Sensitive tax and property information belonging to hundreds of thousands of people has been exposed in a breach of France’s tax administration.
The French Ministry of the Economy and Finance confirmed that an attacker gained unauthorized access to systems operated by the General Directorate of Public Finances (DGFiP) and extracted data concerning 678,000 individuals and professionals.
This breach came to light after a threat actor using the name “ZeroBytes” advertised stolen data for sale on the PwnForums hacking forum on Aug. 12, 2026.
An investigation by French authorities subsequently determined that compromised access points had been used to view and extract tax, business, and property information.
Financial and property records can provide attackers with personal details that may be useful for fraud and other identity-based attacks.
Key takeaways of the French Tax Authority breach
- French authorities confirmed that attackers accessed and extracted tax, business, and property data belonging to 678,000 individuals and professionals.
- Taxpayer accounts, user IDs, and passwords were not compromised, but sensitive financial and cadastral information was exposed.
- Threat actor ZeroBytes claims it accessed property data covering roughly 20 million French citizens and extracted records involving more than 2 million people, though authorities have not confirmed those figures.
- The stolen tax, income, address, and property data could enable more convincing phishing, impersonation, and fraud attempts.
What data was exposed in the incident?
According to the French Ministry of the Economy and Finance, the compromised information included reference tax income, family quotient information, and withholding tax rates.
For businesses, exposed records included company names and SIREN identification numbers.
Attackers also accessed cadastral information related to addresses and property sizes.
The ministry emphasized that taxpayers’ online accounts were not compromised and that user IDs and passwords were not exposed.
After identifying the breach, DGFiP notified France’s data protection authority, the Commission Nationale de l’Informatique et des Libertés (CNIL).
Access to sensitive information systems was also restricted while officials continued investigating the incident with France’s National Cybersecurity Agency (ANSSI).
Attacker claims access to millions of property records
ZeroBytes also claimed access to the Serveur Professionnel de Données Cadastrales (SPDC), an online platform operated by the French tax authority that provides access to centralized land registry and property ownership information.
The attacker claimed the compromised platform provided potential access to information concerning approximately 20 million French citizens.
However, ZeroBytes said only 252,149 records containing information on more than 2 million people were extracted because collecting the larger dataset would have required too much time.
French authorities have not confirmed those broader figures, with the official investigation currently identifying 678,000 affected individuals and professionals.
Why the stolen tax data matters
Tax income, withholding rates, addresses, property information, and business identifiers can give attackers contextual information that makes fraudulent activity more convincing.
For example, criminals could incorporate legitimate financial or property details into phishing emails, phone calls, impersonation attempts, or other social engineering schemes.
Information from the breach could also potentially be combined with data obtained from other sources to build more detailed profiles of victims.
What individuals should do
Individuals affected by similar breaches should focus on reducing the risk of phishing, fraud, and identity theft.
- Be cautious of unexpected emails, calls, texts, or letters requesting personal or financial information, and verify communications through official channels before responding.
- Monitor bank accounts, credit reports, and other financial activity for unauthorized transactions or signs of identity theft, and consider a fraud alert or credit freeze when appropriate.
- Enable MFA on financial, email, and other sensitive accounts, and follow any additional precautions provided in official breach notifications.
What organizations should do
Organizations handling sensitive personal, financial, or government data should combine preventative controls with monitoring and incident response measures.
- Monitor for abnormal database queries, bulk exports, unusual privileged activity, and suspicious data transfers that could indicate unauthorized access or exfiltration.
- Enforce least-privilege access, regularly review privileged and service accounts, and revoke unnecessary permissions or compromised sessions.
- Implement data loss prevention (DLP), rate limiting, and export restrictions to detect or prevent unauthorized bulk extraction of sensitive information.
- Strengthen authentication, encryption, and credential management for systems containing sensitive data, including rotating credentials and authentication tokens following suspected compromise.
- Segment sensitive databases and applications from other systems and restrict unnecessary network connectivity to reduce lateral movement and unauthorized access.
- Maintain comprehensive logging, conduct threat hunting after suspected compromises, and preserve forensic evidence to determine what systems and data attackers accessed.
- Test incident response plans and use attack simulation tools with scenarios around data exfiltration and phishing attacks.
Bottom line
The DGFiP breach highlights the need to validate controls around bulk data access, exports, and exfiltration, especially for high-value data stores.
Security teams should also track the investigation for details on initial access and ZeroBytes’ broader claims, which could reveal security gaps relevant to other data-intensive environments.
Zero trust can help in these types of incidents by continuously verifying access and limiting privileges, helping reduce the blast radius after an initial compromise.





