News Briefing

French Tax Authority Confirms Two Data Thefts, 678,000 Income Records Exposed

Aug 17, 2026News Briefingwww.imidaily.com

France’s tax administration confirmed two separate cyber‑intrusions that exposed personal and business tax data. The first breach at the end of June compromised up to 678 000 records, while a second breach at the end of July added roughly 200 000 land‑registry accounts.

Scope of the June breach

  • Records affected: at least 678 000 rows extracted from an internal VPN‑protected search tool.
  • Data included:
    • Individuals – name, family quotient, revenu fiscal de référence (reference income), and withholding‑tax rate.
    • Businesses – SIREN numbers and public company addresses.
  • Breakdown (FrenchBreaches analysis): 392 867 individuals and 285 570 businesses. Among the individuals, 26 805 reported a reference income ≥ €100 000, 386 ≥ €1 million, and eight ≥ €10 million.
  • Tax relevance: the revenu fiscal de référence determines eligibility for the contribution différentielle sur les hauts revenus, a supplemental household tax that can reach 20 % for single filers above €250 000 (or €500 000 for couples).

Scope of the July breach

  • System targeted: Serveur professionnel de données cadastrales (SPDC), the land‑registry lookup database.
  • Records claimed: 252 149 rows, which the intruder estimated correspond to 2 041 778 individuals (multiple rights holders per parcel).
  • Official count: DGFiP investigators cite about 200 000 affected accounts, with analysis ongoing.
  • Data type: cadastral parcel information linking owners to specific land parcels; considered less sensitive than tax data but still personal.

Method of intrusion

  • The hacker, using the handle ZeroBytes, obtained VPN credentials for the tax officials’ internal network, allowing automated extraction of the June file.
  • For the July attack, he reportedly bypassed multi‑factor authentication on the SPDC system before abandoning a full download, citing the time required.

Timeline and disclosure

Date Event
Late June 2024 Intrusion detected; connection cut by auditors.
13 August 2024 Ministry announced the June breach had been stopped.
12 August 2024 Public disclosure after union criticism of delayed communication.
29 July 2024 Second intrusion on the cadastral system.
13 August 2024 CNIL (data‑protection authority) notified (within GDPR’s 72‑hour window).
Early September 2024 DGFiP to send affected individuals a breakdown of accessed data and recommended precautions.

Earlier data‑security incidents in 2024‑2025

  • February 2024: Unauthorized access to FICOBA, the national bank‑account register, affecting at least 1.2 million accounts.
  • April 2024: Hack of the Agence nationale des titres sécurisés (ANTS), exposing roughly 11.7 million identity‑document applications.
  • 2025‑2026: Legislative measures introduced to allow company directors to hide home addresses from public corporate records and to extend security support for at-risk individuals.

Risks for affected persons

  • Phishing: Combined name, address, income, and tax‑withholding data enable highly credible fraudulent messages.
  • Identity theft: Exposure of bank‑account registers and cadastral ownership links can facilitate impersonation or targeted scams.
  • Physical security: For high‑net‑worth individuals, linking income levels to specific property parcels may increase personal safety concerns.

Practical advice for those potentially impacted

  • Monitor communications from DGFiP for detailed information on what was accessed.
  • Treat any unsolicited messages referencing tax or property matters with heightened suspicion; verify through official channels before responding.
  • Consider additional identity‑theft protection services, especially for high‑income or high‑net‑worth individuals.
  • Evaluate personal security measures if cadastral data links you to valuable property.

The breaches underscore ongoing vulnerabilities in French public‑sector IT systems, despite recent regulatory steps to tighten data protection and cybersecurity.