DGFiP Data Breach 2026: 5 Things You Need to Know
Table des matières
France’s tax authority confirmed on August 14 that an attacker was inside its systems for weeks before anyone noticed. The entry point was not a zero-day. It was a stolen credential.
What happened at the DGFiP?
Between June and July 2026, an attacker operating under the alias ZeroBytes accessed the DGFiP’s internal systems by impersonating the credentials of a DGFiP agent and an authorized third-party partner. The access went undetected. The DGFiP only identified the breach after ZeroBytes listed the database for sale on PwnForums on August 12 and ANSSI alerted Bercy the same day.
The DGFiP confirmed on August 14 that 678,438 individuals and professionals had data consulted and extracted. The stolen records include reference tax income, withholding tax rates, home addresses, property sizes, and SIREN numbers for businesses. Online taxpayer accounts and login credentials were not compromised.
A second intrusion on July 29 targeted the cadastral server SPDC. ZeroBytes claims to have accessed records covering over 2 million property owners, though the DGFiP has not independently confirmed that figure. A third incident involving a public portal was announced on August 18. The Paris prosecutor opened a criminal investigation. France’s data protection authority, the CNIL, has been notified.
A threat actor profile: Who is ZeroBytes?
ZeroBytes is a financially motivated French-speaking threat actor who first surfaced in criminal forums in early 2026. Prior confirmed targets include Intermarché Drive and EVA GG, a French gaming platform. The DGFiP intrusion is the most significant in their documented history.
The actor told FrenchBreaches directly: “Money is the main motivation, plus a desire for power.” ZeroBytes published a breakdown of the DGFiP dataset, unverified by the authority, identifying 386 individuals with declared incomes above €1 million and 8 above €10 million. According to CertiK data cited by Cryptopolitan, France recorded 33 of the 52 verified physical attacks targeting high-net-worth individuals in Europe in H1 2026. A dataset that maps declared wealth to a home address is a materially different risk than a standard credential dump.
The access method across every DGFiP intrusion was the same: VPN credentials belonging to a legitimate user, used to reach internal tools with no anomaly detection on authorized accounts behaving unusually. ZeroBytes did not exploit a software vulnerability. The actor found a door that was already open.
The breach extends beyond the DGFiP
On August 17, ZeroBytes claimed a second target: the Éducation nationale. The ministry confirmed an intrusion into a staff training system dating to July 25-26. ZeroBytes claims 43GB across 346 million raw lines covering twenty years of records, including 1.22 million deduplicated student identifiers and 4.35 million staff records via the I-Prof personnel management system. The ministry has not confirmed the full scope of those figures.
Separately, a different actor group claimed a breach of Santé publique France on August 11, with approximately 80,000 healthcare and social sector contacts confirmed by the agency. France VAE, the government vocational certification portal, also reported a security incident in the same week.
The minister acknowledged that the DGFiP alone faced 6,972 cyberattacks in 2025 and cited decades of accumulated technical debt. The response plan announced August 19 includes mandatory double authentication for all DGFiP agents, a full review of external partner access, early warning detection systems, and a bug bounty program.
What this means for organizations working with French state data
The access ZeroBytes exploited was legitimate third-party access. The minister explicitly called out the need to review “all access to data, including that passing through external partners.” Any service provider, technology vendor, or data processor that holds authorized credentials to French state infrastructure is now part of an active criminal investigation and a likely CNIL enforcement review.
The data is already in criminal markets. The gap between credential compromise and public disclosure was six weeks. The gap between public disclosure and criminal market availability was hours. CybelAngel monitors dark web forums and criminal marketplaces for data connected to French state institutions and their partner ecosystems. If your organization’s data passed through any of the affected systems, the question is not whether it will appear. It is whether you will find out before someone acts on it.
This marks the initial phase of our investigation. We are monitoring the situation closely as the CNIL review, criminal investigation, and ZeroBytes’ criminal forum activity develop.
CybelAngel works with organizations across the French public and private sectors to monitor credential exposure and dark web activity before it reaches this point. The DGFiP breach was detected six weeks after the first intrusion. Organizations working with CybelAngel would have seen the credential exposure in real time.
FAQ
No. The DGFiP confirmed the method explicitly: credential usurpation, not a software vulnerability. ZeroBytes logged into an internal VPN tool using stolen identifiers and extracted data over weeks. Initial access controls did not flag the data leaving. The sophistication was not technical. It was patience, and the absence of anomaly detection on authorized accounts behaving unusually.
No. The DGFiP was explicit: user login credentials and passwords were not exposed, and online taxpayer accounts were not compromised. What was exposed is more durable: tax income figures, withholding rates, home addresses, and property data. None of that can be changed. It will remain accurate for years.
Audit every credential that grants access to French government systems immediately. The minister called out the need to review “all access to data, including that passing through external partners.” Service providers, technology vendors, and data processors holding authorized access to French state infrastructure should treat their credential posture as part of an active criminal investigation and a likely CNIL enforcement review.
Yes. ZeroBytes listed the DGFiP database for sale on August 12, the same day ANSSI alerted Bercy. The gap between credential compromise and public disclosure was roughly six weeks. The gap between public disclosure and criminal market availability was hours. CybelAngel monitors dark web forums and criminal marketplaces for data tied to French state institutions and their partner ecosystems in real time.
The minister announced a response plan on August 19: mandatory double authentication for all DGFiP agents, early warning detection systems, a full review of external partner access, mandatory cyber training, and a bug bounty program. ANSSI and the Paris prosecutor are running parallel investigations. Affected individuals will be contacted directly by the DGFiP by email or post.
