Back to blog
Famous hacksFrancedata breachGDPR

DGFiP Breached by ZeroBytes: Inside France's Biggest Tax Data Leak of 2026

Published on 2026-08-207 min readCleanIssue

> TL;DR: The DGFiP (France's tax authority, operator of impots.gouv.fr) confirmed on August 13, 2026 an unauthorized intrusion into its information system that began in late June through impersonated agent credentials. An attacker going by ZeroBytes claims to have extracted 678,438 individual and business records in a first intrusion, then accessed the professional cadastral data server (SPDC) with 252,149 records corresponding to more than 2 million people. It's one of the largest breaches ever suffered by a French government agency.

Timeline

Late June 2026: An attacker impersonates an agent's credentials to access an administrative VPN, then reaches an internal lookup tool covering individuals and businesses. The connection is cut during a routine security check, but the session had already allowed the attacker to view and extract data.

Late July 2026: A second intrusion targets the Serveur Professionnel de Données Cadastrales (SPDC), a professional cadastral data system normally reserved for authorized professionals (notaries, surveyors, local authorities).

August 12-13, 2026: ZeroBytes publicly claims the attack. The DGFiP confirms the incident the following day via an official statement from the Ministry of Economy, restricts access, and opens a joint investigation with ANSSI (France's cybersecurity agency) and the Haut fonctionnaire de défense et de sécurité (SHFDS).

August 14-20, 2026: The breach-monitoring site FrenchBreaches details the scope of the cadastral leak. A criminal complaint is filed and CNIL, France's data protection authority, is notified. Affected individuals are to be contacted once the exact scope is determined.

Attack vector: nothing exotic

Based on public information, this attack did not rely on a spectacular zero-day vulnerability: a single compromised agent credential (phishing, password reuse, or an earlier leak) was enough to get through a VPN access point that did not enforce MFA on every account at the time. Once inside, the attacker was able to query and export data using the privileges already granted to the impersonated account, without triggering any mass-extraction detection.

Data exposed

  • First intrusion (impots.gouv.fr): roughly 678,000 records, including ~393,000 individuals and ~286,000 businesses/professionals — identity, tax ID, withholding tax rate, reference tax income, contact details.
  • Second intrusion (SPDC, cadastral data): 252,149 records claimed, corresponding according to the attacker to more than 2 million people (a single property can have multiple co-owners) — names, dates of birth, addresses, MAJIC property identifiers, cadastral sections and parcels, links between co-owners.
  • Third breach (August): the vacant estates portal was also reportedly accessed.
  • Note: the highest figures (up to 20 million people mentioned by the attacker for the full SPDC scope) come from the hacker's own claims, relayed by breach-monitoring sites, and remained officially unconfirmed by the DGFiP at the time of writing.

    What this reveals about public-sector cybersecurity

    Multi-factor authentication was not enforced across the board on administrative VPN access — a year after NIS2 entered into force, which requires strengthened authentication measures for covered entities.

    Agent accounts had overly broad access to databases holding tens of millions of records, with no segmentation by geographic or functional scope — the same structural flaw we documented in our France Travail breach analysis.

    No automated alert stopped the mass extraction before the volume became significant. An account that exports hundreds of thousands of records within hours should trigger an immediate alert, not be discovered after the fact.

    What CleanIssue checks for

    This type of incident — compromised credentials, no MFA on sensitive access, overly permissive access control, no detection of abnormal extraction — is exactly what we test during an external review: authentication bypass attempts, verification of least-privilege on privileged accounts, and the presence (or absence) of guardrails against mass data exfiltration.

    Key takeaways

  • MFA must be enforced on every privileged access point, without exception — an unprotected administrative VPN is a direct gateway to the entire information system.
  • Least privilege mechanically limits the scale of a compromise: a single agent account should never be able to query an entire national database.
  • Mass-extraction detection (volume, frequency, unusual hours) must be a baseline control, not an afterthought — it's often the difference between a contained incident and a multi-million-victim breach.
  • Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.

    Need an external review of your HR SaaS?

    Share your product, stack, and client context. We will come back with the right review scope.

    Discuss your audit