On 12 August 2026 a threat actor using the handle ZeroBytes put a database from the Direction générale des Finances publiques — France's tax authority — up for sale on a criminal forum.

The Ministry of the Economy and Finance has since confirmed the breach, shut the affected systems down, and opened an investigation with ANSSI, France's national cybersecurity agency.

The three numbers, kept separate

The ministry's account distinguishes between what was reachable and what was taken, and the distinction is the story:

Individuals and professionals whose data was extracted678,000
Records potentially accessible through a property-registry platformaround 2,000,000
Of those, actually stolen252,149

That middle figure is the one that would have led every headline if the ministry had not published the third alongside it. Two million accessible and 252,149 taken are different facts about the same weakness, and an organisation that publishes both is doing something most do not.

We spent last week on 3.6 million Entra records where the only thing independently checked was the shape of the data. This is the opposite posture: the victim counted, and told you which number is which.

What was in it

Not credentials. Something arguably worse for the people affected.

The exposed data includes tax information — reference tax income, the quotient familial that encodes household composition, and withholding tax rates — plus business identifiers including company names and SIREN numbers, and cadastral data giving addresses and property sizes.

The ministry has been explicit that user IDs, passwords and online accounts were not compromised, and that is worth stating plainly rather than burying: your impots.gouv.fr login is not in this.

Why "no passwords" is thinner comfort than it reads

A password can be changed. Your income cannot, and neither can your address or the size of your house.

What this dataset gives an attacker is the ability to be convincing. Someone who knows your reference tax income, your household composition and your property already sounds like the tax office when they call, and the single most effective French-language phishing lure of the last decade has been a tax refund. Combine an accurate income figure with a refund amount and the usual advice — "the tax office will never ask you for this" — stops carrying the weight it needs to.

The cadastral component adds a second, less discussed risk: a list of addresses with property sizes, tied to income brackets, is a target list for offline crime as much as online.

The third major French public breach this year

Context the ministry did not supply, and it matters:

  • France Travail, the employment agency — 43 million records
  • FICOBA, the national bank account registry — 1.2 million accounts
  • DGFiP678,000 individuals and professionals

Those are three separate central government systems in a single year, holding employment, banking and tax data on overlapping populations. Any individual breach is an incident. Three is a pattern, and the pattern is that the highest-value citizen databases in the country are being reached one after another.

For readers in India this is the near future of the same question. The DPDP Act's notification duties come into force in November 2026, and the French response — count precisely, publish the distinction between accessible and taken, write to the affected individually — is roughly what "reasonable" will end up meaning in practice.

What the ministry is doing

Affected individuals are being contacted directly, by email or letter, with detail on what was exposed and what precautions to take. Systems were taken offline on discovery.

Direct notification with specifics is the part worth crediting. "We were breached, change your password" is what most disclosures amount to, and it is useless here, because the password is not the problem.

What to do if you are in France

  • Treat any tax communication about a refund as hostile. Especially one that quotes a figure correctly. That accuracy is now available to anyone who bought this data.
  • Verify by going to the site yourself. Never through a link, never through a number in the message.
  • Read the ministry's letter when it arrives. It is supposed to say what was exposed in your specific case, which changes what you should watch for.
  • Watch for correspondence that references your property. Cadastral data was in this, and address-plus-income is a distinctive combination.

What is not established

  • How the attacker got in. The ministry has not described the intrusion route.
  • Whether the data has been sold. It was listed for sale; no buyer is known.
  • Whether ZeroBytes acted alone, or is a reseller of someone else's access.
  • Whether the 2 million exposure was reachable for long enough for anyone else to have used it. Only the 252,149 figure is attributed to this actor.