"We couldn't finish the extraction because honestly, it's just horrible to scrape and would have taken months. I'm still logged into the panel, so if you want, you can buy it along with the database," wrote the threat actor using the handle ZeroBytes in a post on the PwnForums hacking forum, a claim that prompted French authorities to disclose a large tax-authority breach on August 12, 2026.
ZeroBytes' claim on PwnForums
ZeroBytes posted a sale listing on PwnForums on August 12, 2026, asserting access to systems operated by the French tax authority and offering stolen databases for purchase. In that post the actor said they remained logged into an administrative panel and described the mechanics of scraping the data as time-consuming and "horrible" — a practical claim that coincided with the French Ministry of the Economy and Finance's discovery of unauthorized access to tax systems.
Data accessed from DGFiP systems
The Ministry of the Economy and Finance said investigations since August 12, 2026, "have established that, prior to their interruption, these access points had been used to consult and extract data concerning a total of 678,000 individuals and professionals." The ministry listed the types of tax data accessed: reference tax income, family quotient, and withholding tax rate. For businesses, data included company name and SIREN number. Cadastral data relating to addresses and property sizes were also accessed.
The ministry emphasized that online accounts of individual and professional users were not compromised and that "User IDs and passwords were not compromised." After detecting the attack, the French tax administration shut down access to sensitive information systems while it works to assess the full impact.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildAccess to the Serveur Professionnel de Données Cadastrales (SPDC)
ZeroBytes also claimed access to the Serveur Professionnel de Données Cadastrales (SPDC), a portal operated by the tax authority that provides access to the country's central land registry and property ownership records. According to the post, the portal gave access to data on roughly 20 million French citizens, although the actor said they managed to extract 252,149 records "containing data on over 2 million people" before stopping the process.
The threat actor added, "I'm not going to sell this one for very much anyway. And as always, no mention from France about this incident," an assertion that preceded the ministry's public disclosure and notification plans.
French response, regulatory notifications, and recent related incidents
Following discovery of the intrusion, the French Public Finances Directorate (DGFIP) notified the French Data Protection Authority (CNIL) and is investigating the incident with assistance from the National Cybersecurity Agency of France (ANSSI). The ministry said it will contact all affected individuals starting next week via email or letter, with details on what data may have been accessed or stolen and the precautions to take.
The ministry framed this breach as part of a sequence of recent cyber incidents affecting French government agencies. In January, the French data protection authority fined the national employment agency France Travail €5 million after hackers stole the personal information of 43 million people. One month later, the Ministry of Finance disclosed another breach affecting over 1.2 million user accounts after hackers stole a database from the national bank account registry (FICOBA) systems. More recently, France Titres disclosed a breach after a threat actor put up for sale a database containing 19 million records allegedly stolen from the National Agency for Secure Documents (ANTS).
What this means for technologists and security teams, policymakers and regulators, and affected individuals and professional users
- Technologists and security teams: The ministry's shutdown of sensitive systems and its joint investigation with ANSSI signal a forensic and containment phase. Teams responsible for tax-adjacent systems will likely watch for indicators tied to the access points ZeroBytes described and evaluate controls around cadastral and tax-data extractability.
- Policymakers and regulators: CNIL has been notified; regulators will be directly engaged as notifications go out to affected people. The sequence of recent disclosures — including a €5 million fine tied to the January incident — underscores regulator-driven consequences and follow-up scrutiny.
- Affected individuals and professional users: The ministry will contact those impacted by email or letter starting next week with specifics on exposed fields and recommended precautions. The ministry's statement that user IDs and passwords were not compromised narrows the immediate account-security advice, but cadastral, tax and company-identifying fields were among the exposed data.
Investigations are ongoing and the ministry has restricted access to the systems in question while working with ANSSI to determine the full scope. The next concrete actions announced by the government are the planned individual notifications and the continued forensic work to assess cross-system impact.




