Skip to content

Invest2 publishers3 min readPublished

France logged fake crypto support calls five months before the tax breach began

Meria's Owen Simonin ties a wave of calls impersonating Binance and his own support desk to France's pile-up of data leaks. The state cyber agency was already recording the same script in January, before the DGFiP intrusion.

The Investor · Invest desk

Illustration accompanying France logged fake crypto support calls five months before the tax breach began

What happened

  • Owen Simonin, founder of the French platform Meria, said in a September 20 post on X that a wave of calls from people posing as exchange support staff follows France's run of data breaches.
  • The callers have impersonated Binance support and Meria's own staff, telling holders their account is compromised and that funds must move at once to a wallet the caller supplies.
  • France's tax authority said in mid-August that an intruder had used a stolen identity to pull personal and tax records, in a breach that began in late June and was closed by the end of that month.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • exposure A holder whose number sat in the tax file can be called by someone who already knows their address, birth details and tax ID, so the identity questions a support desk would ask are answerable by the caller.
  • cost Simonin expects generative tools to cut the cost of each attempt, and the payout per success is a whole wallet balance, which stands where a card payment would be reversed.
  • constraint Recovery after transfer is rarely possible, so the loss lands on the holder, and the call itself is the only place to stop it.

A cold-calling operation spends most of its money dialling people who turn out not to own crypto. A leaked tax file removes that waste. The fields the DGFiP said may have been exposed include names, birth information, addresses, phone numbers, email addresses and tax ID numbers [7]. Cross-reference those against other leaks and you have the holders and the platforms they use, Simonin said [5]. The script that follows is short. The caller says the account is compromised, and the fix is to move the funds straight to a secure wallet that belongs to the caller [1].

The dates point to more than one cause. Cybermalveillance.gouv.fr flagged the same pattern on January 22, when its 17Cyber help line was inundated with reports from holders contacted by fake crypto operators and fake bank anti-fraud desks [9]. The DGFiP intrusion began in late June and was closed by the end of that month [6], about five months later [1]. Whatever fed the January calls was already in circulation. Crowdfund Insider reported that separate accounts have described large commercial lists of French crypto users circulating in underground markets [19].

"We're going through a phase where data leaks are piling up in private companies as well as in the public sector," Simonin wrote in French, according to X's translation [4]. On the size of the exposed pool the two publishers differ. Cryptopolitan put the estimates at 678,000 taxpayers up to millions of people [7], and Crowdfund Insider said officials confirmed records belonging to hundreds of thousands of taxpayers [8]. Read "millions" as two million and the top end is about three times the 678,000 floor [2].

The violent route costs more than the phone route. Pavel Durov said in April that France had seen 41 kidnappings of crypto holders in the first three and a half months of 2026 [12]. Interior Minister Laurent Nuñez counted 77 kidnappings, unlawful detentions, extortions or attempts linked to crypto by the end of June, against 45 in all of 2025 [13]. That is roughly 36 more incidents in about two and a half months, or some 14 a month [4]. About 200 people have been arrested after attacks or in preventive operations [14], about 2.6 for every recorded incident [5]. The phone scams run alongside those attacks [15].

In my view the data is the scarce input and the tax records are the cheapest version of it so far. The counter-thesis is that the lists were always commercial and sourced from the platforms themselves, in which case the public-sector breaches change little and the January bulletin supports that reading [9]. The one named thread that could settle provenance is the preliminary investigation into the crypto firm Waltio, run by the Paris prosecutor's cybercrime section and the national gendarmerie cyber unit [11]. Neither publisher reported how much money the callers have taken [6].

Simonin has warned that generative tools will make these campaigns cheaper and more scalable, letting attackers automate the outreach and refine the scripts at speed [17]. Once coins leave a victim's wallet, recovery is rarely possible, Crowdfund Insider reported [18].

What to watch

  • Whether the DGFiP revises its exposure count above the 678,000 taxpayer floor, which would reprice the size of the callable list.
  • Whether the preliminary investigation into Waltio by the Paris prosecutor's cybercrime section produces findings on where the crypto-holder lists originated.
  • Whether any French authority puts a euro loss figure on the fake-support calls, the way it has counted violent incidents.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories