France Tax Hack: 678,000 Taxpayers’ Data Stolen

📑 Table of Contents
Hackers breached France’s national tax administration, exposing the personal data of 678,000 taxpayers — both private individuals and businesses — in what officials called the most sophisticated attack on the authority to date. The Paris Public Prosecutor’s cybercrime unit has opened an investigation.
The breach, disclosed late Thursday and confirmed Friday, is the latest in a string of cyberattacks on French public institutions this year. It renews questions about how well governments protect the massive troves of personal and financial data they hold on citizens.
What happened
The attack targeted the Directorate-General for Public Finances (DGFiP), the agency responsible for France’s tax system. Hackers extracted data from a state-operated personal information system in an attack tax officials described as “more complex than cyberattacks they had faced in the past.”
The breach affected 678,000 users of the French tax system. Prosecutors said the inquiry covers fraudulent data extraction as well as suspected participation in a criminal conspiracy aimed at preparing an offence punishable by at least five years in prison — a sign investigators believe the attack was organized and premeditated.
Public Accounts Minister David Amiel asked the DGFiP to begin informing affected taxpayers as early as Monday, August 17, and to propose how security procedures should be strengthened.
What was stolen
For individual taxpayers, the information obtained included full names, family quotient details, reference taxable income, and withholding tax rates, according to Amélie Verdier, Director-General of Public Finances.
That data is sensitive in combination. Income figures, tax rates, and family circumstances are exactly the details fraudsters use to make phishing emails, text messages, and phone calls appear convincing. The ministry explicitly warned that the stolen information could be exploited to make fraudulent messages appear more authentic.
For businesses, the exposure was considered less sensitive. Officials said it included a company’s SIREN registration number, its business address, and the address of its authorized representative.
What’s safe
The DGFiP stressed that the stolen data does not provide access to taxpayers’ secure accounts on the impots.gouv.fr website. There is no evidence the attackers obtained login credentials, passwords, or banking information.
Tax officials sought to reassure users about the integrity of the impots.gouv.fr platform. The breach involved an internal information system — not the public-facing portal where taxpayers log in.
The investigation
The cybercrime unit of the Paris Public Prosecutor’s Office is leading the inquiry, entrusted to Ofac, France’s Office for the Fight against Cybercrime. Investigators are working to establish how attackers gained access, who was responsible, and whether the stolen data has been shared or sold.
The breach follows a series of recent cyberattacks on French public bodies, including systems linked to the National Agency for Secure Documents (ANTS), the national statistics agency INSEE, and an incident that took down online postal services.
The incident is part of a broader pattern in France, where public administrations and databases holding large volumes of personal information have become frequent targets. Each successful breach raises the same uncomfortable question: whether state-held data — tax records, identity documents, health information — is being protected with the same urgency as the private sector’s crown jewels.
What affected taxpayers should do
French authorities said affected people would be contacted from early this week. The immediate priority is warning them about the risk of identity theft and fraudulent attempts to obtain further personal information.
Officials urged anyone contacted in connection with the breach to be cautious about requests for passwords, banking details, or other sensitive information — a hallmark of follow-up phishing attacks. The core advice: the government will never ask for your password by email, text, or phone.
Bottom line
The French tax breach is a reminder that government databases are increasingly attractive targets. While no login credentials appear to have been stolen, the combination of income, tax, and family data is enough to fuel convincing fraud. Affected taxpayers should expect contact from the DGFiP and remain wary of any unsolicited request for sensitive information in the coming weeks.