
France's tax authority has confirmed that an attacker gained unauthorized access to its information systems and extracted data belonging to individuals and businesses.
Separately, a hacker using the name ZeroBytes claims to have obtained cadastral records linked to more than two million property owners.
The Direction générale des Finances publiques (DGFiP) disclosed the incident on August 13, one day after a threat actor publicly claimed responsibility for an intrusion that the agency says occurred in late June 2026. According to the DGFiP, the attacker gained access through an identity impersonation scheme, and the connection was cut during security controls at the end of June.
However, an initial investigation found that the unauthorized session had already allowed the attacker to view and extract data concerning private individuals and professional users. The DGFiP has not yet disclosed what information was taken or how many people are affected.
The DGFiP is the French government department responsible for collecting taxes, managing public finances, maintaining property and cadastral information, and operating online tax services used by millions of residents and businesses.
French breach-monitoring site FrenchBreaches reported on August 14 that ZeroBytes also claimed access to the DGFiP's Serveur Professionnel de Données Cadastrales (SPDC), a professional cadastral data system reachable through apexappliext.dgfip.finances.gouv.fr.
According to the hacker's claims, 252,149 records were extracted from the system, corresponding to 2,041,778 people because individual records can contain multiple property holders. A sample reportedly contained:
- Names
- Gender
- Dates and places of birth
- Mailing addresses
- MAJIC property identifiers
- Municipalities
- Cadastral sections and parcel numbers
- Property rights information
- Links between co-owners of the same property
ZeroBytes also claimed to have authenticated to the service after bypassing multi-factor authentication and maintained access for an extended period. The attacker said the extraction was stopped voluntarily because retrieving the records was slow and alleged that the complete system could contain information on roughly 20 million people.
Those figures, the claimed MFA bypass, duration of access, and potential exposure of 20 million people remain unverified. FrenchBreaches also noted that the same actor previously claimed to have extracted 678,438 records from systems associated with impots.gouv.fr.

FrenchBreaches
Following the public claim, the DGFiP said it implemented additional access restrictions to terminate unauthorized activity and prevent further intrusions. Its security teams are investigating alongside France's economic and finance ministries, the Haut fonctionnaire de défense et de sécurité (SHFDS), and the national cybersecurity agency ANSSI.
The authority plans to notify France's data protection regulator, the CNIL, and file a criminal complaint. Affected users will be contacted individually once investigators determine what information was exposed.
People receiving a DGFiP notification should be particularly cautious of emails, calls, or messages referencing tax or property information. Stolen identity and cadastral data could support convincing phishing, impersonation, and social-engineering attacks, so users should independently verify requests through official government websites rather than links or contact details supplied in unsolicited messages.







Leave a Reply