General Directorate of Public Finances
Incident posture
Linked entities
- Victim
- General Directorate of Public Finances
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
The French Ministry of Finance confirmed that a malicious actor broke into the General Directorate of Public Finances (DGFP) systems, prompting an investigation into the scope of the taxpayer data exposure. FrenchBreaches said the hackers claimed the breach involved data on nearly 700,000 taxpayers, while the ministry said affected users would receive personalized notices explaining what information may have been viewed or extracted and any precautionary steps they should take.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
The breach of France’s General Directorate of Public Finances occurred in late June 2026. A malicious actor gained access to the agency’s systems and subsequently claimed responsibility for the intrusion. The French Ministry of Finance later announced the breach approximately two months after the initial compromise. Its investigation confirmed the attacker’s claim that the DGFP systems had been breached. The ministry stated that additional investigations were underway to establish how many taxpayers were affected and what information was involved. It did not provide a confirmed total number of affected taxpayers or identify the specific categories of data accessed or extracted.
FrenchBreaches, a platform that tracks cyberattacks in France, reported that the hackers told it the breach involved data on nearly 700,000 taxpayers. That figure came from the attackers and was not confirmed by the Ministry of Finance. According to Reuters, the ministry did not respond to a request for comment made through FrenchBreaches. The reported scope therefore remained unverified, while the government continued its investigation into the number of people and records involved. The ministry said affected users would receive personalized notices. Those notices were intended to explain which data may have been viewed or extracted. They would also identify any precautionary steps affected users should take where necessary. The source did not state when the notices would be issued, how many had been sent, or whether any taxpayer had yet received one. It also did not identify the attacker, describe the method used to gain access, specify which DGFP systems were compromised, or confirm whether the intrusion had been contained. The incident followed other reported cyber incidents affecting French data in 2026, including the theft of medical data belonging to 15 million citizens in February and unauthorized access to a bank database containing information on 1.2 million accounts that same month.
Sources
Sources available to members: 1 source.