← Blog

DGFiP Cadastre Breach: 1.8M Property Accounts

Share on X

France’s tax authority DGFiP now says a second summer incident hit its professional cadastre server (SPDC): about 1.8 million accounts tied to cadastral property files were compromised — on top of the earlier confirmed 678,000 tax records from June–July credential theft. Canonical: dgfip-spdc-cadastre2026. Prior row: 678k fiscal breach. Reporting: Cyberattaque.org.

This is not a duplicate of the August communiqué about reference tax income and SIREN fields. Bercy is describing a separate compromise path against the Serveur Professionnel de Données Cadastrales that actor ZeroBytes marketed on 13 August as 252,149 lines and ~2.04 million titulaires. The ministry’s revised census — 1.8 million accounts — lands close to the actor’s order of magnitude while using “accounts” rather than “people,” because one owner can appear on multiple parcels.

Three DGFiP incidents in one summer

Do not merge these rows when you search “DGFiP data breach 2026”:

  • June–July fiscal access — stolen agent/third-party credentials; 678,000 individuals/professionals; RFR, withholding rates, SIREN, some cadastral surfaces (confirmed 14 August).
  • 29 July SPDC cadastre — professional cadastre server; now 1.8 million accounts per DGFiP investigations (Cyberattaque.org summary, August 2026).
  • Successions vacantes portal — separate vulnerability; theft acknowledged, volume still unknown (dgfip-successions-vacantes2026).

Crossing tax, property, and estate data makes French citizens attractive targets for scams that sound like official cadastre or notaire mail — even when the incidents involve different actors and entry paths.

What cadastral data means in practice

Cyberattaque.org’s sample analysis of the ZeroBytes SPDC claim included names, birth dates and places, addresses, parcel identifiers, and co-owners on properties. That is enough to craft “your parcel 000 AB 123 needs a signature” lures without guessing. It is also enough for targeted harassment if combined with other leaks.

DGFiP has reiterated that user portal passwords were not taken in the earlier fiscal incident; treat cadastre exposure as a separate data class until the ministry publishes a unified field list for SPDC.

Who is at risk

Property owners and professionals who use SPDC — notaires, surveyors, local officials, and anyone whose cadastral identity sits in professional workflows. If you own French real estate and interact with cadastre services through a professional, assume your parcel metadata may be in criminal datasets until notified otherwise.

Action items

  1. Bookmark impots.gouv.fr and ignore cadastre links in unsolicited email/SMS.
  2. Do not pay “cadastre regularization fees” from messages citing exact parcel trivia.
  3. Notaires and agents: verify identity before sending wire instructions — BEC crews love property context.
  4. Wait for official DGFiP/CNIL letters rather than forum “check if you were in the 1.8M” bots.
  5. If you were in the 678k fiscal notice, you may still need a separate cadastre assessment — the incidents differ.

Canonical record and sources

Catalog: dgfip-spdc-cadastre2026 — recordsAffected 1800000 (DGFiP account census); companyConfirmed true. Related: 678k fiscal breach, 678k blog.

Search coverage: DGFiP data breach 2026, French cadastre hack, SPDC leak, ZeroBytes DGFiP, impots.gouv.fr breach, property records exposed France, was I affected DGFiP cadastre.

Phishing after a named breach usually arrives before any polished FAQ. Attackers need a headline and a few accurate fields, not your regulator’s timeline.

Property and tax data together enable scams that cite your exact parcel reference — verify every “impots.gouv.fr” link against a bookmark you set before the headline.

Food-aid beneficiaries face stigma as well as fraud; treat any message exposing your aid status as hostile even if the sender knows your address.

Journalists should separate confirmed ministry sentences from actor table counts in every headline. Collapsing them produces false precision.

Secondary scams include fake “leak lookup” bots, fake regulator complaint portals, and monitoring signups that harvest more data than they protect.

If you forward breach news in work Slack, forward the official domain and the BreachHistory canonical link — not a forum sales screenshot.

Support agents and volunteers become social-engineering targets when organizational context leaks. Brief them early.

International staff of French agencies should not assume “France only.” Personalized lures travel with the email address.

Call-center staff should use out-of-band verification when a caller recites recent trivia. Accuracy is not authentication.

Expect copycat leak posts that paste the same victim name with inflated numbers. Check dates and primary URLs.

Legal teams drafting notices should wait for inventory rather than marketing every actor CSV as gospel.

Open bookmarks to official portals now so you are not searching under panic later.

When samples appear in trade press, demand schema description without republishing identifiable rows.

Partners reading this as a peer incident should tabletop: Sunday discovery, same-day holding statement, and customer SMS without payment links.

The practical closing line: confirm via official channels, rotate reused passwords, and treat hyper-accurate outreach as hostile.

BreachHistory updates rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture.

Merchants whose customers appear in a loyalty or support-platform dump still own the customer relationship — and the phishing blowback.

Rotate API keys and webhook secrets whenever a vendor chat or analytics stack is named in a leak claim, even before confirmation.

Phishing after a named breach usually arrives before any polished FAQ. Attackers need a headline and a few accurate fields, not your regulator’s timeline.

Property and tax data together enable scams that cite your exact parcel reference — verify every “impots.gouv.fr” link against a bookmark you set before the headline.

Food-aid beneficiaries face stigma as well as fraud; treat any message exposing your aid status as hostile even if the sender knows your address.

Journalists should separate confirmed ministry sentences from actor table counts in every headline. Collapsing them produces false precision.

Secondary scams include fake “leak lookup” bots, fake regulator complaint portals, and monitoring signups that harvest more data than they protect.

If you forward breach news in work Slack, forward the official domain and the BreachHistory canonical link — not a forum sales screenshot.

Support agents and volunteers become social-engineering targets when organizational context leaks. Brief them early.

International staff of French agencies should not assume “France only.” Personalized lures travel with the email address.

Call-center staff should use out-of-band verification when a caller recites recent trivia. Accuracy is not authentication.

Expect copycat leak posts that paste the same victim name with inflated numbers. Check dates and primary URLs.

Legal teams drafting notices should wait for inventory rather than marketing every actor CSV as gospel.

Open bookmarks to official portals now so you are not searching under panic later.

When samples appear in trade press, demand schema description without republishing identifiable rows.

Partners reading this as a peer incident should tabletop: Sunday discovery, same-day holding statement, and customer SMS without payment links.

The practical closing line: confirm via official channels, rotate reused passwords, and treat hyper-accurate outreach as hostile.

BreachHistory updates rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture.

Merchants whose customers appear in a loyalty or support-platform dump still own the customer relationship — and the phishing blowback.

Rotate API keys and webhook secrets whenever a vendor chat or analytics stack is named in a leak claim, even before confirmation.

Phishing after a named breach usually arrives before any polished FAQ. Attackers need a headline and a few accurate fields, not your regulator’s timeline.

Property and tax data together enable scams that cite your exact parcel reference — verify every “impots.gouv.fr” link against a bookmark you set before the headline.

Food-aid beneficiaries face stigma as well as fraud; treat any message exposing your aid status as hostile even if the sender knows your address.

Journalists should separate confirmed ministry sentences from actor table counts in every headline. Collapsing them produces false precision.

Secondary scams include fake “leak lookup” bots, fake regulator complaint portals, and monitoring signups that harvest more data than they protect.

If you forward breach news in work Slack, forward the official domain and the BreachHistory canonical link — not a forum sales screenshot.

Support agents and volunteers become social-engineering targets when organizational context leaks. Brief them early.

International staff of French agencies should not assume “France only.” Personalized lures travel with the email address.

Call-center staff should use out-of-band verification when a caller recites recent trivia. Accuracy is not authentication.

Expect copycat leak posts that paste the same victim name with inflated numbers. Check dates and primary URLs.

Legal teams drafting notices should wait for inventory rather than marketing every actor CSV as gospel.

Open bookmarks to official portals now so you are not searching under panic later.

When samples appear in trade press, demand schema description without republishing identifiable rows.

Partners reading this as a peer incident should tabletop: Sunday discovery, same-day holding statement, and customer SMS without payment links.

The practical closing line: confirm via official channels, rotate reused passwords, and treat hyper-accurate outreach as hostile.

BreachHistory updates rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture.

Merchants whose customers appear in a loyalty or support-platform dump still own the customer relationship — and the phishing blowback.

Rotate API keys and webhook secrets whenever a vendor chat or analytics stack is named in a leak claim, even before confirmation.

Phishing after a named breach usually arrives before any polished FAQ. Attackers need a headline and a few accurate fields, not your regulator’s timeline.

Property and tax data together enable scams that cite your exact parcel reference — verify every “impots.gouv.fr” link against a bookmark you set before the headline.

Food-aid beneficiaries face stigma as well as fraud; treat any message exposing your aid status as hostile even if the sender knows your address.

Journalists should separate confirmed ministry sentences from actor table counts in every headline. Collapsing them produces false precision.

Secondary scams include fake “leak lookup” bots, fake regulator complaint portals, and monitoring signups that harvest more data than they protect.

If you forward breach news in work Slack, forward the official domain and the BreachHistory canonical link — not a forum sales screenshot.

Support agents and volunteers become social-engineering targets when organizational context leaks. Brief them early.

International staff of French agencies should not assume “France only.” Personalized lures travel with the email address.

Call-center staff should use out-of-band verification when a caller recites recent trivia. Accuracy is not authentication.

Expect copycat leak posts that paste the same victim name with inflated numbers. Check dates and primary URLs.

Legal teams drafting notices should wait for inventory rather than marketing every actor CSV as gospel.

Open bookmarks to official portals now so you are not searching under panic later.

When samples appear in trade press, demand schema description without republishing identifiable rows.

Partners reading this as a peer incident should tabletop: Sunday discovery, same-day holding statement, and customer SMS without payment links.

The practical closing line: confirm via official channels, rotate reused passwords, and treat hyper-accurate outreach as hostile.

BreachHistory updates rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture.

Merchants whose customers appear in a loyalty or support-platform dump still own the customer relationship — and the phishing blowback.

Rotate API keys and webhook secrets whenever a vendor chat or analytics stack is named in a leak claim, even before confirmation.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.

BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.