Hackers Raid French Tax Systems, Exposing Data of Nearly 900,000 Accounts
Hackers breached French tax and land registry systems in separate attacks, exposing data linked to at least 678,000 individuals and professional accounts, plus 200,000 land registry accounts.
Xcademia Team
Xcademia Research Team

Hackers Raid French Tax Systems, Exposing Data of Nearly 900,000 Accounts
France is investigating two separate cyberattacks that compromised sensitive information held by government tax and property systems, raising fresh concerns about the security of public-sector databases.
According to a report by The Star, France's General Directorate of Public Finance, known as DGFiP, confirmed that its computer systems were breached in June and July.
The incidents affected tax-related records as well as information connected to the country's land registry.
678,000 tax and professional accounts affected
The first attack took place in June and involved information associated with at least 678,000 individuals and professional accounts, according to the authorities.
The compromised information included names, "reference income data" and tax rates paid.
The incident is significant because tax records can contain information that provides insight into an individual's or company's financial circumstances. However, the authorities did not indicate that the stolen data included passwords, payment credentials or other categories beyond those identified in the announcement.
Additional details were not disclosed in the announcement.
Second attack targeted land registry information
A separate incident occurred in July and involved approximately 200,000 land registry accounts, according to the DGFiP.
The hacking group known as Zerobytes had previously claimed responsibility for the attacks on a dark-web forum. The group claimed that it had obtained information involving 250,000 land registry accounts, which it said related to around two million people who owned land or property.
The difference between the government's figure and the group's claim has not been independently resolved in the source material.
The attackers also claimed that they gained access through a VPN used by tax officials. The authorities' announcement, as reported by AFP, did not provide further technical details about the alleged access method.
Why the stolen information matters
Tax and property records are particularly sensitive because they can connect people's identities with financial and ownership information.
Even when a breach does not expose passwords or banking credentials, stolen personal data can potentially increase the risk of phishing, impersonation and other forms of fraud.
France's tax authority has previously warned the public about fraudulent messages impersonating DGFiP officials. Its official guidance says attackers may attempt to obtain login credentials or financial information through deceptive emails and calls.
The DGFiP also disclosed a separate February 2026 incident involving illegitimate access to the FICOBA national bank-account database. The authority said the incident involved personal banking information and warned of possible phishing and identity-theft attempts.

A growing security challenge for government systems
The latest incidents come after other major cyberattacks affecting French public-sector systems.
The source report notes that France's agency responsible for identity-document applications, ANTS, was hit by a major attack in April that affected data associated with nearly 12 million individuals and professionals.
In February, France's finance ministry also reported a large-scale breach involving information connected to 1.2 million bank accounts.
These incidents illustrate the security challenge facing government organisations that manage large volumes of sensitive personal and financial information.
The broader issue is not limited to France. Public-sector agencies are attractive targets because they often maintain databases containing information about large populations, businesses, property ownership and financial activity.
The VPN access claim
One of the most notable claims surrounding the latest incidents is Zerobytes' statement that the attackers obtained access to a VPN used by tax officials.
A VPN can provide an authenticated connection to internal resources, but the source material does not establish how the attackers allegedly obtained access or whether the VPN itself was the root cause of the breach.
It is therefore important to distinguish the hacking group's claim from information confirmed by French authorities.

What the incidents mean for organisations
For enterprises and public agencies, the attacks highlight the importance of protecting access to systems that contain high-value personal information.
The announcement does not disclose the specific security controls being reviewed or any technical remediation measures being implemented by the French authorities.
The company did not provide specific information about this area.
However, the incidents demonstrate why security teams need to consider not only the protection of databases themselves, but also the systems and identities that provide access to them.
Remote-access infrastructure, employee accounts and authentication mechanisms can all become important parts of an organisation's security perimeter.
What users should watch for
People potentially affected by a government data breach should be particularly cautious about unexpected emails, text messages and phone calls that appear to come from tax authorities or other government organisations.
The DGFiP advises users to be cautious with communications requesting sensitive information. Its official guidance states that the tax administration does not request login credentials or bank-card information through messages.
For individuals, the immediate concern following a breach may therefore be secondary fraud attempts rather than the original intrusion itself.

The bigger picture
The French incidents underline a broader industry shift toward treating government data as a high-value cybersecurity target.
Large public databases can contain information that remains useful to attackers even when direct financial credentials are not exposed. Names, income-related information and property records can provide valuable context for targeted scams and impersonation attempts.
At the same time, the available information around the June and July incidents remains limited. Authorities have confirmed the affected categories and approximate number of accounts, while some additional claims have come from the attackers themselves.
Until French authorities release further technical findings, the full scope and method of the intrusions remain unclear.
For now, the incidents serve as another reminder that protecting sensitive government data requires security across the entire access chain, from user authentication and remote access to databases and monitoring systems.
Source: AFP, as published by The Star
About the Author