France’s tax administration confirmed on Friday that intruders stole taxpayer data in two separate incidents, one at the end of June and a second at the end of July. That first intrusion reached reference income data on at least 678,000 individuals and businesses.
The Direction générale des Finances publiques (DGFiP) counts 200,000 accounts in the second theft, which hit land registry records. A cybercriminal operating under the handle ZeroBytes claimed both on a darkweb data resale forum.
Neither figure is final. Investigators are working with the Agence nationale de la sécurité des systèmes d’information (ANSSI) to establish what the intruder took and whose records it covers.
What the June file contains
Individual records are sensitive by the DGFiP’s own description, covering names, quotient familial, revenu fiscal de référence, and withholding tax rate. Business records are less so, running mostly to SIREN numbers and public company addresses.
FrenchBreaches, the monitoring outlet that first published the claim, counted 392,867 individuals and 285,570 businesses in the file. Its review of a sample identified 26,805 individuals with a revenu fiscal de référence at or above €100,000 (US$115,700). Another 386 sat above €1 million (US$1.16 million), and eight above €10 million (US$11.6 million).
The DGFiP’s account differs on the split. Slightly more businesses than individuals appear in the affected population, the administration said, reversing the ratio FrenchBreaches published.
That income measure does specific work in French tax law. It sets the entry threshold for the contribution différentielle sur les hauts revenus, which tops household tax up to a minimum 20%. Single filers cross it at €250,000, couples at €500,000.
Wealth taxation has driven two years of budget fights in Paris. Deputies rejected both the Zucman tax and a Socialist alternative last November, days after narrowly voting down a tax on wealthy expatriates.
Paris private bankers and tax lawyers logged a 30% jump in calls from panicked clients around the July 2024 snap election. Bastien Trelcat, then managing partner of Harvey Law Group Thailand, gave the figure. Amélie de Montchalin, then budget minister, warned last year that the levy risked driving France’s wealthiest out.
Stolen VPN access to an internal search tool
ZeroBytes told the forum he acquired credentials for a virtual private network (VPN) used by tax officials. That opened an internal lookup tool covering both individuals and businesses, from which he automated an extraction of close to 680,000 rows before the connection dropped.

France’s finance ministry has confirmed the intrusion without endorsing that account. It blamed an identity theft, and said auditors cut the connection in late June.
The July 29 intrusion hit a different system: The Serveur professionnel de données cadastrales (SPDC), which handles land registry lookups. ZeroBytes claims he got past multifactor authentication (MFA) there, then abandoned the download because a full extraction would have run for months.
He puts the haul at 252,149 rows. A single parcel can carry several rights holders, so those rows represent 2,041,778 people by his count. DGFiP investigators stick to 200,000 accounts and say their analysis continues.
Cadastral records are less revealing than they sound, the administration argued. Obtaining detailed land registry data is “relatively simple” for anyone who justifies the request, it noted.
Six weeks between detection and disclosure
Officials acknowledged the June breach on Thursday. That was a day after the file went on sale, and they notified the Commission nationale de l’informatique et des libertés (CNIL) the following evening. Under the General Data Protection Regulation (GDPR), a controller has 72 hours from discovery to notify the supervisory authority.
Access ended in late June. The ministry said so on August 13.
Solidaires Finances Publiques, a union representing tax staff, called the communication late. Nothing official emerged until the August 12 claim and the press coverage that followed, the union said.
Affected users hear directly from the DGFiP starting next week. Each will receive a breakdown of what the intruder may have consulted or extracted, alongside any precautions the administration recommends.
Charlie Maggi, founder and CEO of The Open World, reads the response more favorably. “France reacted quite quickly by blocking the compromised access, launching an investigation, notifying the CNIL and informing the people affected,” he said.
France lost bank account and identity data earlier this year
In February, the finance ministry disclosed unauthorized access to FICOBA, the national register of bank accounts, covering at least 1.2 million accounts. A parliamentary question dated that access to late January 2026, through a civil servant’s stolen login.

Hackers hit the Agence nationale des titres sécurisés (ANTS) in April, the body that processes identity document applications. The interior ministry put that exposure at 11.7 million accounts.
Insiders have proved a weakness alongside external intruders. Prosecutors accused a tax official at the Bobigny office of using internal software to build profiles of cryptocurrency investors. She sold them on to criminals who used the addresses for physical attacks, they allege.
Aran Hawker, co-founder of CIP Turkey, reads both failures as one problem. “It’s all well and good when governments ask you for all kinds of personal data,” he said.
Insiders selling that data produced “life-changing, horrific events for the victims” in the crypto case, by his account. “How can they expect us to trust them with this sensitive information?” he asked.
Whether the state will hold itself to the standard it applies elsewhere is his second question. “Now that this has happened a second time in France, I wonder whether they will punish themselves for their own incompetence,” Hawker said.
“I’m sure they wouldn’t be very forgiving if a private company had these same consecutive breaches of data security, both internal and external,” he added. “Doesn’t inspire confidence, does it?”
Maggi sets the same case against what followed it. “After the recent kidnappings targeting crypto entrepreneurs and their families, measures were introduced to better protect personal information,” he said.
Those measures run to “allowing company directors to hide their home addresses from public corporate records, alongside increased security support for people considered at risk.” A decree created that right in August 2025, and a second one widened it in April 2026 to cover associates and filed documents.
“These are obviously separate incidents, but they highlight the same concern: When sensitive financial and personal data is exposed, the consequences can go well beyond privacy,” Maggi said. “France is clearly taking the issue seriously and strengthening both cybersecurity and the protection of individuals.”
What the file sells for
Whoever breaks into a system is rarely the one who defrauds the victims. Files change hands first, and ZeroBytes told AFP he wanted several thousand euros for the June data, declining to say whether a buyer had materialized.
He described himself to the agency as one of two people working together, with no motive beyond money.
Phishing is the immediate risk. A record pairs a taxpayer’s name and address with income, withholding rate, and past correspondence with the tax office. That combination lets a fraudster write a message the recipient has little reason to doubt.
The cadastral file carries a different exposure. It ties a named person to a specific parcel, which turns an income figure into an address.
Hawker’s advice to any high-net-worth individual (HNWI) sitting in the file runs to two options. “If I were a HNWI on the new list in France, I would be seriously looking at relocating to somewhere safer, or getting some security urgently,” he said.