惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
小众软件
小众软件
MongoDB | Blog
MongoDB | Blog
Hugging Face - Blog
Hugging Face - Blog
Jina AI
Jina AI
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Stack Overflow Blog
Stack Overflow Blog
L
LangChain Blog
大猫的无限游戏
大猫的无限游戏
量子位
A
About on SuperTechFans
G
Google Developers Blog
雷峰网
雷峰网
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
IT之家
IT之家
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园_首页
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Vercel News
Vercel News
V
Visual Studio Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 聂微东
U
Unit 42
Apple Machine Learning Research
Apple Machine Learning Research

Consumer Insights

Weverse data breach affects 422,584 user accounts Manchester Airports Group cyberattack exposes data of 8.7 million customers Sakura Internet hack may affect 1.36 million accounts Phone number leaked in the Bloctel breach? Here’s what to do. SplitVPN breach reveals 58 million hidden connection logs South Korea diplomatic academy hack exposes diplomat data Credential stuffing attack at Chick-fil-A comes with data breach notice for customers Coca-Cola halts Fairlife production across US after ransomware attack Qantas data breach started with a fake IT support call Lidl warns customers after data breach How to find out if your identity has been exposed by infostealers Texas breach exposes PII of 3 million hunting and fishing license customers Maine forced to take down data breach portal after fake notices filed with authorities Carnival breach exposes data of nearly 6 million people 7-Eleven data breach exposes data of 185,000 people UK Water Supplier Fined Nearly £1 Million After Hackers Roamed Networks for Almost 2 Years DAEMON Tools Lite breach prompts urgent update after malware-laced installer Instructure confirms breach; millions of Canvas users potentially impacted Stalkerware data leak exposes private screenshots linked to celebrities and influencers Hackers claim to have breached Udemy, stealing 1.4 million user records Rituals data breach exposes customer details Booking.com says breach exposed travelers’ data Basic-Fit data breach exposes member information across Europe Rockstar Games confirms breach after ShinyHunters leaks stolen analytics data Lapsus$ claims AstraZeneca breach exposes code and credentials Aura data breach exposes 900,000 records after phishing attack Telus Digital data breach confirmed after ShinyHunters claims 1PB theft Was Your Data Exposed in the Latest Under Armour Breach? Here’s What You Should Do Breach at Tinder, Hinge and OkCupid exposes user data Europe Fines Big Tech €1.2 Billion under GDPR in 2025
French tax authority breach exposes data of 678,000 peopl...
Alina BÎZGĂ · 2026-08-18 · via Consumer Insights

France's tax authority has confirmed a major data breach affecting 678,000 individuals and professionals after cybercriminals gained access to systems of the Direction générale des Finances publiques (DGFiP).

The disclosure came after a threat actor publicly claimed responsibility for the attack and advertised allegedly stolen DGFiP information on a cybercrime forum.

Key takeaways

  • 678,000 individuals and professionals are confirmed to have been affected
  • Attackers accessed tax and property-related information, including reference taxable income, family quotient, withholding tax rates, property addresses and property sizes
  • For businesses, exposed information included company names and SIREN identification numbers
  • DGFiP says users' online tax accounts were not compromised, and usernames and passwords belonging to individuals and businesses were not exposed
  • Affected users can expect to be contacted directly by DGFiP by email or postal mail, with information about what data may have been accessed or stolen

What happened in the DGFiP data breach?

According to the French government, the attacker gained access to DGFiP information systems in June and July using compromised credentials.

DGFiP says it terminated access for the accounts involved after detecting the intrusions. However, initial access checks did not reveal that data had also been stolen, which authorities attributed to the attack's sophistication.

Following claims made by the attacker on August 12 and 13, investigators conducted a deeper analysis and determined that the unauthorized access had been used to view and extract information belonging to 678,000 people and professionals.

The incident is now being investigated by France's national cybersecurity agency, ANSSI. DGFiP has also notified the French data protection authority, CNIL, and said it will file a criminal complaint.

What information was exposed?

The confirmed compromised information includes some sensitive financial and tax-related details.

For individuals, the exposed data includes reference taxable income, family quotient and withholding tax rates. Cadastral information was also accessed, including property addresses and property sizes.

For businesses, the stolen information may include company names and SIREN numbers.

Importantly, DGFiP says personal and professional accounts available through its online services were not compromised and users' usernames and passwords were not stolen.

What should affected users expect?

DGFiP says it will contact each affected individual and professional directly by email or postal mail. Those notifications should explain which information may have been stolen and provide recommendations on precautions users should take.

Even without exposed passwords, however, the stolen information could create opportunities for highly convincing fraud.

Tax information, property details and other data can give scammers valuable context when impersonating tax authorities, banks or other organizations. Affected users should therefore be particularly cautious about unexpected messages claiming to come from DGFiP or another government service, especially those asking them to verify an account, provide additional information, follow a link or make a payment.

How can you stay safe after the DGFiP breach?

If you receive a notification from DGFiP, don’t panic. Read it carefully and check what information was affected. Keep in mind that scammers may also try to take advantage of news about the breach by sending fake notifications of their own.

Here are a few precautions you can take:

  • Change your password as a precaution. DGFiP says taxpayer usernames and passwords were not compromised. Still, consider updating the password you use for your tax account, particularly if you have used it on another website. Use a strong, unique password for every important account and enable two-factor authentication (2FA) wherever it's available.
  • Be wary of breach-related scams. Watch for unexpected emails, texts or calls claiming to come from DGFiP, tax officials, banks or other government services. Criminals could potentially use stolen tax and property information to make their stories sound more convincing.
  • Don't trust someone simply because they know information about you. Just because caller knows details about your finances, taxes or property doesn’t mean he’s legitimate. Never provide passwords, banking information or verification codes in response to an unsolicited request.
  • Don't click first and investigate later. Be especially cautious with messages about tax refunds, unpaid taxes, compromised accounts or urgent verification requests. Instead of following the provided link, navigate directly to the organization's official website.
  • Check suspicious messages and links for free. If you're unsure whether something you've received is legitimate, ask Bitdefender Scamio, our free AI-powered scam detector, to analyze suspicious messages, emails, QR codes and links. You can also check suspicious URLs with the free Bitdefender Link Checker before opening them.
  • Keep an eye on your exposed personal information. Bitdefender Digital Identity Protection helps you monitor your digital footprint and alerts you when your personal information is found in data breaches and leaks.

Also, remember that information stolen in a data breach can remain useful to criminals long after the initial incident. Tax, financial and property information could also be combined with data obtained from other breaches to build a more complete profile of a potential victim, making future phishing, impersonation and social engineering attempts harder to spot.