France’s tax administration has confirmed a major data breach. On 13 August 2026, the Direction générale des Finances publiques (DGFiP) — the French equivalent of the IRS or HMRC — acknowledged that intruders illegitimately accessed its information system and extracted sensitive fiscal data belonging to hundreds of thousands of taxpayers. The government’s own tax portal was not compromised, but the exposed data opens the door to a wave of convincing scams.
TL;DR
- A hacker using the alias ZeroBytes claimed on 12 August to hold 678,438 lines of French tax data.
- The DGFiP confirmed the intrusion (late June 2026, via identity spoofing) but has not yet published its own victim count.
- Exposed data for individuals includes name, address, household composition, reference tax income and withholding-tax rate.
- The public portal impots.gouv.fr and personal accounts were NOT breached.
- The real danger is phishing. France’s data-protection regulator (CNIL) and Paris prosecutors are now involved.
First, the context: who is the DGFiP?
The Direction générale des Finances publiques (DGFiP) is France’s national tax authority — it assesses and collects income tax, manages taxpayer records and runs the public tax portal impots.gouv.fr. Think of it as France’s IRS (US) or HMRC (UK). Two French fiscal concepts matter here. The revenu fiscal de référence (RFR), or “reference tax income,” is an official figure summarizing a household’s total income — it effectively reveals how much you earn and is used to set eligibility for many benefits. The prélèvement à la source is France’s pay-as-you-earn system; your personal withholding-tax rate also hints at your income level. Both were among the leaked fields — which is what makes this breach unusually sensitive.
What happened
On 12 August 2026, a hacker known as ZeroBytes claimed on a cybercrime forum to have exfiltrated 678,438 lines of data from the DGFiP. The next day, the French Ministry for Public Action and Accounts confirmed an “illegitimate access” to the agency’s information system, dating back to late June 2026.
Notably, there was no software exploit or ransomware. The entry point was identity spoofing: someone impersonated an authorized user — using the credentials of an agent and/or an authorized third party — and queried an internal search tool. Access was cut off by late June during a routine control, but data had already been consulted and extracted.
What data was exposed
According to the breach-tracking platform FrenchBreaches, which reviewed samples of the files, individuals’ records include identity, date and place of birth, tax address, household situation and number of tax “parts,” plus the two sensitive figures above — reference tax income and withholding rate. Business records (company name, SIREN registration number, address) are considered less sensitive as they are often already public.
The platform counts 678,437 people across the files (392,867 individuals and 285,570 businesses). Crucially, these numbers come from the attacker’s files, not from an official tally: the DGFiP says its investigation is ongoing. A second, unconfirmed claim on 14 August concerns cadastral (land-registry) data — potentially hundreds of thousands to over two million property rights-holders, depending on the source.
Why it matters even outside France
Anyone who has filed taxes in France — including foreign residents, cross-border workers and expatriates — could theoretically be in scope. The immediate threat is not stolen money but highly targeted phishing: with your name, address and real fiscal details, scammers can craft “tax refund” or “outstanding payment” emails that look authentic. Treat any unsolicited “impôts” or “tax office” message as suspicious, never click the link, and log in only by typing the official address yourself. The DGFiP never asks for bank details by email or text.
The official response
The DGFiP has apologized and says it will contact every affected person individually — by email or letter, starting the week of 18 August 2026 — specifying which data may have been accessed and what precautions to take. It has notified France’s data-protection authority, the CNIL, filed a criminal complaint, and the Paris public prosecutor’s cybercrime unit has opened an investigation.
FAQ
Was my data leaked?
Only the DGFiP can confirm this. It will contact affected people directly from the week of 18 August 2026. The figures circulating come from the attacker’s files, not a final official count, so no one can confirm individual exposure from those numbers alone.
What’s the actual risk?
Mainly targeted phishing and identity fraud: criminals could use the exposed data to make scams convincing. No direct theft of bank funds has been reported through this incident.
What should I do?
Be wary of any unsolicited “tax office” email or text, never click embedded links, never share bank details, log in only via the official address you type yourself, and keep any official DGFiP notification you receive.
Was impots.gouv.fr compromised?
No. According to the administration, the public portal and users’ personal accounts were not breached. The intrusion targeted an internal tool via identity spoofing on the professional-access side.
By Patrick Lancier



