Cyber Incident Victim: Direction Générale des Finances Publiques
Timeline
Summary
A hacker claimed to have breached the internal network of the French tax authority (DGFiP) and offered stolen taxpayer data for sale on a cybercriminal forum. The authority later confirmed that a cyberattack had occurred and that personal information had been exfiltrated, noting that the intrusion had been terminated during a routine check but the data theft went unnoticed. The breach exposed sensitive details managed by the agency’s online tax platform, prompting an official acknowledgment of the leak and raising concerns about the effectiveness of monitoring controls.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On August 12, 2026, a user on a forum frequented by cybercriminals posted a claim that they had infiltrated the internal network of France's Direction Générale des Finances Publiques (DGFiP), the tax authority responsible for the country's online tax platform, and had exfiltrated personal data of taxpayers. The post stated that the stolen data was being offered for sale, although no price was specified in the message. The claim quickly attracted attention from security observers and prompted the French Finance Ministry to prepare an official response. Later that week, on the evening of August 13, the ministry issued a press release confirming that it had suffered a cyberattack and that a data leak involving taxpayer information had occurred.

In the press release, ministry officials acknowledged that the attacker's access to the DGFiP network had been terminated at the end of June during a routine security check, but they noted that the data exfiltration had not been detected at that time. They explained that the intrusion had been identified only after the hacker's public claim prompted an internal review of logs and network traffic. Officials also stated that they were working with national cybersecurity agencies to assess the full scope of the compromised data.
The hacker's original forum message described the intrusion as having been achieved through a virtual private network (VPN) connection that allowed remote access to an internal tool used by DGFiP staff. The actor wrote that they were disconnected quickly after the routine check in June, yet they claimed to have continued extracting data without the ministry noticing the activity. The post concluded with the assertion that the government had not publicly acknowledged the intrusion despite being aware of the ongoing data transfer. The available source does not include further technical details about the vulnerability exploited or the exact volume of records taken.
