Stolen details range from contact information to household finances and withholding rates

France's General Directorate of Public Finances (DGFiP), the national tax authority, has confirmed a data breach that exposed information belonging to approximately 600,000 individuals and businesses. The compromised data includes tax identification numbers, marital status, email and postal addresses, phone numbers, household composition, number of dependents, family quotient, reference tax income, and withholding rates.
For about 250 individuals, the breach also included the content of messages exchanged with the tax authority, while lists of messages were exposed for a larger, unspecified number of taxpayers. Approximately 350,000 individuals were affected by the exposure of personal and tax-related information.
In addition to individual taxpayer data, the breach impacted around 250,000 businesses and professionals, though the exposed information for these entities was limited to company names and SIREN numbers, which are unique nine-digit identifiers for French businesses. Cadastral data, including property addresses and dimensions, was also compromised, but DGFiP stated this information is already publicly available.
The DGFiP is in the process of notifying affected taxpayers via email or postal mail. The authority has warned that the stolen details could be used by criminals for more convincing phishing attempts, impersonation, CEO fraud, and scams involving bogus bank advisers. DGFiP reiterated that it would never request sensitive information like PINs or identity documents by phone, text message, or email, and would only request such material through its secure online portal.
The confirmed number of affected parties, roughly 600,000, is lower than the 678,000 "individuals and professionals" initially reported by DGFiP last week. It is also significantly less than the more than 2 million records claimed to have been stolen by an alleged cybercriminal operating under the alias "ZeroBytes," who initially publicized the attack. The tax authority has not provided an explanation for these discrepancies.
Separately, DGFiP disclosed a "technical vulnerability" in the government's Vacant Successions Portal (PSV), a service used to search for estates without known heirs. The service has been suspended following the discovery of the flaw. While an investigation into potential exposure of applicants' details is ongoing, DGFiP has stated there is no current evidence of personal data leakage from this vulnerability.
This incident is one of several cybersecurity challenges faced by the French public sector recently. In February, the finance ministry, which oversees DGFiP, reported an intrusion into a database containing citizens' bank details, affecting 1.2 million people. In March, the Health Ministry confirmed that 15.8 million administrative files, including 165,000 containing doctors' notes, were stolen during an attack on healthtech company Cegedim Santé. An alleged attack in April on France Titres, responsible for identity documents, was claimed to have affected between 18 million and 19 million people. Furthermore, in June, an alleged breach of Tchap, the government's encrypted messaging platform, prompted an investigation after attackers claimed access to 73,000 user accounts, 643,000 messages, and nearly 60,000 media files.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a