on your own security. If you haven't enabled multi-factor authentication (MFA) on your personal and professional accounts, do it now. This breach proves that even government systems can be compromised; your personal email or bank account is likely far less protected.
- Assume your data is compromised. Even if you aren't one of the 678,000, these attacks happen with alarming frequency. Treat all digital contact with suspicion.
This isn't an isolated incident. France has seen a string of major data thefts this year, from the 43 million records taken from the unemployment agency in January to the bank account registry breach in February. The state is scrambling, with new cybersecurity plans and investments being announced, but bureaucracy moves slowly.
Your data security is ultimately your responsibility. Stop waiting for the government to protect your digital identity and start locking down your own information today. The thieves are already inside the house; don't make their job any easier.