France’s Tax Authority Hack: Data Breach Confirmed by Finance Ministry

Written by: Adel Khelifi on August 16, 2026

The French tax administration, the General Directorate of Public Finances (DGFiP), has confirmed that it was the victim of unauthorized access to its information system. In a statement published on August 13, 2026, it said that this access, which occurred in late June 2026 following identity theft, allowed the viewing and extraction of data relating to individuals and professionals. The Paris prosecutor’s office opened an investigation.

According to the statement from Bercy, the intrusion dates to the end of June and was made possible by the hijacking of an identity that allowed access to the system. The access was cut off at the end of June during an inspection, but it had already been used to view and extract data.

The administration states that investigations are ongoing to determine the exact number of affected users and has not yet released any official figures. It announces that those affected will receive individualized information detailing the data that may have been viewed and the precautions to take.

What is Claimed

The case came to public attention on August 12, when a malicious actor presenting themselves under the pseudonym ZeroBytes claimed the attack. They claim to have extracted 678,438 lines of data, presented as only a portion of the information accessible.

The breach-tracking site French Breaches mentions a file concerning more than 678,000 people, including about 392,900 individuals and 285,600 professionals.

The exposed data would include first and last names, dates of birth, addresses, family status, as well as tax-related details such as declared income, the withholding tax rate, and the number of dependents.

The same actor also claims a second intrusion, occurring less than 48 hours after the first, targeting a cadastral API interface of the tax administration.

A Second Incident in Six Months

This breach is not isolated. In February 2026, the DGFiP had already acknowledged unauthorized access to the national bank accounts file (FICOBA), obtained after the impersonation of a civil servant’s credentials, affecting about 1.2 million accounts.

The common thread between the two cases is striking and instructive: in both cases, the breach did not originate from an external software vulnerability exploited from outside, but from the hijacking of a perfectly legitimate access. It is identity and access management, and the detection of abnormal usage, that are at issue, more than the firewall.

A Lesson That Transcends French Borders

Beyond the French case, this episode illustrates a reality also experienced by Tunisian administrations and companies: the most serious intrusions do not always come via sophisticated technical attacks, but through the compromise of an authorized account. Once the identity of an official is usurped, the attacker moves through the system with the rights of a legitimate user, making detection considerably harder.

For any organization that centralizes sensitive data, the question raised by the six-month repetition of this scenario is about segmenting access, limiting rights to the strict minimum, and monitoring unusual behaviors, such as mass viewing of records.

In the short term, the main risk for those affected is phishing. Authentic personal and tax data would make emails, text messages, or calls pretending to be from the tax administration particularly credible. Vigilance against any solicitation claiming to come from the tax authorities is therefore essential, regardless of the final scale of the leak.

What remains is to know the official tally: as long as the DGFiP has not completed its investigations and notified the users, the real number of taxpayers affected and the precise nature of the data extracted remain to be determined.




Adel Khelifi

Adel Khelifi

My name is Adel Khelifi, and I’m a journalist based in Tunis with a passion for telling local stories to a global audience. I cover current affairs, culture, and social issues with a focus on clarity and context. I believe journalism should connect people, not just inform them.