// 2 CRITICAL · 1 ZERO-DAY · 5 CVE · 3 EXPLOIT · 1 ADVISORY IN THE LAST 24H
The French Finance Ministry confirmed on August 17, 2026, that the DGFiP suffered a breach exposing sensitive tax data for 678,000 individuals and professionals. The attacker, known as ZeroBytes, used stolen professional credentials to access the corporate VPN and exfiltrated records one by one to evade SIEM volume thresholds. The CNIL mandated MFA for large databases in February 2026, creating a potential enforcement precedent for the missing control.

The French Finance Ministry confirmed on August 17, 2026, that the DGFiP suffered a breach of tax data belonging to 678,000 individuals and professionals, with exfiltration beginning between late June and August 12. The attack exploits a recognized architectural weakness: stolen professional credentials, no confirmation of multi-factor authentication, and record-by-record extraction designed to blend into daily administrative traffic. The stakes now extend beyond late notification to whether the CNIL will enforce the February 2026 rule making MFA mandatory for large databases.

Key Takeaways
  • 678,000 individuals and professionals affected; exposed data includes reference tax income, family quotient, withholding tax rate, and cadastral data, per the Finance Ministry statement.
  • Compromised credentials belonged to at least one DGFiP employee and one authorized third party, with access via corporate VPN; no credentials from the public impots.gouv.fr portal or bank account numbers were stolen.
  • The attacker, identified as ZeroBytes, extracted data record by record to evade traditional SIEM alert thresholds.
  • The CNIL established a binding MFA obligation for organizations with large databases in February 2026; the implementation gap now exposes the DGFiP to potential retroactive enforcement.

How the Silent Extraction Works

ZeroBytes did not dump the database in bulk. According to TechTimes, citing an interview with FrenchBreaches, the attacker queried the system "record by record," distributing queries over time. The method is technically simple: a single request per taxpayer does not exceed the volume thresholds traditional SIEMs use to flag anomalies. The resulting pattern mimics an intensive but legitimate administrative session.

The French Ministry described the operation as "sophisticated," explaining the DGFiP's failure to detect it immediately. Stolen professional credentials opened corporate VPN access, but the dossier does not clarify whether MFA was implemented on those entry points or bypassed. This gap is central: the CNIL cannot sanction an undocumented technical bypass, but it can sanction the absence of controls it made mandatory five months earlier.

What the Ministry Confirms, and What It Does Not

In its official August 17 statement, the Ministry provided unusual granularity for an initial institutional communication. Exposed data for individuals includes: reference tax income, family quotient, withholding tax rate, addresses, property dimensions, and administrative contact history. For professionals: company name, SIREN number, business addresses, and addresses of authorized representatives. The Ministry explicitly ruled out compromise of impots.gouv.fr accounts, user IDs, passwords, and bank account numbers.

"The in-depth investigations conducted since August 12, 2026, have established that, prior to their interruption, these access points had been used to consult and extract data concerning a total of 678,000 individuals and professionals" — French Finance Ministry, official statement

Le Monde verified a sample of the data offered by ZeroBytes on criminal forums, confirming the presence of names, home addresses, phone numbers, tax details, dependent information, and administrative contacts. This independent corroboration strengthens the credibility of the claim compared to simple ghosting operations.

ZeroBytes also claimed to have extracted 252,149 records from the SPDC (Serveur Professionnel de Données Cadastrales), out of more than 2 million potential records, stating the operation was not completed. The DGFiP has neither confirmed nor denied this secondary claim.

The CNIL Precedent: February Rule, August Trap

The CNIL established a binding obligation in February 2026: organizations holding large client databases must implement multi-factor authentication. The rule was already in effect when the DGFiP attack began, presumably in late June. This creates a rare temporal conjunction in enforcement: the regulator can sanction a security violation that occurred after a specific obligation took effect, not merely after a late notification.

CNIL's 2025 activity numbers provide operational context: 6,167 breach notifications, a 9.5% increase over 2024, and cumulative fines of approximately 487 million euros. For 2026, the CNIL indicated that 50% of audits and enforcement will be dedicated to data security. The DGFiP case presents as an immediate test of this reallocation.

The notification gap spans roughly seven weeks from initial detection. The Ministry ordered individual notifications starting the week of August 17, on the directive of Minister David Amiel. The Paris Prosecutor's Office opened a criminal investigation via the OFAC (Office Central de Lutte contre la Grande Délinquance Financière et en Matière de Corruption).

ZeroBytes: Motivations and Method

The actor, interviewed by FrenchBreaches, stated a purely financial motivation. The dossier documents no links to state actors or geopolitical motives.

"Money is the main motivation, plus a desire for power. I don't have a particular preference — I think everything sells, so I retrieve what I can." — ZeroBytes, in interview with FrenchBreaches

ZeroBytes published a demographic breakdown of the exposed data that the dossier does not attribute to DGFiP verification: 26,805 individuals with income exceeding 100,000 euros, 386 with income exceeding 1 million, and 8 with income exceeding 10 million. If these figures correspond to real data, they would signal a potential target for physical attacks ("wrench attacks") or personalized extortion, but they remain in the realm of unconfirmed claims.

Why This Matters

The DGFiP case is not technically complex: valid credentials, legitimate queries distributed over time, absence of behavioral controls. Its relevance lies in the conjunction between a compliance rule that just took effect and a breach that presumably violates it. For European public administrations, the case measures the real-time gap between the issuance of a security policy and its operational implementation.

For enterprises, the potential precedent is clear: MFA is no longer a recommendation but a sanctionable obligation, even when the attack exploits internal credentials on administrative tools not facing the public. For SIEMs, the episode confirms that volume thresholds are insufficient to detect mimetic extraction: behavioral profiling of administrative sessions is required, not just request counting.

The CNIL has not yet announced specific sanctions. The dossier does not document corrective measures adopted by the DGFiP after August 12. Comparison with the December 2025 FICOBA breach, which exposed 1.2 million accounts, shows an institutional pattern of abusive access to French tax databases, but the dossier treats the FICOBA case as separate context not directly linked.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. techtimes.com
  2. bleepingcomputer.com
  3. securityweek.com
  4. cloaked.com
  5. deals.bleepingcomputer.com