French tax authorities confirmed a cyberattack in late June that breached the Directorate General of Public Finances (DGFiP) systems, exposing personal and business taxpayer data for between 678,000 and nearly 700,000 individuals and companies [1, 2, 3]. The hackers gained unauthorized access through a compromised internal VPN, targeting DGFiP’s computer systems [1, 4].
The stolen information includes taxpayer names, reference income, withholding tax rates, family quotient, tax residence details, and business registration numbers. French authorities emphasized that the breach does not allow access to taxpayers’ secure online accounts and does not include usernames or passwords [2, 4, 3]. Amelie Verdier, DGFiP’s director general of public finances, stated, "The compromised personal data includes names, family quotient information, reference tax income and withholding tax rates" [3]. The tax authority added, "The stolen information does not allow access to the secure account on impots.gouv.fr" [3].
The breach was part of multiple cyberattacks against French government databases. In July, another hack targeted about 200,000 land registry accounts. The hacker group Zerobytes claimed responsibility, stating they hold data on 250,000 land registry accounts linked to some 2 million property owners [2].
Discrepancies in reports include the total number of affected taxpayers and the full scope of exposed data. While some sources specify roughly 678,000 individuals affected, others suggest the incident may involve millions [1, 2, 4, 3]. Scope disagreements include whether additional contact information such as postal addresses and emails were exposed [4] or if the theft was limited mostly to tax income details and withholding rates [3].
French judicial authorities have responded by opening investigations into the cyberattacks. On August 15, the Paris prosecutor’s office officially launched a probe with support from the Anti-Cybercrime Office [3]. Prior to this, the French Finance Ministry publicly confirmed the data breach on August 13 [1, 4].
Authorities continue to assess the full impact of the breaches. Security measures have been intensified following the attacks, while the investigation aims to identify perpetrators and prevent further incursions.
The inquiry by the Paris prosecutor’s office is ongoing, focusing on tracking down those responsible for the June and July attacks and mitigating any additional risks to taxpayers’ personal and financial information [3].