Desk live·
ForensicPost
Breaches/Public sector/File 26-0825

French Tax Authority Confirms Data on 678,000 Taxpayers Was Extracted With Valid Logins

DGFiP established that credentials belonging to an employee and an authorised third party were used over June and July to pull tax data on 678,000 individuals and businesses. A forum seller’s claim came first; the official count followed.

Constructed geometry · not a chart of case data
JurisdictionFranceParisthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetDGFiP taxpayer records
ActorUnattributed
D. Kennedy11 min readConfidence: high3 sources reviewed

France’s Directorate General of Public Finances confirmed in late August 2026 that data on approximately 678,000 individuals and professionals had been consulted and extracted from its systems during June and July. The route was not an exploit: compromised credentials belonging to a DGFiP employee and to an authorised third party were used to query systems those accounts were entitled to reach. Exposed fields include reference tax income, family quotient and withholding rates; for businesses, names and SIREN numbers; and cadastral data covering addresses and property sizes.

Disclosure followed the market. An actor using the handle ZeroBytes claimed access on 12 and 13 August and listed a database for sale on a criminal forum; the ministry’s confirmation and the ANSSI investigation came after. Online tax accounts, usernames and passwords were not compromised, per the authority.

Two Accounts Doing What They Were Allowed To Do

Both credentials were legitimate, and one belonged to an outside party authorised to query the register — the arrangement every large administration runs, and the pattern filed at 25-0421b as the dominant intrusion mode of this period. Authentication succeeded every time. The control that failed sits a layer up: nothing asked why two accounts were consulting records at a scale no ordinary workload produces, the bulk-retrieval blindness recorded at 25-0612 when 300,000 crash reports left Texas the same way.

A Register Nobody Can Leave

A taxpayer cannot close their account with the tax authority, choose a competitor or decline to file. Reference income and family quotient are precisely the fields a convincing tax-refund scam quotes to prove it is genuine, and 678,000 people now face that exposure through a relationship they were never free to refuse.

The Seller Announced It Before The State Did

The sequence — forum listing on 12 August, official confirmation later in the month — repeats the ordering this database keeps recording: the attacker publishes first, on their own timeline, with their own figures. Here the official count of 678,000 arrived with an investigation behind it, and the forum claim of 600,000 undershot it. Claims can run low as well as high; what they cannot do is substitute for a count someone verified.

How we reported this

Compiled from the ministry’s statements as reported and contemporaneous coverage, listed below. The 678,000 figure and the credential route are the authority’s findings; the forum claim is carried as a claim. The seller’s handle is reported, not verified as an identity. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. French tax authority data breach affects 678,000 individualsBleepingComputer
  2. France investigates tax authority breach after hacker claims 600,000 victimsThe Record
  3. French tax agency breach: 678,000 records, one stolen loginTNW
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary