The breach, first reported by cybersecurity news site Cybernetica and widely shared on technical forums, involved unauthorized access to DGFiP's internal systems, potentially compromising tax returns, income declarations, and banking details of affected taxpayers. The agency acknowledged the incident on August 25, 2026, following discovery by its security teams.
While DGFiP has not yet disclosed the full scope of the breach, early reports suggest the attackers exploited a vulnerability in the agency's web portal to exfiltrate data over several weeks. Affected individuals began reporting suspicious activity on tax accounts and phishing attempts referencing specific tax information just days before the official announcement.
French Finance Minister Antoine Armand stated that the government is working with the National Cybersecurity Agency (ANSSI) and judicial authorities to investigate the attack. "We take this extremely seriously and are mobilizing all resources to identify those responsible and strengthen our defenses," he said in a press briefing.
For taxpayers, the breach raises immediate concerns about identity theft and financial fraud. France's data protection authority, the CNIL, has urged citizens to monitor their bank accounts and tax notices for irregularities. The government is establishing a dedicated hotline and credit monitoring services for those affected.
This incident follows a pattern of increasing cyberattacks against European government institutions. In 2024, France was hit by a ransomware attack on its unemployment agency, and in 2025, Italy's tax agency suffered a similar breach. French lawmakers are now calling for urgent parliamentary hearings on the state of public sector cybersecurity.