Bercy Confirms Two DGFiP Data Breaches, Including 678,000 Tax Accounts

The Direction générale des Finances publiques has confirmed two data breaches involving French tax systems, with roughly 678,000 personal and professional accounts affected by the first and about 200,000 people potentially exposed by a second incident linked to cadastral property records.

For the first attack, DGFiP director general Amélie Verdier said the stolen information included names, addresses, the number of tax parts and the reference tax income, among other fields, but not the full contents of a tax return. She stressed that the data alone does not allow direct access to secure accounts on impots.gouv, while acknowledging that its circulation makes identity theft easier. Affected people are to be contacted starting next week.

Verdier apologised to users and said the second breach, involving cadastral information, was still being assessed. She described that data as less sensitive than income-tax records because some of it can already be viewed by the public on request. According to the DGFiP, the attacker used a different tax-agent account for each attack and exploited the fact that double identification was not implemented in all cases.

The leaks were disclosed by a profile called ZeroBytes on an online forum. The confirmation comes as critics have argued that France is late in transposing the European NIS 2 cybersecurity directive, though Verdier said she could not say whether earlier adoption would have prevented the incident.

Why Leaked French Tax Data Is an Identity-Fraud Risk, Not a Direct Account Breach

Why Verdier Separates Direct Account Access from Identity-Theft Risk

The DGFiP's position is that the stolen tax data does not contain enough credentials to enter secure impots.gouv accounts, but that it is precisely the kind of personal dossier used to answer identity-verification questions or to open financial products in someone else's name. Name, full address, family situation via the number of parts and the reference tax income are valuable raw material for fraudsters even without a password. That distinction matters: it lowers the risk of an immediate account takeover, but it does not reduce the long-term risk of impersonation.

Tax Files Versus Cadastral Records: Two Different Exposure Profiles

The second confirmed event involves property-cadastre information, which Verdier framed as less sensitive because some of it is already accessible to the public. The main danger is not secrecy but plausibility: cadastral details can make a phishing message or a fraudulent call seem legitimate, especially when combined with the leaked tax identity data. A person who never lost a password could still be targeted with surprisingly accurate personal details.

The Control Failure Was Also a Deployment Gap

The attacker did not break the secure portal itself; according to the DGFiP, the intrusion relied on compromised agent accounts and a bypass of double identification. Verdier acknowledged that dual authentication was in place only in certain cases, not across the whole system, and said it will now be applied more broadly. That is an operational admission: the vulnerability was not merely a sophisticated external actor, but an incomplete roll-out of a standard account-protection control.

The NIS 2 and CNIL Questions Are Not Yet Closed

The DGFiP says it detected a compromised agent account in June and immediately cut access, but did not initially realise that data had been exfiltrated because the attack was more sophisticated than what it had seen before. Critics have questioned the delay in notifying the CNIL for the first attack and have linked the episode to France's slow transposition of the EU's NIS 2 directive. Verdier could not say whether the legislation would have prevented the incident, but the debate is likely to continue because the breach touches a core state digital service.

What French Taxpayers Should Do After the DGFiP Data Leaks

  • If you are among the 678,000 account-holders or the roughly 200,000 cadastral-record subjects, expect a DGFiP contact starting next week; verify any message through the official impots.gouv secure channel before responding.
  • Activate or confirm double authentication on your impots.gouv account now, because the DGFiP has said it was not applied in all cases and will only be extended soon.
  • Treat any call, SMS or email that quotes your name, address, number of tax parts or reference tax income as a potential impersonation attempt; do not provide additional personal, banking or payment details.
  • For any contact tied to the cadastral leak, remember that cadastral information is less sensitive but can make a scam look credible; no legitimate response requires a payment or remote access.
  • Keep a written record of suspicious messages and report them to the DGFiP or CNIL through their official portals if someone attempts to use the leaked data fraudulently.