DGFiP Data Breach Exposes Records of 680,000 French Taxpayers
France's Directorate General of Public Finances (DGFiP) has confirmed a major data breach affecting approximately 678,000 individuals, discovered after a threat actor advertised their access to the agency's internal systems on a hacking forum. Investigators determined that attackers used compromised credentials from a DGFiP employee and a third-party account to infiltrate the network during June and July. While DGFiP initially suspended unauthorized access upon detection, it later confirmed evidence of data exfiltration that had not been previously identified.
The exposed dataset includes reference tax income figures, withholding tax rates, company names with unique identifiers, and cadastral data covering real estate addresses and surface areas. According to the agency, no usernames, passwords, or banking details were compromised. DGFiP has reported the incident to France's data protection authority, the Commission Nationale de l'Informatique et des Libertés (CNIL), and committed to notifying each affected individual directly. Given the sensitivity of the leaked financial and property records, impacted taxpayers are advised to verify whether their credentials or email addresses have appeared in prior exposures using an email breach checker and to confirm that no fraudulent tax accounts have been created in their name.
The breach underscores how credential-based intrusions remain one of the most effective initial access vectors for threat actors targeting large government institutions. Security teams defending similarly sensitive environments should enforce hardware-based multi-factor authentication on all internal and third-party accounts, enforce least-privilege access controls, and audit privileged sessions through centralized logging. A compromised password tied to a single contractor or employee can cascade into mass data exposure, as this incident demonstrates. Organizations can also use a password checker to evaluate whether employee credentials meet current complexity and breach-resistance standards, and run a broader privacy checkup to identify publicly exposed assets that could fuel credential-stuffing or targeted social engineering attacks.
The disclosure comes roughly one month after Romania's National Agency for Cadastre and Property Registration (ANCPI) was struck by a separate cyberattack attributed to a threat actor known as ByteToBreach, who stole employee credentials and internal documents before attempting extortion. When the ransom demand was refused, the actor wiped encrypted data, disrupting official applications, sites, and email services, and effectively halting Romania's real estate market for nearly three weeks. Together, these twin incidents targeting European tax and cadastral authorities signal an escalating interest by financially motivated criminals in government-held property and financial records.