France Confirms DGFIP Breach; Hacker Claims 600K
France's tax authority confirms unauthorized access in late June via credential theft. A threat actor claims 600,000 records stolen. Investigation ongoing.

Confirmed. France’s Directorate General of Public Finances — Direction générale des finances publiques, DGFIP — acknowledged unauthorized access to its systems in late June 2026. The Record broke the confirmation today.
Status
Access confirmed. French authorities state that someone gained unauthorized entry to DGFIP systems in late June by stealing or misusing employee identity credentials. Account compromise — not a disclosed software vulnerability.
600,000 victim claim. Unconfirmed. The threat actor asserts 600,000 individuals are affected. DGFIP has not verified that figure. Treat as adversary claim pending independent corroboration.
Data exfiltrated. Not confirmed publicly. DGFIP has not disclosed what records, if any, were removed from its systems.
Why This Matters
DGFIP administers tax collection, public accounting, and financial management for the French state. Its databases hold tax returns, income declarations, and financial disclosure data for individuals and businesses across France. If the 600,000 figure holds, this ranks among the larger government-sector data exposures in Western Europe in 2026.
The entry vector — credential misuse, not a zero-day — is the same playbook seen repeatedly this year: acquire working credentials, authenticate legitimately, operate quietly. Harder to detect than exploit chains and outside most automated vulnerability-scan coverage entirely.
What’s Not Confirmed
- The 600,000 figure is the attacker’s claim, not verified by DGFIP or independent investigators.
- Whether exfiltrated data includes personally identifiable information, financial records, or both.
- The identity or affiliation of the threat actor.
- Whether access reached internal systems only or also external-facing portals used by taxpayers.
What to Watch
GDPR imposes a 72-hour breach notification window once a data controller confirms personal data exposure. If DGFIP concludes personal data was exfiltrated, a formal notification to France’s CNIL data-protection authority follows — triggering additional mandatory public disclosure.
Active investigation. No attribution announced.
Also developing today: RingCentral Breach — ShinyHunters Claims 1.6M Accounts. Earlier: Trezor — 14,000 Customers Exposed via ShipMonk.
Found this useful? Share it.


