Security6 distinct publishers3 min readPublished Updated
France's tax authority says an intruder used a stolen or misused identity to reach its systems in late June and extract data on individuals and businesses before access was cut.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
France's Economy Ministry said late Thursday that an attacker gained unauthorized access to systems at the Directorate General of Public Finances, the DGFiP, in late June after stealing or misusing someone's identity, and that the intrusion allowed the attacker "to view and extract data belonging to individuals and businesses" [1][2]. The mechanism is the story: the ministry's account describes an identity being taken over, not a software flaw being exploited, which puts the failure in access control and monitoring rather than patching [19].
Officials said the unauthorized access was detected and cut off in late June [3]. The public learned about it only this week, after a hacker claimed responsibility, at which point the tax authority imposed additional restrictions to prevent further unauthorized access [4]. Detection did not trigger disclosure; the attacker's own publicity did [20].
FrenchBreaches, a site that tracks data leaks in France, reported that the attack was claimed by a hacker using the alias ZeroBytes [8]. According to that account, the hacker said access to internal servers let them connect to the agency's VPN and use an internal tool to search for information on individuals and businesses, and that they began stealing data before the access was cut off [11][12]. If that description holds, the extraction was done with the agency's own lookup tooling working as designed, which is the hardest kind of activity to separate from routine work. The hacker claimed data on more than 600,000 people, including names and other personal information, tax identification numbers, email addresses, family circumstances and details about tax status [9]. Neither the claim nor the authenticity of the purportedly stolen data has been independently verified, and the DGFiP has not attributed the breach to a specific actor or confirmed the hacker's figures [10][13].
Authorities are still working out what was actually accessed and how many individuals and businesses are affected [5]. The DGFiP said those whose data was compromised will be contacted individually and told what may have been exposed and what precautions to take, and that it would notify France's data protection authority, file a criminal complaint and provide further information as the investigation continues [6][7].
This is not an isolated year for French public-sector data. In April, hackers targeted the website of the National Agency for Secure Documents, ANTS, which handles applications for passports, national identity cards, residence permits and driver's licences [14]. That same month, the Education Ministry disclosed that an attack on a system used to manage student accounts had exposed students' personal information [15]. In February, part of the National Bank Accounts File was breached, exposing information linked to roughly 1.2 million accounts out of more than 300 million entries, or about 0.4 percent of the database [16][17]. Earlier this year police arrested a 20-year-old suspected of carrying out dozens of breaches involving government bodies, sports federations and private companies [18].
Three things to watch. First, whether the DGFiP's eventual count lands near the claimed 600,000 or well away from it [9][5]. Second, whose identity was used: the ministry's statement does not say whether the credentials belonged to staff, a contractor or another connected party, and that distinction determines whether the fix is internal hygiene or supplier control [21]. Third, the notification timeline, since individual letters and the filing with the data protection authority will be the first externally checkable evidence of how wide the agency thinks the exposure runs [6][7].
Ranked by verification strength, evidence, and original report placement.
France's Economy Ministry said late Thursday that an attacker gained unauthorized access to systems at the Directorate General of Public Finances (DGFiP) in late June after stealing or misusing someone's identity.
According to the ministry, the intrusion allowed the attacker "to view and extract data belonging to individuals and businesses".
Officials said the unauthorized access was detected and cut off in late June.
The incident became public after a hacker claimed responsibility earlier this week, prompting the tax authority to impose additional restrictions to prevent further unauthorized access.
Authorities are working to determine precisely what information was accessed or stolen and how many individuals and businesses were affected.
The DGFiP said people whose data was compromised will be contacted individually and told what information may have been exposed and what precautions they should take.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Official confirmation, unverified scale
The core facts rest on an on-record Economy Ministry statement: identity-based entry, data viewed and extracted, detection and cut-off in late June, and committed next steps (individual notification, regulator notice, criminal complaint). Everything quantitative - 600,000 people, data categories, VPN and internal-tool tradecraft - is attacker-sourced via a leak-tracking site and explicitly unverified, and the cluster has only one publisher, capping the score well short of strong.
Confirmed incident, unquantified footprint
Real-world occurrence is not in doubt - the affected agency confirmed it and imposed additional restrictions - and it sits in a documented series of French public-sector incidents this year, which raises the pattern's weight. But the affected population is officially unknown, the only figure on offer is unverified, and the impact is confined to one national agency, so measured footprint stays middling.
Mildly overstated by the claimant's figure
Slightly positive. The most quotable number in circulation - 600,000 victims - originates with the attacker and is unverified, yet it anchors the headline framing while the agency has confirmed neither scale nor attribution. Offsetting this, the report labels the claim unverified in the same breath and the cluster's own framing (identity-based entry rather than an exploited bug) tracks the ministry statement precisely, so the gap is small rather than severe.
Claimant self-promotion plus reactive official disclosure
Moderate distortion pressure on both sides of the record, visible in the source itself. The scale and tradecraft narrative comes from an actor who benefits from appearing capable and whose data has not been authenticated, while the agency's public account emerged only after the attacker went public and stops short of attribution or victim counts. No sponsorship, vendor, or commercial interest is evident in the reporting.
Solid on cause, weak on magnitude
Confidence is high that an identity-mediated intrusion occurred and that data on individuals and businesses was extracted, because the affected ministry says so on the record and the sequence of dates and remedial steps is internally consistent. Confidence is low on magnitude, actor identity, and technical path, all of which rest on one unverified claimant relayed by one publisher with an investigation still open.
security
Intruders took donor emails from two Russian charities through a Stripe-WooCommerce integration1 distinct publisher
product
France's tax agency lost 678,000 records through logins it had issued itself1 distinct publisher
product
C-Track breach reached at least twelve judiciaries, including Ontario1 distinct publisher
security
The aim point was a peripheral: how US operators blinded Iran's air defenses1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 17, 2026
1 article · August 17, 2026
1 article · August 16, 2026
1 article · August 17, 2026
1 article · August 17, 2026
1 article · August 14, 2026