France’s tax authority has confirmed that an intruder extracted taxpayer data from its systems in June, after a cybercriminal using the alias ZeroBytes advertised a database of 2 million records on a hacking forum.
The General Directorate of Public Finances (DGFiP) said in a statement that initial investigations confirm the unauthorized access, which came after an identity theft, allowed the consultation and extraction of data on individuals and professionals. The agency said the access was severed at the end of June during an audit and that it has since implemented new restrictions.
ZeroBytes claimed the haul covers more than 2 million French taxpayers, gained through stolen credentials and an MFA bypass technique. The seller also claimed to retain access to DGFiP’s systems and offered to sell that alongside the database, a claim the agency disputes.
DGFiP said it would report the incident to France’s data protection watchdog, CNIL, and notify affected users once investigators determine exactly who was impacted.
The intrusion extends a brutal year for French public-sector security. In February, the Finance Ministry admitted attackers using stolen credentials took 1.2 million bank records. In March, healthtech supplier Cegedim Sante was hit in an attack that stole around 15.8 million administrative files. In April, France Titres, the agency behind passports and driver’s licenses, probed claims of an 18-19 million record breach, allegedly the work of a 15-year-old.
For organizations, the pattern is familiar: stolen credentials plus a bypassed second factor. The French response also highlights the value of rapid audit-based detection, since the access was caught and cut off during a scheduled review. Taxpayers should watch for phishing that weaponizes the stolen data, since attackers now have verified personal details to make lures far more convincing.
