France's tax authority knew in late June. You found out on 13 August
In February, the French tax authority had 1.2 million records stolen from FICOBA, the national register of French bank accounts, using one officer's credentials. In late June, it had 678,000 tax files stolen using one officer's credentials. In between, the Prime Minister announced 200 million euros for the state's cybersecurity.

In February, the French tax authority had 1.2 million records stolen from FICOBA, the national register of French bank accounts, using one officer's credentials.
In late June, the French tax authority had 678,000 tax files stolen using one officer's credentials.
In between, on 30 April, the Prime Minister announced 200 million euros for the state's cybersecurity, from the offices of the agency for secure documents, which had just lost 11.7 million accounts.
The whole case is there. The rest is volume and commentary.
What happened
In late June, an actor calling themselves ZeroBytes got hold of an authorised officer's credentials. From there: compromise of internal servers, VPN access, then use of an internal tool for querying the files of individuals and businesses.
No exotic flaw, no novel exploit, nothing that justifies the word « sophisticated » that has been so widely used this week. They walked in through the door, with someone else's keys, and used the tool designed for consulting files in order to consult files.
Access was cut on the day it was detected, during a check. That is the only good news in the case, and it is why they walked away with 678,438 rows rather than ten times more. Just under 393,000 concern individuals, the rest businesses whose information is largely public.
The contents of a record: name, birth name, used name, date and place of birth, tax address, mailing address, family situation, spouse's identity, composition of the tax household, family quotient, reference tax income, withholding rate.
The reference tax income changes what the object is. A contact list is for sending mass emails and hoping 0.5% of recipients click. A list sorted by declared income to the euro is for choosing who you are going to go after. A tax file is a shopping list.
The seven weeks in which nothing happened
The intrusion dates from late June. Detection was fast, since access was cut the same day. The public learned of it on 13 August, the day after the attacker put it up for sale.
Seven weeks. Here is what can be observed over that period.
No communication. The administration's first public word came after the claim on a criminal forum and the release of a free sample. Without that publicity stunt by the seller, the disclosure date remains unknown.
Notification to the regulator and the filing of a complaint appear in the 13 August statement in the future or present tense, not the past. The GDPR allows 72 hours from becoming aware of the breach. Seven weeks is not 72 hours. It is the only point in this case where a penalty is legally conceivable, and it is the one nobody is discussing.
Individual notification of victims is only just beginning, while those people have been living since late June with monetisable data in the wild, without knowing they should be on their guard.
And on 14 August, the same pseudonym claimed a second intrusion, dated 29 July, on the professional land registry server. 252,149 rows according to them, corresponding to more than two million people since a plot can have several holders. That part is unconfirmed and the figures are the seller's, who has an interest in inflating them. But if the date holds, it says the essential thing: a month after being detected and cut off, the same actor came back through another door of the same house.
This is not a resources problem. A month is short for overhauling identity management. It is more than enough to tighten access to sensitive applications when you have just been caught.
What staggers me
Not the hack. We will be caught out again, myself included. Zero risk does not exist and we have been saying so for twenty years.
The same administration had already been caught four months earlier by the same kind of vector. In February, the finance ministry confirmed illegitimate access to the national register of bank accounts, roughly 1.2 million accounts potentially exposed, obtained through an officer's credentials acquired fraudulently.
Between February and late June, somebody at the tax authority knew exactly which door had been used, on what type of account, with what consequences. This was not a discovery waiting to be made, it was an open case with a real victim and a documented attack chain.
The tax authority is not a small structure you secure in a quarter. Several hundred digital products in production, thousands of IT staff, systems covering up to forty million users. Rolling out strong authentication on every privileged account, removing inherited generic accounts, detecting abnormal extractions on business applications that are twenty years old, these are multi-year programmes. Nobody serious will claim it was achievable in eighteen weeks.
What was achievable was prioritising the exact type of access that had just been used. That was arbitrated against something else. There is a committee minute, a tracking sheet, an email. It is not classified, it is ordinary governance, and nobody will ask for it.
Compliance worked perfectly
Access cut on detection. Regulator notified. Complaint filed. National agency and senior defence official mobilised. Additional restriction measures. Paris prosecutor seized on 15 August, investigation entrusted to the anti-cybercrime office. Individual notification under way.
Flawless. The manual was followed, with the right counterparts.
And your data is out there, for sale, exploitable for years.
We have built a considerable regulatory apparatus that measures the quality of the reaction after an incident, and that has no grip on what would have prevented the extraction. You can tick every GDPR box and remain exactly as open as you were the night before. The tax authority has just demonstrated this at full scale, with 678,000 people as witnesses.
Those who sell compliance as though it were security should look at this case for a long while. So should those who buy it.
The scams that are coming, precisely
This data is not for emptying your account. It is for making a message credible. Here is what will be built with it.
The fake breach notification. The most immediate, and it will be well made. An email or text telling you that you are affected by the tax authority breach, with a link to « check whether your data is exposed ». Genuine individual notification is going out right now, which gives the fakes perfect cover.
The fake refund. The great tax classic, made formidable by the contents of the file. A message quoting your exact reference tax income and withholding rate, announcing an overpayment to reclaim. You check against your tax notice, the figures match, you enter your bank details.
The fake tax officer. On the phone, with your family situation, your address and your income. Pretext: urgent adjustment, calculation error, audit under way. The goal is an immediate transfer or the entry of a code received by text.
The fake bank adviser. The costliest fraud in France, and the tax breach gives it exactly what it lacked. Someone who knows your declared income and your household passes the credibility test in ten seconds. What follows is always the same: a fraudulent transaction to cancel, a code to confirm, a security transfer to make.
Administrative identity theft. The file contains precisely the fields requested when opening an account or a credit line: birth name, date and place of birth, address. Account openings, consumer credit, phone contracts, remote subscriptions. You will only find out when a payment is missed.
Mobile line hijacking. Birth name and place of birth are the answers to most operators' security questions. A hijacked line means receiving your one-time codes, and therefore access to your accounts protected by text message.
Cross-referencing with earlier breaches. This is where it gets serious. Free, SFR, Bouygues, the secure documents agency, the employment agency, sports federations, Bloctel. Aggregate them and you get identity, address, phone, email, identity document number, employer or employment status, and now income. The file is nearly complete, and it belongs to nobody but whoever assembles it.
Physical targeting. For households appearing with high incomes, the risk leaves the screen. The file contains more than 26,000 declarations above 100,000 euros and a few hundred above a million, with the address alongside. Reconnaissance, burglary, extortion. France has already seen kidnappings organised from lists of this kind in the cryptocurrency world. The mechanics are identical, the list is simply better.
Social targeting. At the other end, a high family quotient identifies a large family and a low income identifies someone eligible for benefits. Scams around social benefits, training accounts and energy grants already work very well without data. With it, the conversion rate changes scale.
This data does not expire. An address changes, an income moves, but a birth name and a place of birth follow you to the end. The file will still be in use in five years.
What every incident this summer has in common
Tax authority, hijacked officer account. Education ministry in late July, hijacked professional account, covering staff who have worked in a regional education authority since 2001. Scalingo, administrator account on an internal tool, roughly 90,000 people. Santé publique France, hosting provider, 80,000 people. The French handball federation, 1.36 million members with identity cards and passports, which nobody discussed even though it is the worst data set of the period.
Not one of these intrusions is an exploit against the victim organisation's exposed perimeter. They are legitimate access turned against its owner, or dependencies nobody monitors because they belong to somebody else.
That is exactly what the NIS2 directive targets with its obligations on identity management and supply chain security. The framework exists, it names the problem correctly, and it prevented nothing.
What is being asked of French citizens meanwhile
On 14 August, the day the finance ministry set out the scale of the tax breach, the Constitutional Council struck down the first article of the law banning social media for under-fifteens. Among the grounds cited, the absence of sufficient privacy safeguards, the legislature having failed to determine the conditions and limits of the age verification imposed on all users.
Two decisions on the same day on the same underlying question: this state's capacity to collect, centralise and protect identity data. The answer arrived through both doors at once.
And it continues. Digital identity, electronic invoicing, age verification which will return in another form, declaration of crypto wallets. Always more collection, always more centralisation, always the same promise that it is for your protection. According to Surfshark, France recorded 23.5 million compromised accounts in the first quarter of 2026 alone, second in the world behind the United States.
Before building cathedrals, one ought to know how to keep a wall standing.
The only question that matters
Between February and June, who saw this risk, how far up it travelled, and what it was arbitrated against.
Nobody will ask. There will be an audit, a plan, a budget. The plan will contain sound measures, and it will also contain, almost certainly, actions already listed as priorities in the one from 30 April, which itself repeated programmes announced earlier.
The statement for the next breach is already written. It is missing the date, the name of the service and the number.
Frequently asked questions
How do I know if I am affected by the tax authority breach?
The tax authority is contacting affected people individually. If you receive nothing, you are probably not in the file. A genuine message from the administration will never ask you to click to check your situation or to enter your credentials. If in doubt, go to impots.gouv.fr directly by typing the address yourself.
Was my personal impots.gouv.fr account hacked?
No. According to the administration, users' personal accounts were not compromised. The extraction went through an internal, staff-side tool, using the credentials of an authorised person.
Why is the reference tax income so sensitive?
It gives your declared income to the euro. Cross-referenced with your address and household composition, it allows an entire population to be sorted by wealth and targets to be selected. That is what distinguishes this breach from a leak of email addresses, and what makes it exploitable for years.
Which scams will I receive first?
A fake breach notification, a fake tax refund quoting your real figures, a fake tax officer on the phone, a fake bank adviser. The common thread: the person contacting you will know information only the administration is supposed to hold, which dissolves your caution in seconds.
What should I actually do?
Never handle a request through the channel it arrived in. Hang up, look up the official number yourself, call back. No administration and no bank will ask you for a transfer, a code received by text, or your credentials over the phone. Enable two-factor authentication on your main mailbox and your bank accounts, through an app rather than by text.
Should I change my passwords?
That is not the priority here, since user accounts were not affected. The protective move in this specific case is vigilance about incoming messages and two-factor authentication.
How would I know if my identity has been used fraudulently?
Watch your bank statements and switch on your bank's alerts. You can also exercise your right of access to the national register of consumer credit repayment incidents, held by the Banque de France, to check that no credit has been taken out in your name.
Has the land registry part been confirmed?
No. It is claimed by the attacker and has not been officially confirmed. The figures circulating on that scope, including the two million people threshold, come from the seller, who has a direct commercial interest in presenting them as high as possible.
Did the tax authority comply with the GDPR?
On informing the public, there is no legal obligation to issue a press release, so the accusation of concealment that circulated widely does not hold legally. On notifying the regulator, however, the deadline is 72 hours from becoming aware of the breach. An intrusion detected in late June and a notification in August would pose a real compliance problem, and that is the only angle on which follow-up is conceivable.
Can I obtain compensation?
You can report the facts to cybermalveillance.gouv.fr, declare card fraud through Perceval, and file a complaint with the regulator. Class actions generally appear after this kind of incident. In practice, compensation for moral damage without proven fraud remains difficult to obtain before French courts.
Will this happen again?
Yes. The vector used here, the hijacking of legitimate access, recurs in nearly every incident this summer, in the public sector as in the private. As long as the question asked after an incident concerns the size of the budget rather than the chain of decisions that left the risk open, the cycle will repeat unchanged.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
