A new serious data breach has been revealed in France, with the competent authorities confirming that a cybercriminal gained access to information systems of the Directorate General of Public Finances (DGFiP) and managed to extract data relating to approximately 678,000 individuals and professionals.

The case became known on August 12, when a hacker with the nickname "ZeroBytes" claimed responsibility for the attack and claimed to have a stolen database, which he even put up for sale on a cybercrime forum.
French authorities immediately launched an investigation to determine which systems were breached and the exact scope of the leak.
What data was exposed?
According to the French Ministry of Economy and Finance, the attackers used specific access points to retrieve and extract tax information. At the same time, information related to professionals and businesses was affected, including company names and SIREN numbers, the unique identification numbers of French businesses.
See also: Planet9 CVE-2026-50601: Exposed key opens repositories
Of particular concern is access to land registry information. According to authorities, the records contained information such as addresses and property sizes, creating a combination of tax and property information that could be exploited for targeted fraud.
No passwords were compromised
Despite the severity of the attack, the French government clarified that no users' personal online accounts . Also, according to the information so far, no usernames or passwords were exposed.
The DGFiP has restricted access to the systems hosting the information in question and is continuing the technical investigation with the assistance of the French National Cybersecurity Agency (ANSSI). At the same time, the French Data Protection Authority (CNIL) has been informed.
The claims about the French land registry
"ZeroBytes" claims that it also managed to gain access to the Serveur Professionnel de Données Cadastrales (SPDC), a platform connected to the country's cadastral records.
The perpetrator claims that this infrastructure contains information related to approximately 20 million citizens, but reports that he managed to extract 252,149 records, which contained data for more than two million people.
At the same time, it claims that the bulk data extraction was particularly difficult, as it required a time-consuming scraping process. These claims have not been confirmed by the French authorities and are the subject of an investigation.

Data breach: Citizens will be informed
The French Finance Ministry announced that it will start communicating with individuals who may have been affected starting next week. The update will be sent via email or letter and will include information about the data that may have been exposed, as well as instructions on the protective measures they should take.
See also: SafePal incident: Data leak affects 39,798 customers
This move is critical, as even when passwords are not leaked, a combination of tax, business, and property information can be valuable material for phishing, impersonation, and other forms of social engineering.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Another cyberattack in France
The incident adds to a series of serious attacks that have hit French state institutions. In January, the CNIL fined France Travail after a breach involving the personal data of 43 million people.
The following month, the French Ministry of Finance revealed a new leak, this time from FICOBA, the national bank account registry, with more than 1.2 million accounts affected.
More recently, France Titres, after a database with 19 million records allegedly coming from the National Secure Documents Service (ANTS) emerged.
See also: Threema: Major outage from series of DDoS attacks

The sequence of incidents highlights a broader problem: government infrastructures accumulate vast amounts of high-value data and, as such, are increasingly attractive targets. For cybercriminals, a successful attack no longer needs to result in immediate financial theft. Access to trusted personal and asset data itself can be the real “weapon” for a subsequent series of attacks.
Source: www.bleepingcomputer.com
