Best practice and case studies for Finance, Shared Services and Indirect Tax professionals. Automation tips and strategies in our webinars, articles, events.

French Tax Authority Data Breach Affects 678,000 Individuals and Businesses


{{article.author.firstname}} {{article.author.lastname}}
Sarah Fane
Aug 19, 2026
computer

France's tax authority has confirmed that data relating to around 678,000 individuals and businesses was accessed and extracted following unauthorised access to its information systems.

The Directorate General of Public Finances (DGFiP) said the intrusions took place during June and July 2026 after a malicious actor obtained the credentials of a DGFiP employee and an authorised third party.

The breach came to light after the attacker publicly claimed on 12 and 13 August to have gained access to the DGFiP's systems.

According to the authority, access to the accounts involved was suspended as soon as the intrusions were initially detected. Checks carried out at the time did not identify any data theft, however, which the DGFiP attributed to the sophistication of the attack.

Further investigations launched following the claims in August have since established that the compromised access points were used to view and extract information relating to approximately 678,000 individuals and professionals.

Tax and Business Data Accessed

The information affected includes tax data such as reference tax income, family quotient and withholding tax rates.

For businesses, information accessed included company names and SIREN identification numbers. Cadastral information, including addresses and property sizes, was also accessed.

The DGFiP stressed that taxpayers' online accounts themselves were not compromised and that user IDs and passwords were not affected.

The authority has notified France's data protection regulator, the CNIL, of the breaches.

Additional security measures have also been introduced, including the preventative shutdown of access to sensitive information systems.

Investigations are continuing to establish the precise nature and volume of information extracted and the total number of users affected.

The DGFiP said its information systems teams are working with other government cybersecurity bodies, including the High Official for Defence and Security (SHFDS) and the National Agency for Information Systems Security (ANSSI).

Affected Taxpayers to Be Contacted

Beginning next week, the DGFiP plans to contact each individual and professional affected by the breach directly.

Those affected will receive an email or letter explaining which information may have been accessed or extracted and, where necessary, what precautionary measures they should take.

The DGFiP said it will file a complaint over the incident and provide further information as the investigation progresses.

View the full press release here


This content is intended to share insights and practical considerations based on industry experience. It does not constitute legal, regulatory, or financial advice. Regulatory requirements vary by jurisdiction and circumstance, so any compliance-related matters should be reviewed and validated with your own professional advisors.