Fuite de données à la DGFiP en 2026 : 5 choses à savoir
Table des matières
France’s tax authority confirmed on August 13 that an attacker had been extracting data from its systems since late June. The intrusion itself was detected and cut off at the time. What went unnoticed for six weeks was that data had left. The entry point was a stolen credential.
What happened at the DGFiP?
On June 26, 2026, an attacker operating under the alias ZeroBytes accessed the DGFiP’s internal systems using the usurped credentials of a DGFiP agent and an authorized third-party partner. The connection reached an internal taxpayer lookup tool via the internal VPN.
The DGFiP did detect the suspicious connections and cut access to the affected accounts. What the access controls performed at that moment did not establish was that the intrusions had resulted in data being extracted. Bercy attributes that gap to the sophistication of the attack: the actor deliberately avoided the kind of bulk queries that trigger detection. The DGFiP dates its own awareness of the data theft to August 12, when ZeroBytes listed the database for sale on a criminal forum and an ANSSI alert reached Bercy the same day.
The ministry confirmed the illegitimate access on August 13 and published a detailed statement on August 14: approximately 678,000 individuals and professionals had data consulted and extracted. The exposed records include names and company names, email addresses, postal addresses, phone numbers, reference tax income, family quotient, withholding tax rates, property sizes, and SIREN numbers for businesses. Online taxpayer accounts, login credentials, and passwords were not compromised.
One number deserves care. ZeroBytes claimed 678,438 lines of data, and the DGFiP has confirmed that order of magnitude in terms of people and businesses affected. A line is not a person: a single taxpayer can appear across several records. Analysis relayed by FrenchBreaches breaks the set down into roughly 392,867 individuals and 285,570 professionals.
Three separate DGFiP incidents, three different methods
A second intrusion on July 29 targeted the Serveur Professionnel de Données Cadastrales (SPDC), the professional cadastral data server. Here the entry point was an authorized partner account, with multi-factor authentication bypassed. ZeroBytes claimed 252,149 extracted lines covering more than 2 million property rights holders. On August 18, the DGFiP confirmed a scope of up to 1.8 million accounts — larger than the first incident, and close to the attacker’s own order of magnitude. The two figures are not directly comparable: the administration counts accounts, the attacker counted individuals in the records, and one owner holding several parcels can appear repeatedly.
A third incident, detected on August 17 and announced on August 18, involved the vacant estates portal (portail des successions vacantes). This one relied on no stolen credential at all: a vulnerability allowed certain information to be accessed without prior authentication. The flaw was corrected and access cut the same day. The volume remains under analysis, and the DGFiP presents it as smaller in scale than the first two.
Those three modes of entry matter more than the headline totals. Usurped agent credentials on an internal tool. An authorized partner account that got around MFA. An unauthenticated public portal. This is not one door left open. It is three, of three different kinds, across a single administration in roughly seven weeks.
The Paris prosecutor opened a criminal investigation on August 15, assigned to the Office anti-cybercriminalité (OFAC), for fraudulent extraction of data and criminal conspiracy. France’s data protection authority, the CNIL, has been notified and has stated publicly that it is already seized of the matter, making individual complaints on the subject unnecessary.
A threat actor profile: Who is ZeroBytes?
ZeroBytes is a financially motivated French-speaking threat actor who first surfaced in criminal forums in early 2026. Prior claimed targets include Intermarché Drive, EVA GG (a French gaming platform), and the Fédération Française de Handball, where the actor claimed 1,367,197 member records on August 10. The DGFiP intrusion is the most significant in their documented history. Nothing at this stage points to a state-sponsored operation: the stated motive is financial, which means the data is intended to be resold.
The actor told FrenchBreaches directly: “Money is the main motivation, plus a desire for power.” ZeroBytes published a breakdown of the DGFiP dataset, unverified by the authority, identifying 26,805 individuals with a reference tax income at or above €100,000, 386 above €1 million, and 8 above €10 million. Reference tax income is calculated by the administration at household level: it is not the tax paid, nor necessarily the individual’s personal salary. According to CertiK data cited by Cryptopolitan, France recorded 33 of the 52 verified physical attacks targeting high-net-worth individuals in Europe in H1 2026. A dataset that maps declared wealth to a home address is a materially different risk than a standard credential dump.
Across the first two DGFiP intrusions, the pattern was legitimate access, misused. Valid credentials reached internal tools, and nothing flagged an authorized account behaving unusually. In both cases the actor did not exploit a software vulnerability. They logged in.
The breach extends beyond the DGFiP
The Éducation nationale acknowledged an intrusion into one of its information systems on July 31, dating the compromise to the night of July 25, 2026. The method was familiar: a compromised professional account gave access to a staff training system. The ministry cut external access, activated a crisis unit, filed a complaint, and opened investigations with ANSSI and the CNIL, without confirming the scope.
The scale only became public in mid-August, when ZeroBytes claimed the intrusion. The actor claims 43GB across roughly 2,500 files and 346,178,591 raw lines, spanning more than twenty years of records. The claimed breakdown includes 1,224,291 deduplicated student identifiers, 4.35 million staff identifiers via the I-Prof personnel management system, and around 602,000 academic account records, drawn from systems including BE1D, SCHAAF, SCONET and the Créteil and Versailles academic directories. The ministry has not confirmed those figures.
These datasets should not be treated as a single set, and there is no evidence that every French public sector incident this summer traces back to the same actor. But cross-referencing tax data, cadastral records, and education records would allow extremely precise profiles to be built — which is the risk that outlasts any single breach.
The state’s response
David Amiel, Minister for Public Action and Accounts, issued a public apology at a Bercy press conference on August 18, calling what happened unacceptable for French citizens. DGFiP Director General Amélie Verdier confirmed that none of the three incidents allowed entry into a tax account or the retrieval of a password, and cautioned that a significant number of duplicates may exist across the victim lists. Press estimates citing BFM Tech put the combined scope of the three DGFiP incidents at at least three million people, though the administration has not published a consolidated total. The minister cited decades of accumulated technical debt at the administration. Solidaires Finances Publiques, a finance ministry union, says it had raised the risk of identity usurpation and targeted phishing with senior management as early as June 2026.
Individual notification of affected taxpayers began on August 17, by email and post. The DGFiP stresses that genuine notifications come only from the @dgfip.finances.gouv.fr domain and contain no clickable links to a personal account — a detail worth passing on, because the exposed data makes convincing impersonation of the tax authority, a notary, or a land registry service considerably easier.
The DGFiP action plan was presented at that August 18 press conference, following an interministerial crisis unit convened by Prime Minister Sébastien Lecornu on August 17. It includes generalizing two-factor authentication to all DGFiP agents by the end of 2026, a review of the rights granted to external partners, reinforced internal phishing awareness campaigns, and a bug bounty program. Bercy also intends to extend access quotas limiting how much data can be consulted or downloaded from a single account — a control already applied to the FICOBA bank account registry after earlier incidents — and to rework detection so that account usurpation, atypical connections, and mass consultations of sensitive files are caught faster. The stated aim is to shorten the delay between a compromise, its identification, and corrective action. An ANSSI audit is expected in September 2026. In a letter dated August 19, the Prime Minister asked the SGDSN to create a new rapid-response unit of ANSSI staff to intervene on suspected serious compromises of state information systems, noting that few ministries are currently at the required level.
The wider state digital security plan launched on April 30, 2026 — which predates these incidents — provides €200 million for cybersecurity, raises each ministry’s cyber share of digital budget from roughly 1% to 5% from 2027, and creates a new digital authority, ARIANE, before January 1, 2027.
What this means for organizations working with French state data
In two of the three DGFiP incidents, the access abused was legitimate — and in the second, it belonged to an authorized external partner. The minister explicitly called out the need to review “all access to data, including that passing through external partners.” Any service provider, technology vendor, or data processor holding authorized credentials to French state infrastructure is now adjacent to an active criminal investigation and a likely CNIL review.
There is an asymmetry worth understanding here. Article 20 of the French Data Protection Act excludes state processing from the CNIL’s administrative fines, so the DGFiP faces no financial penalty. Private organizations face no such exemption: France Travail was fined €5 million in January 2026 over its own data breach. A private company that discovered an intrusion, took seven weeks to establish that data had left, and disclosed the day after the data appeared for sale would be preparing a defense. If your organization sits in that partner ecosystem, you inherit the exposure without inheriting the immunity.
The data is already in criminal markets, and the sequence matters: the sale listing came first, on August 12, and it is what triggered official disclosure the following day. The gap between the initial compromise and that listing was roughly six weeks — six weeks in which the exfiltration was not established, despite the intrusion having been detected. CybelAngel monitors dark web forums and marketplaces for data connected to French state institutions and their partner ecosystems. If your organization’s data passed through any of the affected systems, the question is not whether it will surface. It is whether you will find out before someone acts on it.
This marks the initial phase of our investigation. We are monitoring the situation closely as the CNIL review, the criminal investigation, the September audit, and ZeroBytes’ criminal forum activity develop.
CybelAngel works with organizations across the French public and private sectors to monitor credential exposure and dark web activity before it reaches this point. The DGFiP data theft was confirmed six weeks after the first intrusion. Organizations working with CybelAngel would have seen the credential exposure in real time.
FAQ
It depends what you mean. There was no software exploit in the first two incidents: the DGFiP confirmed the method as credential usurpation. ZeroBytes logged into an internal tool with stolen identifiers and extracted data over weeks. But the DGFiP does characterize the attack as sophisticated, and specifically more so than earlier attempts, because the actor avoided the bulk queries that are easier to detect. The sophistication was in the tradecraft, not the tooling: patience, restraint, and the absence of anomaly detection on authorized accounts behaving unusually.
No. The DGFiP was explicit: user login credentials and passwords were not exposed, and none of the three incidents allowed entry into an online tax account. What was exposed is more durable: tax income figures, family quotient, withholding rates, home addresses, and cadastral data on property. None of that can be reset. It will remain accurate for years.
The confirmed figures are approximately 678,000 individuals and professionals for the first incident and up to 1.8 million accounts for the cadastral server. Those totals cannot simply be added together. The DGFiP Director General has cautioned that a significant number of duplicates may exist across the victim lists, and the units differ: accounts, records, and people are three different things. Treat the attacker-claimed figures, including the 2 million property holders and the Éducation nationale totals, as unconfirmed.
Audit every credential that grants access to French government systems, including those held by partners and subcontractors, and check whether multi-factor authentication can be bypassed on those paths — that is how the cadastral server was reached. The minister called out the need to review “all access to data, including that passing through external partners.” Service providers, technology vendors, and data processors holding authorized access should treat their credential posture as adjacent to an active criminal investigation and a likely CNIL review, and should note that the state’s exemption from CNIL fines does not extend to them.
Yes. ZeroBytes listed the DGFiP database for sale on August 12, and an ANSSI alert reached Bercy the same day. That listing is what prompted official confirmation on August 13 — the criminal market came before the public disclosure, not after it. Roughly six weeks passed between the initial compromise and the listing. CybelAngel monitors dark web forums and marketplaces for data tied to French state institutions and their partner ecosystems.
The DGFiP action plan was presented on August 18, after an interministerial crisis unit convened by the Prime Minister on August 17. It includes generalizing two-factor authentication to all agents by the end of 2026, a review of external partner rights, extended quotas capping how much data one account can consult or download, reworked detection for atypical connections and mass file consultations, reinforced phishing awareness campaigns, and a bug bounty program. An ANSSI audit is expected in September 2026. On August 19 the Prime Minister requested a new ANSSI rapid-response unit for suspected serious compromises of state systems. ANSSI and the Paris prosecutor, via the OFAC, are running parallel investigations. Affected individuals have been contacted directly by the DGFiP since August 17, by email or post, from the @dgfip.finances.gouv.fr domain and with no clickable links.
Updated August 25, 2026. This article has been revised to reflect developments since first publication on August 21.
