An alleged database containing details for more than 2 million French taxpayers was advertised this week by a user calling themselves "ZeroBytes," who claimed to have extracted the files from the General Directorate of Public Finances (DGFiP) in June and to have used stolen credentials and an MFA bypass to do so.
DGFiP confirms unauthorized June access, says audit severed it
The French Public Finances Directorate acknowledged the incident in a statement released Thursday, disputing the seller's claim of ongoing access while confirming that an intruder had accessed its systems at the end of June 2026. As DGFiP put it: "On Wednesday, August 12, 2026, a malicious actor claimed unauthorized access to the information system of the French Public Finances Directorate, which occurred at the end of June 2026 following identity theft."
DGFiP added that "initial investigations confirm that this access, which had been severed at the end of June as part of an audit, nevertheless allowed the consultation and extraction of data concerning individuals and professionals." The directorate said it immediately implemented "new restrictions to stop the unauthorized access and prevent further unauthorized use" and that "in-depth investigations are ongoing to determine precisely which data and number of users were affected."
What ZeroBytes is claiming on the cybercrime forum
Using the alias "ZeroBytes," the alleged attacker posted on a cybercrime forum on Wednesday and offered a purported database of more than 2 million French taxpayers for sale. The post, as summarized by reporting, included claims that the intruder had used stolen credentials and an MFA bypass technique to gain entry. The vendor also asserted that they retained access to DGFiP systems and offered to sell that continued access alongside the dataset.
DGFiP did not immediately answer questions about the attacker's full set of claims but explicitly disputed the assertion that the actor still had access to its systems.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleNotification and regulatory steps: CNIL and affected users
DGFiP said it will report the incident to France's data protection regulator, CNIL, and will notify affected users "once it had determined who they were." That process follows the directorate's internal investigation into which data were consulted and extracted and its implementation of further restrictions after the intrusion was discovered and cut as part of an audit at the end of June.
Context: part of a wider run of breaches in France's public sector in 2026
This intrusion is the latest public-sector security incident revealed in France during 2026. Earlier in the year, the Ministry of Finance — the ministry that oversees DGFiP — acknowledged in February that miscreants had accessed a database containing French citizens' bank details. According to reporting, attackers used stolen credentials and removed 1.2 million records, despite the ministry saying it quickly revoked their access.
A few weeks after that disclosure, the Health Ministry confirmed a cyberattack on healthtech supplier Cegedim Santé in which around 15.8 million administrative files were stolen; roughly 165,000 of those files contained doctors' notes that in "very limited cases" revealed medical histories. In April, the Interior Ministry confirmed reports that France Titres — the agency responsible for identity documents including passports and driver's licenses — had been attacked; an alleged culprit, reportedly a 15-year-old, advertised stolen data and claimed the breach affected between 18 million and 19 million people. In June, the department responsible for Tchap investigated a suspected breach in which alleged attackers claimed to have accessed more than 73,000 user accounts, 643,000 messages, nearly 60,000 media files, and hundreds of chat rooms.
What this means for taxpayers, regulators, and security teams
- Taxpayers: Individuals and professionals whose data may have been "consulted and extracted" will be notified by DGFiP once the directorate identifies who was affected. Those potentially impacted will need to await that formal notification for details on what categories of information were exposed.
- Regulators (CNIL): DGFiP has said it will report the incident to CNIL. The regulator will now receive the directorate's findings as they determine "precisely which data and number of users were affected," and any regulatory follow-up will be grounded in that disclosure.
- Security teams in government: The incident underscores that DGFiP severed access during an audit but still found that data had been extracted. Government security teams are likely to scrutinize identity-theft vectors, credential protection and multi-factor authentication implementations, and audit controls to understand how the access occurred and what additional restrictions were required to block further misuse.
DGFiP's public admission narrows one part of the record: an intrusion occurred at the end of June and was cut as part of an audit. But key details remain pending the directorate's in-depth investigation and its notification to CNIL and affected users — notably the precise datasets removed and the final tally of individuals and professionals whose information was exposed. Until those findings are published, the claim by "ZeroBytes" that they still have access and the size and contents of the advertised 2 million-record database remain allegations from the posting on a cybercrime forum.




