Overview
- DGFiP disclosed in mid‑August that intrusions in June and July, using a usurped employee account and an authorized third‑party account, resulted in the consultation and extraction of roughly 678,000 records.
- The stolen fields include reference tax income, family quotient, withholding tax rate, company names and SIREN identifiers, plus cadastral addresses and property surface data.
- Officials say implicated accounts were suspended when the activity was detected but initial checks missed the theft and deeper probes since August 12 established that data had been exfiltrated.
- A threat actor using the name ZeroBytes has posted samples and sales listings and claims broader access and an MFA bypass, creating conflicting accounts of the full scope while investigations continue.
- DGFiP has notified CNIL and engaged ANSSI and the finance ministry security office, will contact affected people directly, and warns the exposed data raises risks of phishing, identity fraud and targeted extortion as related intrusions are investigated.