French Tax Authority Breached: Data on Individuals and Businesses Compromised
France's Directorate General of Public Finances (**DGFiP**) has confirmed a significant data breach, with an attacker gaining unauthorized access to its systems in late June. The incident exposed sensitive information belonging to both individuals and businesses, prompting an immediate investigation and heightened security measures.
Franceβs tax authority, the **DGFiP**, has publicly acknowledged a cybersecurity incident that led to the unauthorized extraction of data from its information systems. The breach, which occurred in late June, was disclosed by the **Economy Ministry** after a hacker claimed responsibility earlier this week.
### Unauthorized Access and Data Extraction
According to the **Economy Ministry**, an attacker gained illicit entry into **DGFiP** systems by stealing or misusing an identity. This intrusion allowed the perpetrator to "view and extract data belonging to individuals and businesses."
Officials detected and severed the unauthorized access in late June. The public disclosure followed a claim of responsibility by a hacker, which spurred the tax authority to implement additional restrictions to prevent any further unauthorized access.
### Scope of Compromise Under Investigation
Authorities are actively working to ascertain the precise nature and volume of information accessed or stolen, as well as the total number of affected individuals and businesses. The **DGFiP** has committed to contacting all impacted parties individually, informing them of the exposed data and recommended precautions. The agency will also notify France's data protection authority and file a criminal complaint as the investigation proceeds.
### Hacker Claims and Unverified Details
The website **FrenchBreaches**, which monitors data leaks in France, reported that a hacker operating under the alias **ZeroBytes** claimed responsibility for the attack. **ZeroBytes** alleged to have obtained data on over 600,000 individuals, including names, tax identification numbers, email addresses, family circumstances, and tax status details. These claims, along with the authenticity of the purported data, are currently unverified.
**FrenchBreaches** further indicated that the hacker claimed to have accessed internal servers, enabling them to connect to the agencyβs VPN and utilize an internal tool to search for information before their access was terminated. The **DGFiP** has not yet attributed the breach to a specific threat actor or confirmed the hacker's claims.
### A Series of Cyberattacks on French Institutions
This incident marks the latest in a series of cyberattacks targeting French government agencies this year:
* **April**: Hackers targeted the website of Franceβs **National Agency for Secure Documents (ANTS)**, which manages applications for passports, identity cards, and driverβs licenses.
* **April**: The **Education Ministry** revealed an attack on a student account management system, exposing students' personal information.
* **February**: Attackers breached a portion of the **National Bank Accounts File**, a database containing records of bank accounts in France. This incident exposed information linked to approximately 1.2 million accounts.
French authorities have been actively pursuing individuals suspected of these attacks. Earlier this year, police arrested a 20-year-old man believed to be responsible for dozens of data breaches affecting government bodies, sports federations, and private companies.
