France's General Directorate of Public Finances (DGFiP), the national tax authority, has confirmed a data breach that exposed information belonging to approximately 600,000 individuals and businesses. The compromised data includes tax identification numbers, marital status, email and postal addresses, phone numbers, household composition, number of dependents, family quotient, reference tax income, and withholding rates.
For about 250 individuals, the breach also included the content of messages exchanged with the tax authority, while lists of messages were exposed for a larger, unspecified number of taxpayers. Approximately 350,000 individuals were affected by the exposure of personal and tax-related information.
In addition to individual taxpayer data, the breach impacted around 250,000 businesses and professionals, though the exposed information for these entities was limited to company names and SIREN numbers, which are unique nine-digit identifiers for French businesses. Cadastral data, including property addresses and dimensions, was also compromised, but DGFiP stated this information is already publicly available.
The DGFiP is in the process of notifying affected taxpayers via email or postal mail. The authority has warned that the stolen details could be used by criminals for more convincing phishing attempts, impersonation, CEO fraud, and scams involving bogus bank advisers. DGFiP reiterated that it would never request sensitive information like PINs or identity documents by phone, text message, or email, and would only request such material through its secure online portal.
The confirmed number of affected parties, roughly 600,000, is lower than the 678,000 "individuals and professionals" initially reported by DGFiP last week. It is also significantly less than the more than 2 million records claimed to have been stolen by an alleged cybercriminal operating under the alias "ZeroBytes," who initially publicized the attack. The tax authority has not provided an explanation for these discrepancies.
Separately, DGFiP disclosed a "technical vulnerability" in the government's Vacant Successions Portal (PSV), a service used to search for estates without known heirs. The service has been suspended following the discovery of the flaw. While an investigation into potential exposure of applicants' details is ongoing, DGFiP has stated there is no current evidence of personal data leakage from this vulnerability.
This incident is one of several cybersecurity challenges faced by the French public sector recently. In February, the finance ministry, which oversees DGFiP, reported an intrusion into a database containing citizens' bank details, affecting 1.2 million people. In March, the Health Ministry confirmed that 15.8 million administrative files, including 165,000 containing doctors' notes, were stolen during an attack on healthtech company Cegedim Santé. An alleged attack in April on France Titres, responsible for identity documents, was claimed to have affected between 18 million and 19 million people. Furthermore, in June, an alleged breach of Tchap, the government's encrypted messaging platform, prompted an investigation after attackers claimed access to 73,000 user accounts, 643,000 messages, and nearly 60,000 media files.






