Overview
- DGFiP confirmed late Friday that its systems were breached after attackers used stolen VPN credentials in late June to extract data through an internal lookup tool and that access has been cut off while investigators assess the damage.
- A hacker using the alias “ZeroBytes” is offering a partial dataset reported at about 678,438 records, and FrenchBreaches’ sample review estimates roughly 392,867 individual records and 285,570 business records in the leak.
- Exposed fields in the sample include full legal names, birth details, home and mailing addresses, tax identification numbers, reported taxable income, withholding tax rates, phone numbers, email addresses, family status, dependents, and correspondence with tax officials.
- Security firms warn the data can enable highly convincing phishing and identity-fraud campaigns and that wealthy taxpayers and cryptocurrency holders face elevated risk of targeted scams and violent 'wrench attacks' given dozens of such incidents reported in France over the past year.
- Authorities and security teams are investigating scope and impact and advising affected people to monitor accounts, change credentials and consider extra physical protections after a near-concurrent Trezor customer-data breach raised concerns about opportunistic targeting.