What France's Tax Office Has Confirmed About the Breach

France's Ministry of the Economy confirmed on 13 August that the Direction générale des Finances publiques (DGFiP), which runs the country's tax portal, had been hacked. According to Bercy, a malicious actor used a stolen identity to gain access to the DGFiP information system at the end of June 2026 and was able to view and extract data belonging to both private individuals and professionals.

Officials have not yet said exactly what information was taken or how many taxpayers are affected. French Breaches, a site that tracks cyberattacks in France, reports that the compromised data includes names, dates of birth, addresses, property identifiers, cadastral plot references, phone numbers and email addresses. The ministry has promised that affected people will be notified in the coming days.

The main danger is not the tax site itself, but the way criminals can reuse the stolen details. A fraudster who knows a taxpayer's name, address and tax reference number can craft an email or SMS that looks far more authentic than a typical mass phishing message.

The DGFiP has already reminded taxpayers that it never requests bank details, personal information, supplier or client identification data, invoice details or financial contact references by email or telephone. Anyone contacted with such a request should treat it as fraud.

Advertisement

Why Stolen Tax Data Makes Phishing Harder to Spot

Why a Tax Reference Number Makes a Fake Message Believable

The most consequential detail, if confirmed, is the presence of fiscal identifiers. An email quoting the correct tax reference number, postal address or property reference can break down the natural suspicion people have toward unsolicited messages. The scenario is realistic: a scammer may use the stolen details to convince the recipient that the message really comes from the DGFiP, then ask for a password or direct the person to a fake login page.

This is the difference between generic phishing and a breach-enabled attack. Most fraud schemes rely on volume and guesswork. A breach gives attackers information that only the tax administration or the taxpayer should know, increasing the chance that a recipient will click a link or enter credentials.

What the DGFiP Confirms and What Remains Unverified

The ministry has confirmed the intrusion and the fact that data was extracted. It has not confirmed the exact data fields, nor the number of taxpayers or professional users involved. The list reported by French Breaches is therefore a strong but not yet officially confirmed picture of the breach. That uncertainty matters because the specific risk to each person depends on what was actually taken: a phone number alone is less dangerous than a phone number combined with a date of birth, address and tax identifier.

Even with the official confirmation, there is no indication that passwords or direct access to tax accounts were compromised. The likely risk is indirect: using stolen identity data to trick people into handing over the missing access credentials.

Advertisement

How Taxpayers Should Handle Suspicious DGFiP Messages

The security advice below follows directly from the DGFiP's own warnings after the breach.

  • Check the sender's exact domain. A genuine DGFiP email comes from an address ending in "@dgfip.finances.gouv.fr". Any other domain, even one that looks similar, should be ignored.
  • Never click links in unexpected tax emails or SMS. Go directly to the official impots.gouv.fr portal by typing the address yourself, especially once breach notifications start arriving.
  • Verify the destination before entering any credentials. Official French government tax pages end in ".gouv.fr". If a link takes you anywhere else, close it.
  • Treat mobile numbers as a red flag. The DGFiP does not call from numbers starting with 06 or 07. However, scammers can spoof an official-looking number, so do not provide personal or banking information over the phone even if the number appears legitimate.
  • Do not provide bank details, passwords or personal data in response to email, text or phone requests. The DGFiP says it never asks for such information through these channels.
  • If you are notified that your data was exposed, be especially suspicious of any message quoting your tax reference number. That proves the sender may have stolen data; it does not prove authenticity.