DGFiP Breached by ZeroBytes: Inside France's Biggest Tax Data Leak of 2026
> TL;DR: The DGFiP (France's tax authority, operator of impots.gouv.fr) confirmed on August 13, 2026 an unauthorized intrusion into its information system that began in late June through impersonated agent credentials. An attacker going by ZeroBytes claims to have extracted 678,438 individual and business records in a first intrusion, then accessed the professional cadastral data server (SPDC) with 252,149 records corresponding to more than 2 million people. It's one of the largest breaches ever suffered by a French government agency.
Timeline
Late June 2026: An attacker impersonates an agent's credentials to access an administrative VPN, then reaches an internal lookup tool covering individuals and businesses. The connection is cut during a routine security check, but the session had already allowed the attacker to view and extract data.
Late July 2026: A second intrusion targets the Serveur Professionnel de Données Cadastrales (SPDC), a professional cadastral data system normally reserved for authorized professionals (notaries, surveyors, local authorities).
August 12-13, 2026: ZeroBytes publicly claims the attack. The DGFiP confirms the incident the following day via an official statement from the Ministry of Economy, restricts access, and opens a joint investigation with ANSSI (France's cybersecurity agency) and the Haut fonctionnaire de défense et de sécurité (SHFDS).
August 14-20, 2026: The breach-monitoring site FrenchBreaches details the scope of the cadastral leak. A criminal complaint is filed and CNIL, France's data protection authority, is notified. Affected individuals are to be contacted once the exact scope is determined.
Attack vector: nothing exotic
Based on public information, this attack did not rely on a spectacular zero-day vulnerability: a single compromised agent credential (phishing, password reuse, or an earlier leak) was enough to get through a VPN access point that did not enforce MFA on every account at the time. Once inside, the attacker was able to query and export data using the privileges already granted to the impersonated account, without triggering any mass-extraction detection.
Data exposed
Note: the highest figures (up to 20 million people mentioned by the attacker for the full SPDC scope) come from the hacker's own claims, relayed by breach-monitoring sites, and remained officially unconfirmed by the DGFiP at the time of writing.
What this reveals about public-sector cybersecurity
Multi-factor authentication was not enforced across the board on administrative VPN access — a year after NIS2 entered into force, which requires strengthened authentication measures for covered entities.
Agent accounts had overly broad access to databases holding tens of millions of records, with no segmentation by geographic or functional scope — the same structural flaw we documented in our France Travail breach analysis.
No automated alert stopped the mass extraction before the volume became significant. An account that exports hundreds of thousands of records within hours should trigger an immediate alert, not be discovered after the fact.
What CleanIssue checks for
This type of incident — compromised credentials, no MFA on sensitive access, overly permissive access control, no detection of abnormal extraction — is exactly what we test during an external review: authentication bypass attempts, verification of least-privilege on privileged accounts, and the presence (or absence) of guardrails against mass data exfiltration.
Key takeaways
Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
Free 2024: 24 Million Accounts Exposed, IBANs Included, and CNIL's Record Fine
A look back at the October 2024 Free/Free Mobile cyberattack: 24 million contracts exposed, IBANs leaked for dual-play subscribers, and the 42 million euro fine imposed by CNIL for security failures.
France Travail 2024: 43M French Citizens Leaked, What Really Happened
Technical breakdown of the France Travail data breach in 2024: how 43 million records were exposed, timeline, and lessons learned.
SFR 2024-2025: Two Breaches in One Year, the Second via an Internal Management Tool
SFR suffered two separate security incidents in under 18 months: a breach affecting 3.6 million customers in September 2024, then a new compromise in late 2025. What both episodes reveal about the risk of internal tools.
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.