France’s Economy Ministry has put a number on the DGFiP data breach: 678,000 individuals and professionals had tax and cadastral records consulted and extracted after attackers used stolen credentials in June and July 2026. Headlines round that to 680,000. The official figure comes from investigations that started when a forum actor calling themselves ZeroBytes advertised the haul on 12 August — not from the first containment pass, which missed the theft.
If you file French income tax, run a small company with a SIREN, or own property whose cadastral details sit in DGFiP systems, this is the notice to treat as real. Canonical record: DGFiP 2026 tax-authority breach.
What happened in the French tax authority data breach
On 12 and 13 August 2026, a malicious actor publicly claimed illegitimate access to the information system of the Direction générale des Finances publiques (DGFiP). The ministry’s press release n°953 (Paris, 14 August) says those accesses took place in June and July 2026 and rested on impersonation of identifiers belonging to a DGFiP agent and an authorised third party.
DGFiP says it cut the implicated accounts as soon as the intrusions were detected. Access checks at that moment did not show that data had been stolen. The ministry attributes that miss to the sophistication of the attack. Deeper work after the 12 August claim established that, before the cut-off, the accesses had been used to consult and extract data on 678,000 particuliers et professionnels.
BleepingComputer and SecurityWeek reported the same census on 17 August. SecurityWeek’s “680,000” is a round of the ministry’s 678,000 — BreachHistory stores 678000 as the attested count.
After the theft was identified, DGFiP notified CNIL, shut additional sensitive systems as a precaution, and brought in ANSSI plus the ministries’ Haut fonctionnaire de défense et de sécurité service. The agency said it would contact each affected person the following week by email or letter, file a complaint, and publish further details as the investigation continues.
What data was exposed — and what was not
The ministry’s inventory is specific. For individuals, extracted or consulted tax data included:
- Reference tax income (revenu fiscal de référence)
- Family quotient (quotient familial)
- Withholding tax rate (taux de prélèvement à la source)
For businesses: company name (raison sociale) and SIREN number. Cadastral data on real-estate addresses and property surface areas were also accessed.
What DGFiP says was not compromised:
- Online “espace particulier” and professional user accounts
- Usernames and passwords of individuals and professionals
That split matters. Attackers who hold your RFR and withholding rate cannot log into impots.gouv.fr with a stolen password from this incident — the ministry says those credentials were not taken. They can write a tax-phishing letter that cites a real income band and a real withholding rate. That is the residual harm.
What this is not: a dump of every French taxpayer. 678,000 is large and it is not 40 million. ZeroBytes separately claimed they sat on the Serveur Professionnel de Données Cadastrales (SPDC) land-registry portal with a theoretical reach of about 20 million citizens and only finished scraping 252,149 records covering more than 2 million people. Treat that actor narrative as a claim. The number that belongs in a catalog census is the ministry’s 678,000 until Bercy publishes a revision.
How the attack worked
The confirmed path is credential theft, not a named ransomware encryptor. The ministry describes usurpation of a DGFiP staff identifier and of a third-party account that was authorised to be there. That is a classic privileged-access failure: two identities, one internal and one external, both treated as legitimate until they were not.
Forum coverage adds colour the ministry does not attest. ZeroBytes listed a stolen database for sale on PwnForums around 12 August and claimed ongoing panel access to SPDC, saying extraction was “horrible to scrape” and would have taken months. DarkWebSonar circulated a screenshot of the listing. BleepingComputer notes France had not mentioned the incident in the actor’s telling — which matches the timeline of a silent June–July intrusion followed by a noisy August claim.
Unknowns that still matter:
- How the agent and third-party credentials were stolen (phishing, infostealer, shared password, compromised contractor laptop)
- Whether SPDC was the only surface or one of several
- Whether the 678,000 is the final unique-person census or a lower bound while forensics continue
- Whether a public dump will follow the forum sale post
The ministry is explicit that investigations continue on nature, volume, and the exact number of usagers concerned. Expect the letter you receive to be more precise than the press release about your fields.
Who is at risk
Individuals in the 678,000. If you get a DGFiP or Bercy letter next week describing this incident, assume your RFR, family quotient, withholding rate, and any cadastral address/surface fields in scope are in criminal hands. Watch tax-themed phishing immediately — do not wait for the envelope.
Professionals and companies. SIREN plus raison sociale is enough to forge invoice fraud, URSSAF-style calls, and “your PAS rate changed” emails aimed at payroll staff. Finance teams should brief accounts-payable this week.
Property owners. Cadastral address and surface data feeds deed-fraud and fake-notary scams. If you are selling or buying a home, verify any “cadastre update” message through a notaire you already appointed, not through a PDF in email.
People outside the 678,000. Copycat phishing will still use the headline. If you did not receive an official letter and your impots.gouv.fr login still works with your usual second factor, you are not automatically in the extract. You are still a target for generic “DGFiP data breach — confirm your RFR” lures.
DGFiP staff and contractors. The confirmed path ran through an agent identity and a third-party identity. Internal spear-phish that cites this incident to harvest more MFA codes is the obvious next move.
Timeline
- June–July 2026 — Illegitimate access using a DGFiP agent identifier and an authorised third-party identifier, per the 14 August communiqué.
- Detection (undated in the public notice) — DGFiP interrupts the implicated accounts. Access checks do not flag data theft.
- 12–13 August 2026 — ZeroBytes claims the intrusion on a hacking forum and markets a database; ministry clock on deep investigation starts 12 August.
- 14 August 2026 — Economy Ministry press release: 678,000 individuals and professionals; CNIL notified; ANSSI engaged; individual notices promised the following week.
- 17 August 2026 — BleepingComputer and SecurityWeek carry the 678,000 / ~680,000 census to an English-language audience.
What the company and regulators said
There is no separate “company” here. DGFiP is the tax administration. The Economy Ministry spoke for it. CNIL was notified as soon as the theft was identified. ANSSI is in the investigation. DGFiP said it will file a complaint.
Earlier English coverage on 14 August summarised a confirmation of unauthorised access without the 678,000 figure. BreachHistory first indexed the row on that thinner confirmation, then on an actor/press ~600,000. The 14 August French communiqué — and the 17 August trade-press wave — is the census update. Use 678,000 unless Bercy revises it.
France Travail’s €5 million CNIL fine over a 43-million-person breach, the FICOBA bank-registry incident affecting more than 1.2 million accounts, and the France Titres / ANTS sale claim around 19 million records are the context the ministry does not need to spell out. French government identity systems have had a brutal 2025–2026. This DGFiP incident is smaller than those and still large enough to power a national tax-phishing season.
Industry context: tax agencies as phishing factories
Tax authorities sit on the fields criminals actually use to sound official: income, household composition, withholding rates, company identifiers, property size. A password dump from a retailer is annoying. A tax extract is a script. “We see your RFR does not match your PAS — click to regularise before the next prélèvement” is the message that gets opened.
Credential-based access to government systems is also the 2026 pattern, not a French exception. Romania’s ANCPI land-registry disruption, claimed by bytetobreach, is a cadastral cousin: property systems, stolen access, public panic about deeds. Poland’s MyDr PESEL incident is a different sector with the same lesson — national identifiers plus context beat generic spam. The UK Department for Education contact-data theft showed that even “just emails and job titles” at a ministry scale becomes a spear-phish kit.
For DGFiP specifically, the third-party authorised account is the procurement lesson. Tax administrations cannot run cadastre and withholding without contractors and software vendors. Every extra identity that can see RFR is an extra infostealer target. Boards that treat “the agent laptop is hardened” as sufficient while a vendor VPN still holds a privileged token are reading this incident wrong.
Was I affected?
There is no public “search your numéro fiscal” portal. The ministry said DGFiP will write to each person and professional concerned. That letter — or a matching email from a domain you can verify on economie.gouv.fr — is the document that defines scope.
Do not use a Google result titled “DGFiP breach checker.” Do not upload your avis d’impôt to a third-party site that appeared this week. If you want to see what the tax administration already shows you, log into impots.gouv.fr yourself by typing the address, not by following a link in SMS.
If a week passes after the promised contact window and you heard nothing, you are probably outside the 678,000. Stay sceptical of scare posts claiming “all French taxpayers.”
What you should do after the DGFiP breach
- Read the official letter or email when it arrives. Keep it. It should list which of your fields were consulted or extracted.
- Ignore tax urgency by SMS, WhatsApp, or phone that asks you to “confirm your RFR,” pay a regularisation, or install a “CNIL secure viewer.” Hang up. Call DGFiP using a number from a prior avis, not from the message.
- Do not change your impots.gouv.fr password solely because of this incident unless the official notice says to, or you reused that password elsewhere, or you see a login you do not recognise. The ministry says identifiers and passwords were not taken here.
- Enable or confirm whatever second-factor option your espace particulier already offers. Credential stuffing from other leaks is a separate problem this headline will amplify.
- Companies: brief AP and payroll that SIREN plus raison sociale may be in the extract. Dual-control vendor bank changes this month.
- Property transactions: verify any cadastre or notaire message out of band. Deed fraud loves a fresh address-and-surface file.
- Watch for fake “prélèvement à la source” rate changes. Real PAS changes appear in your official espace, not in a PDF attached to Gmail.
- Staff and contractors at DGFiP vendors: rotate privileged tokens; assume spear-phish that cites this breach.
- If you did not get a notice: still treat DGFiP-branded fear as hostile. The 678,000 is not a cap on phishing volume.
Phishing patterns to expect
Expect French-language lures that quote:
- A plausible RFR range or “your withholding rate is wrong”
- A SIREN and a company name for professional inboxes
- A cadastral commune and surface for sellers
- CNIL notification language and a deadline
- ANSSI “mandatory patch” attachments
Voice calls will follow. A caller who knows your family quotient is not automatically DGFiP. That is what this extract buys. Ask for a written notice in your espace, then log in yourself.
How this compares to other August 2026 disclosures
Same week, SafePal confirmed an order-tracking plugin flaw affecting 39,798 hardware-wallet buyers — contact and shipping data, not seeds. Bits of Gold in Israel said a third-party analytics breach hit about 200,000 customers’ names, national IDs, and bank details, not funds. Those are commercial crypto incidents. DGFiP is a sovereign tax file. The phishing grammar is similar (real fields, fake urgency). The institutional trust is higher, which makes the lure worse.
Relative to France’s own 2026 government-adjacent incidents, 678,000 sits below France Travail and FICOBA and above a routine prefecture leak. It is large enough to rank for searches on “DGFiP data breach 2026” and “French tax authority data breach.” That is why this catalog row now carries the ministry census instead of the earlier ~600,000 press shorthand.
Canonical record and sources
Canonical BreachHistory page: 2026 DGFiP — ministry confirms 678,000 individuals and professionals.
Related context: Santé publique France claim, Cegedim Santé, ANCPI Romania, MyDr Poland.
Sources: Economy Ministry communiqué n°953, BleepingComputer, SecurityWeek, The Record.
Updated 17 August 2026 to the ministry’s 678,000 census (press often says 680,000). Earlier indexing used a confirmation-without-census, then a ~600,000 actor/press figure.
Reading the ministry text carefully
Two sentences in the communiqué get skipped in social posts. First: the initial access checks did not detect theft. That is an admission that logging was not good enough against this operator, not a claim that nothing left. Second: investigations continue on the exact number of usagers. 678,000 is the figure they are willing to print now. It can move.
A third sentence is the one victims need: individual information by email or letter, specifying which data may have been consulted or extracted and which precautions to take. If a message demands immediate payment or a new password before that letter exists, it is not that message.
For employers and accountants
Payroll bureaux that file for clients should assume some client SIRENs are in the professional slice. Do not blast every client with a panic mail that teaches attackers your template. Do tell AP staff that “DGFiP called about your PAS” is a live script. Dual control on any bank-detail change that arrives by email this month is cheap insurance.
Accountants who hold mandates on impots.gouv.fr should confirm their own privileged accounts still use unique passwords and a hardware key or app-based second factor. The confirmed intrusion used legitimate-looking identities. Mandate holders are the next logical impersonation target.
For journalists and researchers
Do not flatten 678,000 into “France’s tax database leaked.” Do not merge ZeroBytes’ 2 million / 20 million SPDC story into the ministry census without labelling it. Do not imply passwords were stolen when Bercy says they were not. Precision is how people recognise the real letter when it arrives.
If a dump appears on a forum, fingerprint it against the field list in the communiqué (RFR, quotient familial, PAS, SIREN, cadastral address/surface) rather than against a fantasy of full avis d’impôt PDFs. Overstating the file helps nobody except the next phishing kit.
FAQ for people searching the DGFiP data breach
Is it 680,000 or 678,000? The ministry printed 678,000. English headlines often say 680,000. Same incident.
Were passwords stolen? DGFiP says no — neither particular nor professional identifiers and passwords.
Do I need to freeze credit? France does not run a US-style credit freeze. Watch for credit applications you did not start, and treat tax-regularisation calls as hostile until you verify in your official espace.
Is this the same as France Travail or FICOBA? No. Different agencies, different years, different counts. Mixing them is how phishing emails steal a second click.
Should I stop using impots.gouv.fr? No. Type the address yourself. The administration still has to collect tax. The risk is impersonation, not the login page existing.