Summary
- Attackers used identities belonging to a DGFiP employee and an authorised third party during unauthorised access in June and July.
- Investigators later established that fiscal information concerning 678,000 individuals and businesses had been consulted and extracted.
- The incident left a gap between terminating unauthorised access and establishing whether data had already been removed.
France’s tax authority has confirmed that information concerning 678,000 individuals and businesses was extracted from its systems after attackers used impersonated credentials belonging to an employee and an authorised third party.
The Direction générale des Finances publiques said the unauthorised accesses took place during June and July, although the incident became public after a malicious actor claimed responsibility on 12 and 13 August. Access associated with the affected identities was terminated when the activity was detected.
Those initial interventions did not establish that information had already left the environment. More detailed investigations beginning on 12 August subsequently found that the accesses had been used to consult and extract records relating to 678,000 private individuals and professionals before containment.
The exposed fiscal information includes reference taxable income, family quotient data, and withholding-tax rates. Business information includes corporate names and SIREN identifiers, while cadastral records covering property addresses and surface areas were also consulted.
DGFiP has drawn a boundary around the affected systems. The public impots.gouv.fr service and the personal and professional Finances publiques account areas were not compromised, while the usernames and passwords used by individual and business taxpayers were not exposed. The intrusion instead involved identities that already had authorised access to internal information.
The authority notified French data protection regulator CNIL after establishing that information had been stolen and introduced additional security measures, including preventive restrictions around access to sensitive systems. Investigations are continuing to determine the precise composition and volume of extracted data and the final number of people and organisations affected.
Stopping a suspicious session does not establish what took place before containment. An organisation may block an account or terminate access promptly while still needing forensic work to reconstruct which records were queried, collected, or removed during the period in which the identity remained active.
That reconstruction becomes harder where an attacker operates through accounts with legitimate permissions. Authentication establishes that a recognised identity has reached a system; it does not establish that every action performed through that identity is legitimate. Monitoring therefore has to account for behaviour, data access patterns, privilege use, and unusual activity inside otherwise authorised sessions.
The involvement of an authorised third-party identity also extends the security boundary beyond the authority’s own workforce. Contractors, suppliers, advisers, and other external organisations can require meaningful access to government systems, placing their identities inside the same control environment as internal employees.
For a tax authority, the information involved remains sensitive even without account passwords. Income data, withholding rates, family information, business identifiers, and property records can provide a detailed picture of individuals, households, and organisations, increasing the consequences of unauthorised extraction.
The Finance Ministry’s incident notice says affected people and businesses will be contacted individually with information on the data that may have been consulted or extracted. DGFiP also intends to file a criminal complaint.
The final scope may change as the investigation continues, but the confirmed sequence is already substantial: authorised identities were misused, access was eventually stopped, and later forensic work established that a significant volume of government-held information had been extracted before containment.



