French tax authority to notify 678,000 victims of major data breach
Victims of a major cyberattack on France's tax administration are expected to receive notification starting Monday, following a sophisticated breach that compromised personal data belonging to 678,000 users.
The attack on the Direction Générale des Finances Publiques (DGFiP) involved attackers impersonating credentials of a DGFiP employee and an authorized third party during intrusions in June and July 2026. The malicious actor publicly claimed responsibility on August 12 and 13, 2026.
For individuals, the stolen information includes names, dates of birth, home addresses, telephone numbers, family circumstances, reference taxable income and withholding tax rates. The withholding tax system, known as prélèvement à la source, has been in effect since January 1, 2019, with employers deducting income tax directly from monthly salaries based on rates provided by the tax authority.
The breach also affected businesses, though the compromised data is considered less sensitive. Information taken includes SIREN registration numbers, business addresses and the addresses of authorized representatives. A separate intrusion in June reportedly exposed around 200,000 accounts containing cadastral information related to property and land ownership.
Sophisticated attack evaded initial detection
Initial access controls failed to detect that data had been stolen due to the sophistication of the attack. The Finance Ministry stated the theft was not detected at the initial stage when suspicious access was identified. Further investigations later established that data had been consulted and extracted before access was removed.
France's National Cybersecurity Agency (ANSSI) is conducting investigations alongside the ministry's security service. The incident was reported to the data protection authority CNIL, in compliance with GDPR requirements that mandate notification within 72 hours of becoming aware of a personal data breach when it poses a risk to individuals' rights and freedoms.
Part of unprecedented wave targeting France
The DGFiP breach is part of an alarming escalation in cyberattacks targeting France. The country experienced 58 ransomware incidents in the first months of 2026, representing a 29% increase compared to the same period in 2025, making it the fifth-most-targeted country globally for cyberattacks.
Cyberattacks targeting France surged from baseline levels of 400,000-500,000 monthly events in May-August 2025 to over 1.3 million attacks in February 2026, representing approximately a threefold increase. The CNIL logged 6,167 personal data breach notifications in 2025, a 20% increase compared to 2023, with France becoming the most heavily breached large jurisdiction in Europe by volume of exposed records.
Recent high-profile incidents include the ANTS data breach in April 2026, which exposed 11.7 million user accounts, making it one of the largest public sector data leaks in French history. A 15-year-old suspect was arrested on April 25, 2026 in connection with that breach. INSEE confirmed on June 26, 2026 that a cyberattack exposed personal data of approximately 12,800 current and former staff members, with the intrusion detected on June 19, 2026.
Government response and security warnings
Public Accounts Minister David Amiel has requested the DGFiP to begin informing affected users from Monday August 17. He has also asked for proposals on strengthening security procedures and identifying lessons from what officials describe as an unprecedented attack on the tax administration.
DGFiP director-general Amélie Verdier apologized to taxpayers and urged those affected to exercise particular caution. The stolen information could enable criminals to make phishing emails, text messages or telephone calls appear more credible by referencing specific details such as a person's tax situation.
While the DGFiP confirms the stolen information cannot be used to access secure taxpayer accounts on the impots.gouv.fr website, authorities warn the personal details could facilitate convincing identity theft attempts.
How to protect yourself
The DGFiP emphasized that its services never request bank details, personal information or identification data by email or telephone. Genuine emails from the tax administration use addresses ending in @dgfip.finances.gouv.fr, and taxpayers should be wary of links to websites that do not end in .gouv.fr.
Even when a telephone number appears genuine, taxpayers should not provide personal or banking information. Fraudsters can use spoofing techniques to make calls appear to come from legitimate numbers.
The DGFiP specifically warned about phishing attempts at a time when taxpayers may be expecting tax refunds or other communications from the administration.
The Paris public prosecutor has opened an investigation to establish how the attackers entered the tax administration's systems, identify those responsible and determine whether the stolen information has subsequently been used or shared.

