How a Late-June Intrusion Exposed Sensitive Tax Records

French prosecutors have opened a formal investigation into a cyberattack on the country's tax administration after officials confirmed that an intruder extracted data on close to 700,000 taxpayers and businesses. The breach occurred at the end of June, when a hacker gained access to the Direction générale des Finances publiques (DGFIP) information system by means of a usurped identity, according to the finance ministry.

The cybercrime section of the Paris public prosecutor's office took up the case on Saturday and assigned it to the Office anti-cybercriminalité (Ofac). The inquiry covers the fraudulent extraction of personal data from a state-run automated processing system, as well as suspected participation in a criminal association preparing an offence punishable by at least five years in prison.

At a press briefing on Friday, the DGFIP apologised to affected users and said 678,000 individuals and professionals were involved, while earlier official communication cited a figure of around 700,000. The authority confirmed that beyond names, dates of birth, phone numbers and postal or email addresses, the hacker was able to consult more protected data: household composition, number of tax shares, the applicable tax rate and the revenu fiscal de référence. For businesses, the exposed information mainly consisted of Siren numbers, company addresses and the identity of legal representatives.

The DGFIP said the stolen data does not allow access to the secure account on impots.gouv.fr, and that affected users would be contacted at the start of the following week to be warned about identity theft risks.

What the DGFIP Breach Means for France's Cyberdefense

What makes this breach more serious than a contact-list leak

The DGFIP has confirmed that the intruder did not simply take names and addresses. The presence of the revenu fiscal de référence, the tax rate and the household composition changes the risk profile: those data points can be combined with public or separately stolen records to impersonate taxpayers or target higher-income households. Bercy's statement that the data do not give access to impots.gouv.fr limits the immediate account-takeover risk, but it does not remove the longer-term identity-fraud exposure.

France's repeated public-sector cyber problem

This breach is being treated as more than an isolated incident. France is the most affected European country and the second most affected worldwide in leaked accounts, with 43.4 million accounts compromised in the first half, according to a Surfshark figure cited by the ministry. That statistic covers more than state systems, but it explains why the Paris prosecutor's cyber section moved quickly and why the episode is already feeding into the wider debate about the state's cyberdefence shortcomings.

Who stands to gain from the stolen records

If the extracted data were resold, the buyers would most plausibly be criminal networks specialising in identity theft or financial fraud. Households with higher reported incomes are the obvious targets because the tax rate and reference income reveal which individuals have the strongest financial profile for fake credit applications or impersonation scams. For companies, the administration has said the leaked data are less sensitive than those for individuals, although Siren numbers and legal representative details can still be reused in business-identity fraud and phishing campaigns aimed at employees.

What Affected French Taxpayers Should Do Now

The DGFIP has said affected users will be contacted at the start of the week. Treat that notice as the moment to verify, not as a reason to lower your guard.

  • If you receive a message claiming to be from the tax authority, open impots.gouv.fr by typing the address into your browser rather than clicking links in an email or SMS. The breach did not compromise secure account logins, but stolen personal data makes phishing attempts harder to spot.
  • Do not share your revenu fiscal de référence, tax rate or household composition in response to unsolicited calls, emails or messages. These are among the data points confirmed as exposed and could be used to build a convincing impersonation.
  • Review your tax account for changes you did not initiate, especially any modification of contact details or bank accounts used for tax refunds, once the official notification arrives.
  • If you are a business, brief finance and HR staff that Siren numbers and legal representative details may be used in fraudulent invoices, requests for banking changes or targeted phishing campaigns.