France Tax Authority Breach Exposes Nearly 700,000 People

Tax secrecy has become a cybersecurity battlefield.

Paris, August 2026

France is preparing to notify nearly 700,000 taxpayers and businesses after hackers penetrated systems operated by the General Directorate of Public Finances. The breach exposed highly detailed fiscal and personal information, creating risks that extend far beyond conventional identity theft. French authorities detected the incident after stolen records appeared for sale on a cybercriminal forum in August. The intrusion itself is believed to have occurred in June through compromised access to an internal platform.

The exposed files reportedly contain names, residential addresses, telephone numbers, taxable income, tax rates and the number of dependants registered within individual households. Some records also identify the local tax office and public employee responsible for handling each case. This combination allows criminals to construct convincing profiles of potential victims and tailor fraudulent communications with information that appears authentic. Wealthier households may face additional risks from targeted extortion, impersonation or burglary attempts.

A hacker initially claimed access to information involving tens of millions of people, although that figure appears to describe the broader population contained within the system rather than the number of detailed records extracted. Investigators have identified a dataset containing more than 600,000 entries, while the number of people and organisations expected to receive official notifications approaches 700,000. The precise scale remains under examination as forensic teams assess whether other systems or records were compromised. French officials have restricted access, opened an investigation and prepared notifications to the national data protection authority.

The incident follows an earlier breach involving France’s national database of bank accounts, where information connected to approximately 1.2 million accounts was accessed unlawfully. That intrusion involved stolen credentials belonging to an authorised public employee and exposed names, addresses, bank details and, in some cases, tax identifiers. Repeated attacks against financial databases suggest that identity management and authorised access have become critical vulnerabilities within public administration. A secure perimeter offers limited protection when attackers can enter using credentials that systems recognise as legitimate.

Affected taxpayers should expect an increased wave of messages designed to imitate tax officials, banks or other government services. Criminals may refer to genuine income figures, addresses or previous administrative exchanges to make fraudulent requests appear credible. French authorities are expected to contact identified victims directly, but official notifications will not eliminate the danger created once data enters criminal markets. The breach therefore tests more than technical resilience: it challenges public confidence in the confidentiality at the centre of the tax system.

Phoenix24: clarity in the grey zone. / Phoenix24: claridad en la zona gris.

Related posts

Russia Expands Its Morality Campaign to Online Creators

Bruselas avala 7.900 millones más para la recuperación polaca

Polonia envía un avión especial tras el accidente en Hungría