Since mid-August, the French tax administration has faced one of the most sensitive data breaches ever confirmed on its systems. Two separate intrusions, claimed by a single group going by the name ZeroBytes, enabled the extraction of hundreds of thousands of files belonging to individuals and professionals.
Here is what is known so far about the timeline, the alleged perpetrators, and the measures announced by the government.
Timeline: From the intrusion to the public disclosure
Late June 2026: an initial intrusion targets the information system of the DGFiP. According to the hacker’s account reported by FrenchBreaches, access was gained by impersonating an identifier allowing connection to a VPN normally reserved for tax officers to access internal tools remotely. This would have granted access to an internal search tool for individuals and professionals, from which the attacker claims to have launched an automated data exfiltration. The access was cut off before the extraction was complete, the intruder claiming to have been detected during the exfiltration.
12 August 2026: nearly a month and a half after the events, a message appears on a highly frequented cybercrime forum. Under the pseudonym ZeroBytes, the author claims an intrusion on impots.gouv.fr and offers for sale an excerpt of the database he says he retrieved, namely 678,438 lines. It is the specialized site FrenchBreaches, which tracks such claims daily, that first spots and documents the publication, before the matter becomes publicly known. It is this publication, rather than any official communication, that brings the case to light.
13 August 2026: the Ministry of the Economy and Finance formally confirms the intrusion in a press release. It speaks of an “illegitimate access,” obtained through identity theft, that allowed the viewing and extraction of data from individuals and professionals. The exact number of affected people is not specified at that time.
14 August 2026: the DGFiP reports a first quantitative tally, affecting roughly 678,000 accounts. On the same day, ZeroBytes claims a second intrusion, this time targeting the Professional Property Data Server (SPDC), which provides access to real estate information. The group says it bypassed multi-factor authentication and recovered more than 250,000 lines, before stopping the download itself, deeming it too slow. This second attack, which occurred at the end of July, is confirmed by the DGFiP the same evening.
16-17 August 2026: given the scope of the case, the Matignon (Prime Minister’s) office announces the creation of an interministerial crisis cell, convened to organize victim information. Beginning on 17 August, the 678,000 affected users are to be contacted individually to warn them about potential targeted fraud. The Paris prosecutor’s office confirms it has opened an investigation, notably for fraudulent data extraction and criminal association. Those offenses carry up to seven years in prison.
In total, for the first intrusion alone, the DGFiP counts about 678,000 affected people, including nearly 393,000 private individuals and 286,000 professionals. Among individuals, several thousand report reference fiscal incomes exceeding €100,000, with a handful above €10 million. The second intrusion, concerning cadastral data, would involve according to ZeroBytes more than two million property owners.
What do the stolen data contain?
Based on the elements gathered and published by FrenchBreaches, the samples circulated by the hackers mix full civil status (names, given names, dates and places of birth), contact details (postal addresses, emails, phone numbers), family situation, and tax information proper to taxation: internal tax identifier, reference taxable income, number of tax shares, rate of withholding tax, as well as the history of certain démarches performed with the tax authorities.
However, the DGFiP clarified that the users’ Personal Finances spaces, with their login credentials, were not compromised: this was access to government databases, not a takeover of individual taxpayers’ accounts.
Who is ZeroBytes?
The ZeroBytes pseudonym is not new on the French data-breach scene. The same acronym has previously been linked to several claims involving Intermarché Drive, the Eva platform, and the French Handball Federation.
Contacted on Telegram by the AFP using coordinates published on the dark web forum where the attack was announced, the group presented itself as consisting of two people who claim to be French, though their real identities remain unknown to this day.
The hackers told the news agency they were satisfied to have already moved part of their loot, mentioning two buyers for a total of several thousand euros, while adding that nothing prevents reselling the same files to other clients later. These statements remain unverifiable at this stage.
The existence of a two-person duo was also independently confirmed by cybersecurity expert Clément Domingo, known under the pseudonym Saxx, who told TF1 that he had recently been in contact with one of the group’s two members. According to the information he gathered, the individual is looking for a job and had, in parallel to his illicit activities, attempted to apply for a position in the information technology sector.
On the technical side, the group’s modus operandi rests on hijacking legitimate access rather than exploiting a classic technical flaw: impersonating the credentials of an agent and then of a second authorized party for the first intrusion, and bypassing multi-factor authentication for the second.
ZeroBytes does not appear to be a one-off. The duo also claims, without confirmation from the affected companies so far, to have stolen data from a national telecom operator and a hotel group.
Several other breaches in France in recent months are also attributed to them by FrenchBreaches, spanning a broad range of sectors from retail to sport to education abroad.
This case sits within a broader wave of cyberattacks targeting French administrations and public operators in 2026, following, in particular, the spring attack on the National Identity Authority (ANTS) and a prior fraudulent access to the DGFiP’s FICOBA banking file in February 2026, already linked to identity theft.
The government appears powerless and its “token measures”
In response to the scale of the breach, authorities announced a series of measures, largely standard for this kind of incident but strengthened by the establishment of an interministerial crisis cell:
- Individual notification of those affected: The Treasury has pledged that each user touched will receive a personalized message detailing exactly what data was accessed or extracted and what vigilance steps to take. These messages must come exclusively from the administration, either from an address ending in @dgfip.finances.gouv.fr or by postal mail, with no action requested from the affected individuals.
- Strengthening system security: The administration says it has bolstered monitoring and tightened access controls following the discovery of the intrusion, without publicly detailing the precise technical measures implemented.
- Interministerial crisis cell: Convened at Matignon and chaired by Prime Minister Sébastien Lecornu, it aims to coordinate crisis communications and the information provided to victims across ministries.
- Notification to CNIL: The DGFiP says it has notified the National Commission on Informatics and Liberty (CNIL), which confirms it has been informed of the data breaches and is already handling the file; noting that it is no longer useful to file individual complaints on this subject.
- Filing of a complaint and judicial investigation: The ministry announced a complaint, and the Paris prosecutor’s office confirmed the opening of an investigation into, among other things, fraudulent data extraction and criminal association, offenses punishable by up to seven years in prison.
These announcements, however, do not erase the criticism over the response time. The Solidaires Finances Publiques union said it had warned the general direction as early as June about the risks of identity theft and targeted phishing linked to this kind of incident.
From a legal standpoint, it is worth noting that state data processing falls outside the sanctions regime that the CNIL could impose on a company put in the same situation, by legal exception.
What remains uncertain
Several elements remain to be independently confirmed: the exact scale of the data to which the hackers claim access (they refer to an environment containing millions of tax requests and, for the cadastral component, more than two million property owners), the precise method by which the hijacked credentials were obtained, and the possible persistence of access to the government systems.