Published Security3 min read
DGFiP breach started with a borrowed identity, not a bug
France's tax authority says an intruder used a stolen or misused identity to reach its systems in late June and extract data on individuals and businesses before access was cut.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- France's Economy Ministry said late Thursday that an attacker gained unauthorized access to systems at the Directorate General of Public Finances (DGFiP) in late June after stealing or misusing someone's identity.
- According to the ministry, the intrusion allowed the attacker "to view and extract data belonging to individuals and businesses".
- Officials said the unauthorized access was detected and cut off in late June.
- The incident became public after a hacker claimed responsibility earlier this week, prompting the tax authority to impose additional restrictions to prevent further unauthorized access.
- Authorities are working to determine precisely what information was accessed or stolen and how many individuals and businesses were affected.
Compiled by The WatchSomething wrong?How this is made
Why it matters
France's Economy Ministry said late Thursday that an attacker gained unauthorized access to systems at the Directorate General of Public Finances, the DGFiP, in late June after stealing or misusing someone's identity, and that the intrusion allowed the attacker "to view and extract data belonging to individuals and businesses" [1][2]. The mechanism is the story: the ministry's account describes an identity being taken over, not a software flaw being exploited, which puts the failure in access control and monitoring rather than patching [19].
Officials said the unauthorized access was detected and cut off in late June [3]. The public learned about it only this week, after a hacker claimed responsibility, at which point the tax authority imposed additional restrictions to prevent further unauthorized access [4]. Detection did not trigger disclosure; the attacker's own publicity did [20].
FrenchBreaches, a site that tracks data leaks in France, reported that the attack was claimed by a hacker using the alias ZeroBytes [8]. According to that account, the hacker said access to internal servers let them connect to the agency's VPN and use an internal tool to search for information on individuals and businesses, and that they began stealing data before the access was cut off [11][12]. If that description holds, the extraction was done with the agency's own lookup tooling working as designed, which is the hardest kind of activity to separate from routine work. The hacker claimed data on more than 600,000 people, including names and other personal information, tax identification numbers, email addresses, family circumstances and details about tax status [9]. Neither the claim nor the authenticity of the purportedly stolen data has been independently verified, and the DGFiP has not attributed the breach to a specific actor or confirmed the hacker's figures [10][13].
Authorities are still working out what was actually accessed and how many individuals and businesses are affected [5]. The DGFiP said those whose data was compromised will be contacted individually and told what may have been exposed and what precautions to take, and that it would notify France's data protection authority, file a criminal complaint and provide further information as the investigation continues [6][7].
This is not an isolated year for French public-sector data. In April, hackers targeted the website of the National Agency for Secure Documents, ANTS, which handles applications for passports, national identity cards, residence permits and driver's licences [14]. That same month, the Education Ministry disclosed that an attack on a system used to manage student accounts had exposed students' personal information [15]. In February, part of the National Bank Accounts File was breached, exposing information linked to roughly 1.2 million accounts out of more than 300 million entries, or about 0.4 percent of the database [16][17]. Earlier this year police arrested a 20-year-old suspected of carrying out dozens of breaches involving government bodies, sports federations and private companies [18].
Three things to watch. First, whether the DGFiP's eventual count lands near the claimed 600,000 or well away from it [9][5]. Second, whose identity was used: the ministry's statement does not say whether the credentials belonged to staff, a contractor or another connected party, and that distinction determines whether the fix is internal hygiene or supplier control [21]. Third, the notification timeline, since individual letters and the filing with the data protection authority will be the first externally checkable evidence of how wide the agency thinks the exposure runs [6][7].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
France's Economy Ministry said late Thursday that an attacker gained unauthorized access to systems at the Directorate General of Public Finances (DGFiP) in late June after stealing or misusing someone's identity.
- [2]
According to the ministry, the intrusion allowed the attacker "to view and extract data belonging to individuals and businesses".
- [3]
Officials said the unauthorized access was detected and cut off in late June.
- [4]
The incident became public after a hacker claimed responsibility earlier this week, prompting the tax authority to impose additional restrictions to prevent further unauthorized access.
ReportedView cited source - [5]
Authorities are working to determine precisely what information was accessed or stolen and how many individuals and businesses were affected.
ReportedView cited source - [6]
The DGFiP said people whose data was compromised will be contacted individually and told what information may have been exposed and what precautions they should take.
Sources & coverage · 6 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- therecord.mediaAug 14France investigates tax authority breach after hacker claims 600,000 victims
- securityaffairs.comPierluigi PaganiniAug 16Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers
- bleepingcomputer.comSergiu Gatlan6d ago



