France's DGFiP Tax Authority Confirms Breach After Crook Claims 2 Million Records

France's Directorate General of Public Finances confirmed attackers reached taxpayer data through a stolen identity in late June. A criminal touts 2 million records for sale; officials so far count about 600,000 victims, and the government disputes claims of continued access.

Share
Flat white line-art of a tall public finance building with a stolen key at the entrance and a single flat red dot, on a saturated navy background.

France's tax authority has confirmed that an intruder reached taxpayer data after stealing or misusing someone's identity, an admission that landed only after a criminal began advertising what they claim is a haul of 2 million records. The agency, the Directorate General of Public Finances (French: Direction générale des Finances publiques, or DGFiP), puts its own count of affected people at about 600,000 so far.

The gap between those two figures is the story. According to The Register, the person behind the intrusion is touting 2 million records; The Record reports that officials have so far confirmed roughly 600,000 victims. The DGFiP traces the unauthorized access to identity theft at the end of June 2026, and the French government disputes the attacker's suggestion of continued access.

What France Has Actually Confirmed

Strip away the marketing from the extortion post and a narrow set of facts remains. The DGFiP, which runs France's tax collection and public-finance systems, says an unauthorized party got into its information system by way of a stolen or misused identity, and that the access dates to late June. Officials describe the confirmed impact as affecting about 600,000 people, a figure they have reached by working through the records the intruder could have touched rather than by accepting the criminal's headline number.

That distinction matters for anyone reading the coverage. The 600,000 is an official, defender-side count of who may be affected. The 2 million is a seller's claim attached to stolen goods, the kind of number that tends to inflate in a listing. As of publication, CyberSignal has not seen independent confirmation that 2 million records were taken, and the DGFiP has not endorsed that figure. Some French outlets have put the confirmed tally slightly higher, near 678,000, but the official framing remains in the neighborhood of 600,000.

Two Million Records or 600,000 Victims?

The safest way to read a breach like this is to hold the confirmed count and the criminal's claim in separate columns and refuse to merge them. A record is not a person: a single victim can appear across many records, and a criminal advertising "2 million records" may be counting rows in a database dump, not distinct human beings. The DGFiP's roughly 600,000 is a count of affected people; the crook's 2 million is a count of records, offered without proof. Whether the seller has published a sample to back the claim is not something we can confirm.

France's government has also pushed back on the narrative of an open door. The DGFiP says it moved to shut the access down, and it disputes the attacker's implication that they still have a way in. That dispute is worth flagging plainly: the government's position is that the access has been cut, while the criminal's sales pitch benefits from suggesting the tap is still running.

DGFiP Breach: Confirmed vs Claimed
● Confirmed by Officials
About 600,000 victims counted so far. Access came through a stolen or misused identity. The intrusion is dated to late June 2026.
● Claimed by the Crook
2 million records touted for sale. This number comes from the extortionist, not from the DGFiP, and remains unverified.
● Disputed
The attacker hints at ongoing access. The French government says the access was cut and disputes any claim of continued entry.
● The Weak Point
A single trusted identity opened the door. When one privileged login is enough, an entire record store sits one theft away.

What Remains Unconfirmed

Several load-bearing details are still open, and honest coverage should say so rather than paper over the gaps:

  • Whose identity was stolen or misused, and how, has not been disclosed.
  • No threat actor has been named or attributed.
  • Whether tax records themselves were exfiltrated, as opposed to merely viewed, is not established.
  • Whether the criminal has published a sample to prove the 2 million claim is unconfirmed.

On the regulatory side, the DGFiP has indicated it would report the incident to CNIL, France's data-protection regulator, and notify affected people once it has identified them. That is a stated intention drawn from the agency's public remarks; CyberSignal has not independently confirmed that a formal CNIL filing has been logged. Treat it as a plan on the record, not a completed step.

The Real Lesson: One Trusted Identity

The technically interesting part of this breach is also the most familiar. Access reportedly ran through a single stolen or misused identity. That is the same broken record defenders have been playing for years: when one trusted login can reach a large store of records, the security of the whole store collapses to the security of that one credential. It is the pattern behind the Snowflake campaign, where stolen customer credentials without multi-factor authentication opened dozens of environments and led to a guilty plea over breaches hitting 165 organizations. It is the same class of exposure that keeps public-sector systems in the headlines, from tax authorities to the water utilities hit across seven US states this year.

For defenders running privileged systems, the takeaways are unglamorous and effective. Enforce phishing-resistant multi-factor authentication on every privileged identity, with no exceptions carved out for service accounts or "temporary" access. Apply least privilege so that a single compromised login cannot read the entire population of taxpayer records. Watch for anomalous bulk queries against sensitive datastores, because a legitimate identity being driven by an illegitimate operator often shows up first as unusual volume rather than a failed login.

For French taxpayers, the practical risk is downstream fraud. Expect a rise in tax-themed phishing that name-drops the DGFiP, references refunds or overdue balances, and pushes toward a fake login page. The exposed data reportedly can include names, dates and places of birth, addresses, family situation, and tax details, which is exactly the raw material for convincing impersonation. Slow down on any unexpected message about your taxes, avoid links in those messages, and reach the tax authority through its official site rather than through a forwarded address.

My Read

My read: the number that will travel is 2 million, and it is the number least worth trusting. Extortion listings are marketing, and inflating a record count is free. The figure I would anchor to is the official count of roughly 600,000 affected people, with the honest caveat that official counts in fresh breaches tend to drift upward as investigators finish their work, not down. The more durable lesson sits underneath both figures: a national tax system was reachable through one misused identity. Until privileged access to bulk citizen data requires phishing-resistant authentication and is boxed in by least privilege, the next agency in this position will be reading from the same script. The dispute over continued access is a detail; the single point of failure is the story.

Primary Documents