in

French Tax Authority Discloses Data Breach Affecting 678,000 People and Businesses

France’s Ministry of the Economy and Finance has disclosed a cybersecurity breach affecting approximately 678,000 individuals and businesses after an attacker gained unauthorised access to systems belonging to the General Directorate of Public Finances, known as the DGFiP. The ministry said the intrusion took place during June and July 2026 using credentials belonging to a tax office employee and an external contractor. The breach came to light after a threat actor listed a stolen database for sale on a hacking forum on August 12, 2026.

What Was Exposed

According to the disclosure reported by BleepingComputer, the data taken on individuals includes names, dates of birth, home addresses, telephone numbers, family circumstances, reference taxable income, and withholding tax rates. Cadastral data covering addresses and property sizes was also accessed.

Hosting 75% off

For businesses, the exposed information is described as less sensitive and includes SIREN registration numbers, business addresses, and addresses of authorised representatives.

The DGFiP has stated that online accounts belonging to individual and professional users were not compromised, and that user IDs and passwords were not part of the stolen data. After detecting the intrusion, the tax administration restricted access to sensitive systems and is investigating alongside ANSSI, France’s national cybersecurity agency. Affected people and businesses are being contacted directly by email or post.

Why Credential Theft Keeps Working

The detail that should get attention is how the attacker got in. This was not an exotic exploit against a novel vulnerability. It was valid credentials belonging to an employee and a contractor, used to walk through the front door.

Contractor and third-party access remains one of the weakest points in most large organisations, public or private. External accounts are often provisioned quickly, monitored less closely than employee accounts, and left active longer than they should be. When those accounts hold access to sensitive systems, one compromised laptop or reused password becomes an organisation-wide problem.

The Particular Problem With Government Data

Breaches at tax authorities carry consequences that last longer than most commercial incidents. A leaked password can be changed. A date of birth, home address, income figure, and property record cannot be. That combination is exactly what makes convincing, targeted fraud possible.

Anyone affected should expect a rise in phishing attempts that reference genuine tax details to establish credibility. Messages claiming to be about refunds, arrears, or account verification are the predictable follow-up to a breach of this kind, and they will be far more persuasive than usual because the sender can quote real information.

What Businesses Should Take From This

The practical lessons here apply well beyond France and well beyond government. Audit which third parties and contractors hold access to your systems and remove the ones who no longer need it. Require multi-factor authentication on every account that touches sensitive data, including contractor accounts. Log and review access patterns, because credential-based intrusions look like normal activity unless someone is watching for anomalies.

For freelancers and consultants who work inside client systems, there is a direct professional point. You are part of your client’s attack surface. Using a password manager, keeping multi-factor authentication switched on, and separating client work from personal accounts is not just good hygiene. It is increasingly something clients will ask about before they hand over access.

What to Watch Next

The investigation with ANSSI is ongoing, and key questions remain open, including how the credentials were obtained in the first place and whether the same access was used against other parts of the ministry’s systems. France, like the rest of the European Union, has been increasing public sector cybersecurity spending, but centralised digital tax systems concentrate risk by design. Efficiency and exposure tend to rise together.

Sources: BleepingComputer and Security Affairs.

Hosting 75% off

Unitree Robotics Set to List in Shanghai After Record 8,000 Times Oversubscription

OpenAI Disbands Its Preparedness Team and Splits Catastrophic Risk Work Across Other Groups