Data Breach at France’s Tax Authority Affects Approximately 680,000 Individuals

Published:

spot_img

France’s Directorate General of Public Finances (DGFiP) has disclosed a data breach impacting approximately 680,000 individuals. The breach was revealed after a threat actor claimed on a hacking forum to have accessed DGFiP’s internal systems and exfiltrated data.

According to DGFiP, the unauthorized access occurred in June and July, and was halted immediately upon detection. However, at that time, the agency did not find evidence of data exfiltration. It was only last week that DGFiP confirmed the attackers had used compromised credentials from an employee and a third-party account to access its systems and steal information from 678,000 users.

The compromised data includes reference tax income, withholding tax rates, company names, unique identifiers, and cadastral data related to real estate addresses and surfaces. Importantly, no usernames or passwords were compromised in this incident, which has been reported to France’s data protection authority, CNIL.

DGFiP is continuing to investigate the breach’s nature and scope, as well as the exact number of affected individuals, and plans to contact each one directly. This incident follows closely on the heels of another cyberattack on Romania’s National Agency for Cadastre and Property Registration (ANCPI), which was reportedly targeted by a threat actor known as ByteToBreach.

For further details, see the full report by SecurityWeek.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

spot_img

Related articles

Recent articles

Snowflake GitHub Actions Vulnerability Allows Command Injection via Crafted Issues

Cybersecurity researchers at Wiz have disclosed a GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository. This vulnerability could be exploited through a...

Citrix security advisory AV26-645 warns of active exploitation of CVE-2026-8451 and CVE-2026-8452

Citrix Security Advisory AV26-645: Critical Vulnerabilities in NetScaler Products On June 30, 2026, Citrix issued a security advisory detailing critical vulnerabilities affecting several versions of...

Colombia’s Ministry of Justice Hit by Ransomware Attack Disrupting Services

In a significant cybersecurity incident, Colombia's Ministry of Justice has fallen victim to a ransomware attack that has disrupted critical public services, particularly those...

Logitech Enhances Hybrid Workplaces in IMEA with AI-Driven Solutions

Logitech's AI-Driven Solutions Transform Hybrid Workplaces in IMEA Logitech is advancing the concept of hybrid workplaces across the India, Middle East, and Africa (IMEA) region...