CSIDB logo
Incident

General Directorate of Public Finances

Incident posture

Attack window
Jun 2026
Location
France
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-10 01:03

Linked entities

Victim
General Directorate of Public Finances
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2026
Discovered
Undetermined
Disclosed
Aug 2026
Resolved
Pending

Summary

The French Ministry of Finance confirmed that a malicious actor broke into the General Directorate of Public Finances (DGFP) systems, prompting an investigation into the scope of the taxpayer data exposure. FrenchBreaches said the hackers claimed the breach involved data on nearly 700,000 taxpayers, while the ministry said affected users would receive personalized notices explaining what information may have been viewed or extracted and any precautionary steps they should take.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

The breach of France’s General Directorate of Public Finances occurred in late June 2026. A malicious actor gained access to the agency’s systems and subsequently claimed responsibility for the intrusion. The French Ministry of Finance later announced the breach approximately two months after the initial compromise. Its investigation confirmed the attacker’s claim that the DGFP systems had been breached. The ministry stated that additional investigations were underway to establish how many taxpayers were affected and what information was involved. It did not provide a confirmed total number of affected taxpayers or identify the specific categories of data accessed or extracted.

FrenchBreaches, a platform that tracks cyberattacks in France, reported that the hackers told it the breach involved data on nearly 700,000 taxpayers. That figure came from the attackers and was not confirmed by the Ministry of Finance. According to Reuters, the ministry did not respond to a request for comment made through FrenchBreaches. The reported scope therefore remained unverified, while the government continued its investigation into the number of people and records involved. The ministry said affected users would receive personalized notices. Those notices were intended to explain which data may have been viewed or extracted. They would also identify any precautionary steps affected users should take where necessary. The source did not state when the notices would be issued, how many had been sent, or whether any taxpayer had yet received one. It also did not identify the attacker, describe the method used to gain access, specify which DGFP systems were compromised, or confirm whether the intrusion had been contained. The incident followed other reported cyber incidents affecting French data in 2026, including the theft of medical data belonging to 15 million citizens in February and unauthorized access to a bank database containing information on 1.2 million accounts that same month.

Sources

Sources available to members: 1 source.

CSIDB