CSIDB logo
Incident

Direction Générale des Finances Publiques

Incident posture

Attack window
Aug 2026
Location
France
Status
Unknown
CIA posture
Available to members
Updated
2026-09-10 13:13

Linked entities

Victim
Direction Générale des Finances Publiques
Threat actors
0 actors
Sources
5 sources

Timeline

Occurred
Jun 2026
Discovered
Aug 2026
Disclosed
Aug 2026
Resolved
Pending

Summary

The French Directorate General of Public Finances (DGFiP) confirmed a cyberattack in which an attacker impersonated authorized users via a VPN connection to access internal consultation tools and extract tax information of approximately 678,000 individuals and professionals. The compromised data included reference tax income, family quotient, withholding rate, identifying details, company names, SIREN numbers and cadastral data on real‑estate addresses and surfaces. Although the unauthorized access was terminated, the data exfiltration was not detected at the time. No usernames or passwords were compromised in the incident. The authority reported the breach to the French data protection agency CNIL and announced it would file a complaint. A prior unauthorized access to another government system had occurred earlier, prompting the authority to strengthen external‑access controls before this event.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

The incident came to public attention on August 12 2026 when a cybercriminal posted on a specialized forum claiming to have accessed data from the French General Directorate of Public Finances (DGFiP) and offering the stolen information for sale. The following day, August 13, the DGFiP confirmed that it had suffered a cyberattack and a data leak, stating that the breach had been identified after a routine check at the end of June 2026 had cut off the attacker’s network access, although the extraction of data had not been detected at that time. Investigations later determined that the unauthorized access had begun in June and persisted into July 2026, with the attacker using compromised credentials belonging to an employee and a third‑party account to gain entry to DGFiP’s internal systems. The intruder impersonated a legitimate user, established a VPN connection, and accessed internal consultation tools used by the tax administration to perform massive queries on taxpayer records.

The data that was consulted and extracted included reference tax income, family quotient, applied withholding tax rate, and other identifying information for individuals; for companies, the compromised data covered corporate names and SIREN numbers. In addition, cadastral details such as real‑estate addresses and property surfaces were accessed. The DGFiP emphasized that no usernames, passwords, or authentication credentials were taken in the breach. Approximately 678 000 individuals and professionals were determined to have had their information exposed, a figure that aligns with the earlier estimate of 678 000 affected parties mentioned in the initial reports. The agency promptly reported the incident to France’s data protection authority, the CNIL, and announced its intention to file a criminal complaint, while also implementing new restriction measures and terminating the accesses associated with the identified intrusion.

In response, the DGFiP stated that it continues to investigate the full nature and scope of the data breach, working with the security services of the economic ministries and the French National Agency for Information Systems Security (ANSSI) to determine how the intrusion occurred and to prevent any further unauthorized access. The authority affirmed that it will contact each affected individual directly to inform them of the specific categories of data that may have been consulted or extracted. This episode follows a similar security incident that affected the DGFiP in February 2026, when unauthorized access to the FICOBA national bank‑account file was achieved by impersonating the credentials of an official from another public body authorized to exchange information between administrations. That earlier breach, which occurred between the end of January and February 13 2026, allowed consultation of account holders’ names, addresses, and banking data such as RIB and IBAN, affecting roughly 1.2 million accounts—less than one percent of FICOBA’s total records—while tax identifiers were not consulted. After the FICOBA incident, the DGFiP had strengthened security mechanisms for external accesses in coordination with ANSSI, limited the number of external officials permitted to consult FICOBA, and begun introducing additional authentication measures for its citizen‑facing services. These actions were referenced again in the context of the June‑July 2026 breach as part of the ongoing effort to harden the administration’s defenses against credential‑based impersonation attacks.

Sources

Sources available to members: 5 sources.

CSIDB