Massive data leak from the French tax authority: 678,000 taxpayers at risk

The French tax authority (DGFiP) has officially confirmed a large-scale data breach. As a result of unauthorized access to information systems, the attacker obtained personal data on 678,000 taxpayers, including information on income and real estate. This event is already being called one of the most serious leaks in the history of the French fiscal system.
Incident Details
The attack was carried out between June and July 2026. The attacker used compromised credentials belonging to a DGFiP employee and an external contractor. After penetrating the internal network via VPN, the hacker gained access to search tools and initiated an automatic data export. The process was only stopped after forced access termination.
Notably, an initial review following the detection of suspicious activity did not reveal signs of a leak. The authority attributed this to the high complexity and sophistication of the attack, which was likely planned with internal security protocols in mind.
The stolen data includes individual tax returns (income, family quotient, withholding rates), as well as corporate information, including company identification numbers (SIREN). Additionally, the attacker gained access to cadastral records with addresses and floor areas of real estate properties. It is important to note that taxpayer account login credentials and passwords were not compromised.
Data Publication and Scope of the Leak
The incident became public on August 12, when a user under the pseudonym ZeroBytes put the database up for sale on a criminal forum for several thousand euros. The attacker claimed to have exported 678,438 rows and emphasized that this was only part of the data obtained. An analysis conducted by the specialized resource FrenchBreaches showed that the database contains records on 392,867 individuals and 285,570 legal entities. Among the victims are 26,805 people with an annual income exceeding €100,000, 386 people with an income over €1 million, and eight with an income exceeding €10 million.
In addition to financial indicators, the leak contains taxpayer identification numbers, dates and places of birth, addresses, marital status, contact details, and history of interactions with the tax service. ZeroBytes also claims to possess data on tens of millions of citizens, although these statements have not yet been officially confirmed.
Threat to Cryptocurrency Holders
This incident poses a particular danger to the crypto community. France remains the global epicenter of so-called wrench attacks — violent assaults aimed at forcing the transfer of digital assets. According to Chainalysis, 30 such attacks were recorded in the country in the first half of 2026, compared to 19 for the entire year of 2025. The cumulative damage from such crimes worldwide has already exceeded $30 million.
The leak combined two critical types of data that criminals use to prepare attacks: the victim's income level and physical address. Analysts have identified exactly such leaks as the main catalyst for the surge in violent crimes in the country. Previously, in 2024, a tax service employee was caught selling files on wealthy cryptocurrency asset holders, which led to an increase in attack frequency from 1.9 to 4.6 cases per month.
Although the current leak contains no direct indications of cryptocurrency ownership, experts warn of a likely surge in targeted phishing. DGFiP has already notified CNIL and plans to contact law enforcement. The investigation is being conducted jointly with SHFDS and ANSSI, and on August 15, the Paris prosecutor's office brought OFAC into the case.
My comment: This is not just another data leak — it is a systemic failure in the protection of critical financial infrastructure. The combination of financial and geographic information creates an ideal environment for physical crimes, making this incident an existential threat to wealthy digital asset holders in France. Investors should immediately review their personal security protocols, especially in light of the growing trend toward offline attacks.