>>
Technology>>
Cyber security>>
French Taxpayers' Data Stolen ...The French Finance Ministry has confirmed a cyberattack on its tax authority, the Directorate General of Public Finances, in late June, leading to the exposure and extraction of data belonging to individuals and businesses.
France's tax authority, the Directorate General of Public Finances, was the target of a cyberattack in late June, resulting in the theft of data belonging to taxpayers, the French Finance Ministry has confirmed. The Ministry announced that a malicious actor claimed on Wednesday to have breached the system, and initial investigations have confirmed that the attacker was able to view and extract data.
The breach was carried out after the attacker stole an employee's identity to compromise the system's internal virtual private network. While the unauthorized access was identified and cut off at the end of June, it had already allowed for the extraction of information. The exact number of taxpayers affected has not been officially confirmed by the Ministry, which stated that investigations are ongoing to determine the precise nature and scale of the data theft.
The Scale of the Leak
Although Bercy has not yet confirmed the total number of victims, the specialised website French Breaches has reported that data belonging to nearly 678,000 people may have been compromised, including 392,867 individuals and 285,570 professionals. The Ministry has stated that affected taxpayers will be individually informed about what data may have been exposed and advised on any necessary vigilance measures.
What Data Was Exposed and What Happens Next?
While the Ministry has not published the full list of exposed data, reports suggest the breach may have included sensitive information such as names, dates of birth, postal and email addresses, tax identification numbers, reference incomes, and withholding tax rates. The French data protection authority, the CNIL, has been notified, and the Directorate General of Public Finances has filed a criminal complaint. The national cybersecurity agency, ANSSI, is also involved in the investigation.
Here is the question this breach raises. The theft of hundreds of thousands of French taxpayers' data highlights the vulnerability of state infrastructure to persistent cyber threats. When a nation's core financial systems are compromised, what does it take to restore public trust in digital governance and data security?
As the investigation continues, The Silicon Review asks a final question. When sensitive fiscal data is sold on the dark web, who ultimately bears the cost of this breach of trust?
FAQ:
Q: When did the cyberattack on the French tax authority occur?
A: The intrusion took place in late June 2026 but was only publicly confirmed by the French Finance Ministry on August 13, 2026.
Q: How many French taxpayers are affected by this data breach?
A: While the Ministry has not confirmed a number, the site French Breaches reports that nearly 678,000 individuals and professionals may be affected.
Q: What type of information was stolen in the French tax data breach?
A: The stolen data is believed to include names, addresses, tax identification numbers, reference incomes, and withholding tax rates.
Q: What was the method used in the cyberattack?
A: The attacker used stolen credentials for a "usurpation d'identité" (identity theft) to access a compromised internal VPN.
Q: What is the French government doing in response to the attack?
A: A criminal complaint has been filed, and the incident has been notified to the CNIL. The government is investigating the breach with assistance from ANSSI.
Comments