France's DGFiP Tax Authority Confirms Breach After Crook Claims 2 Million Records
France's DGFiP tax authority traced an intrusion to identity theft in late June and has confirmed 678,000 affected individuals and professionals. The attacker's claim of 2 million records remains unverified.
France's tax authority has confirmed that an intruder reached taxpayer data after stealing or misusing someone's identity, an admission that landed only after a criminal began advertising what they claim is a haul of 2 million records. The agency, the Directorate General of Public Finances (French: Direction générale des Finances publiques, or DGFiP), puts its own count of affected people at 678,000 so far.
The gap between those two figures is the story. According to The Register, the person behind the intrusion is touting 2 million records; The Record reported that officials had at that point confirmed roughly 600,000 victims; the DGFiP has since put the figure at 678,000. The DGFiP traces the unauthorized access to identity theft at the end of June 2026, and the French government disputes the attacker's suggestion of continued access.
What France Has Actually Confirmed
Strip away the marketing from the extortion post and a narrow set of facts remains. The DGFiP, which runs France's tax collection and public-finance systems, says an unauthorized party got into its information system by way of a stolen or misused identity, and that the access dates to late June. Officials put the confirmed impact at 678,000 individuals and professionals, a figure they reached by working through the records the intruder could have touched rather than by accepting the criminal's headline number. On August 17, France's Public Accounts Minister directed the DGFiP to begin notifying them.
That distinction matters for anyone reading the coverage. The 678,000 is an official, defender-side count of who may be affected. The 2 million is a seller's claim attached to stolen goods, the kind of number that tends to inflate in a listing. As of publication, CyberSignal has not seen independent confirmation that 2 million records were taken, and the DGFiP has not endorsed that figure.
Two Million Records or 678,000 Victims?
The safest way to read a breach like this is to hold the confirmed count and the criminal's claim in separate columns and refuse to merge them. A record is not a person: a single victim can appear across many records, and a criminal advertising "2 million records" may be counting rows in a database dump, not distinct human beings. The DGFiP's 678,000 is a count of affected people; the crook's 2 million is a count of records, offered without proof. Whether the seller has published a sample to back the claim is not something we can confirm.
France's government has also pushed back on the narrative of an open door. The DGFiP says it moved to shut the access down, and it disputes the attacker's implication that they still have a way in. That dispute is worth flagging plainly: the government's position is that the access has been cut, while the criminal's sales pitch benefits from suggesting the tap is still running.
What Remains Unconfirmed
Several load-bearing details are still open, and honest coverage should say so rather than paper over the gaps:
- Whose identity was stolen or misused, and how, has not been disclosed.
- No threat actor has been named or attributed.
- Whether tax records themselves were exfiltrated, as opposed to merely viewed, is not established.
- Whether the criminal has published a sample to prove the 2 million claim is unconfirmed.
On the regulatory side, the DGFiP has indicated it would report the incident to CNIL, France's data-protection regulator, and notify affected people once it has identified them. That is a stated intention drawn from the agency's public remarks; CyberSignal has not independently confirmed that a formal CNIL filing has been logged. Treat it as a plan on the record, not a completed step.
The Real Lesson: One Trusted Identity
The technically interesting part of this breach is also the most familiar. Access reportedly ran through a single stolen or misused identity — the entry pattern that dominates the opening hours of incident response. That is the same broken record defenders have been playing for years: when one trusted login can reach a large store of records, the security of the whole store collapses to the security of that one credential. It is the pattern behind the Snowflake campaign, where stolen customer credentials without multi-factor authentication opened dozens of environments and led to a guilty plea over breaches hitting 165 organizations. It is the same class of exposure that keeps public-sector systems in the headlines, from tax authorities to the water utilities hit across seven US states this year.
For defenders running privileged systems, the takeaways are unglamorous and effective, and they start with privileged access management. Enforce phishing-resistant multi-factor authentication on every privileged identity, with no exceptions carved out for service accounts or "temporary" access. Apply least privilege so that a single compromised login cannot read the entire population of taxpayer records. Watch for anomalous bulk queries against sensitive datastores, because a legitimate identity being driven by an illegitimate operator often shows up first as unusual volume rather than a failed login.
For French taxpayers, the practical risk is downstream fraud. Expect a rise in tax-themed phishing that name-drops the DGFiP, references refunds or overdue balances, and pushes toward a fake login page. The exposed data reportedly can include names, dates and places of birth, addresses, family situation, and tax details, which is exactly the raw material for convincing impersonation. Slow down on any unexpected message about your taxes, avoid links in those messages, and reach the tax authority through its official site rather than through a forwarded address.
My Read
My read: the number that will travel is 2 million, and it is the number least worth trusting. Extortion listings are marketing, and inflating a record count is free. The figure I would anchor to is the official count of 678,000 affected people, with the honest caveat that official counts in fresh breaches tend to drift upward as investigators finish their work, not down. The more durable lesson sits underneath both figures: a national tax system was reachable through one misused identity. Until privileged access to bulk citizen data requires phishing-resistant authentication and is boxed in by least privilege, the next agency in this position will be reading from the same script. The dispute over continued access is a detail; the single point of failure is the story.
Updated August 17, 2026: The DGFiP confirmed that 678,000 individuals and professionals were affected and began notifying them at the direction of France's Public Accounts Minister. The 2 million figure remains the attacker's unverified claim.
Corrected August 19, 2026: An earlier version of this article gave the confirmed victim count as roughly 600,000 and described the 678,000 figure as a higher number reported by some French outlets. 678,000 is the DGFiP's own confirmed figure. The count has been corrected throughout.
Primary Documents
- The Register: French tax authority admits data heist after crook touts 2M records
- The Record: France investigates tax authority breach after hacker claims victims
- Help Net Security: France's tax authority admits hackers made off with data on 678,000 individuals
- BleepingComputer: French tax authority data breach affects 678,000 individuals