"For around 250 people, the compromised information also included the messages themselves." — DGFiP
Scope and contents of the DGFiP breach
The General Directorate of Public Finances (DGFiP) updated the public this week after confirming a data raid that exposed a range of taxpayer and business information. DGFiP said lists of messages exchanged with the authority were exposed, and that for roughly 250 people the breach included the message contents themselves. Slightly more than 350,000 individuals were affected by the personal-data elements of the intrusion.
Beyond messages and lists, DGFiP reported exposure of tax identification numbers, marital status, email and postal addresses, and phone numbers. Tax records in the compromised set included household composition, number of dependents, family quotient, reference tax income, and withholding rates. DGFiP also said other datasets contained information that was already publicly available.
For approximately 250,000 businesses and professionals, the affected data was limited to company names and SIREN numbers, the nine‑digit identifiers assigned to French businesses. Compromised cadastral data was limited to property addresses and dimensions, which DGFiP stated were already publicly available.
Notifications, warnings, and service suspensions
DGFiP said it was notifying affected taxpayers by email or post this week and published a frequently asked questions briefing that pegs the total number of affected parties at roughly 600,000. The notification letters warn that criminals could use the stolen details to make phishing attempts appear more convincing, and DGFiP highlighted impersonation attempts, CEO fraud, and scams involving bogus bank advisers as possible follow-on attacks.
The authority reiterated that it would never ask taxpayers to provide sensitive information such as PINs or identity documents by phone, text message, or email, and would request such material only through its secure portal. Separately, DGFiP disclosed a "technical vulnerability" in the government's Vacant Successions Portal (PSV), suspended the service after discovering the flaw, and said there was no evidence so far that personal data had leaked while investigations continue into possible exposure of applicants' details.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildNumbers at odds: DGFiP, earlier statements, and attacker claims
DGFiP's latest figure of roughly 600,000 affected parties is lower than the 678,000 "individuals and professionals" the agency said were affected shortly after the incident was first disclosed last week. The authority did not explain the discrepancy between those two public figures. The alleged cybercriminal behind the attack, who uses the name "ZeroBytes," claimed to have stolen data belonging to more than 2 million people; that claim also appears larger than DGFiP's public totals.
This year’s pattern across France’s public sector
The DGFiP incident joins a string of public‑sector cybersecurity incidents reported in France earlier this year. In February the finance ministry — which oversees DGFiP — disclosed an intrusion into a database containing citizens' bank details that affected 1.2 million people. In March the Health Ministry confirmed that 15.8 million administrative files, including 165,000 files that contained doctors' notes, were stolen during an attack on healthtech company Cegedim Santé. In April an alleged 15‑year‑old carried out an attack on France Titres, which handles identity documents; the attacker claimed that breach affected between 18 million and 19 million people. In June authorities began probing an alleged breach of Tchap, the government's encrypted messaging platform, after attackers claimed access to 73,000 user accounts, 643,000 messages, and nearly 60,000 media files.
What this means for taxpayers, companies, and government IT
- Taxpayers: Those notified face an elevated phishing and impersonation risk because contact details and tax‑record elements were exposed. DGFiP’s specific warnings about impersonation, CEO fraud, and bogus bank‑adviser scams are aimed at reducing successful follow‑on social engineering.
- Businesses and professionals: For about 250,000 businesses the exposed items were limited to names and SIREN numbers; while that information is less sensitive than individual tax records, DGFiP’s disclosure shows how publicly facing identifiers can still be used in targeted social engineering.
- Government IT and oversight: The coexistence of multiple public totals (roughly 600,000, 678,000, and the attacker’s claim of over 2 million) and the suspension of the Vacant Successions Portal while investigators probe a technical flaw underline continuing operational and disclosure challenges for public bodies responsible for citizen data.
The DGFiP update is explicit about the categories of data exposed and about concrete steps — notifications, public guidance, and a suspended portal — that the authority has taken. It is equally explicit in leaving the tally unsettled: three competing numbers sit in public view without an explanation tying them together. As DGFiP continues its investigation and notifies affected parties, the coming days will determine whether the incident's operational impacts remain limited to social‑engineering risk or grow into a broader compromise of sensitive personal records.




