In a span of 24 hours, three major organizations — France's tax authority, Toronto's Hospital for Sick Children, and private equity firm Apollo Global Management — disclosed data breaches affecting hundreds of thousands of individuals, underscoring a relentless wave of cyberattacks targeting government agencies, healthcare institutions, and financial giants.
France's General Directorate of Public Finances (DGFiP) updated its initial breach disclosure on August 20, revealing that attackers may have stolen the contents of private messages exchanged with taxpayers. The incident affects roughly 600,000 individuals, though the number appears lower than the 678,000 initially reported. For about 250 people, the actual message content was compromised. Exposed data includes tax identification numbers, marital status, email and postal addresses, phone numbers, household composition, and withholding rates. For approximately 250,000 businesses, only company names and SIREN numbers were taken. DGFiP is notifying affected taxpayers and warned of potential phishing attacks, CEO fraud, and bogus bank adviser scams. The authority also disclosed a separate vulnerability in the government's Vacant Successions Portal, which has been suspended pending investigation.
Meanwhile, Toronto's Hospital for Sick Children (SickKids) announced on August 21 that a cybersecurity incident exposed personal information of some current and former employees and job applicants. The breach stemmed from a flaw in third-party software. SickKids emphasized that clinical systems and patient records were not affected. The hospital did not disclose the number of impacted individuals but said it is working with law enforcement and cybersecurity experts.
In the financial sector, private equity giant Apollo Global Management confirmed a data breach on August 21, weeks after Google researchers warned that hackers were targeting financial companies. Apollo did not provide details on the scope or nature of the breach, but the confirmation adds to a growing list of cyber incidents targeting major financial institutions this year.
These incidents highlight a troubling trend: attackers are increasingly exploiting both third-party software vulnerabilities and direct intrusions into government and corporate networks. The French tax authority's breach, which included private messages, is particularly concerning because it shows that even internal communications channels are not safe. The SickKids case demonstrates that third-party software flaws remain a common vector, while Apollo's breach underscores the persistent threat to the financial sector, which handles sensitive data and large sums of money.
Analysis
Why This Matters
- These breaches demonstrate that sensitive personal data — including tax records, private messages, and employee information — is being targeted by cybercriminals, increasing the risk of identity theft, phishing, and financial fraud.
- The French tax authority breach is especially significant because it shows that even government agencies with robust security measures can be compromised, eroding public trust.
- The pattern of attacks across government, healthcare, and finance suggests a systematic, well-resourced campaign against critical infrastructure and high-value targets.
Background
Over the past year, France's public sector has faced a series of cyber incidents. In February, the finance ministry disclosed a breach affecting 1.2 million citizens' bank details. In March, the Health Ministry reported that 15.8 million administrative files were stolen from a healthtech company. In April, a 15-year-old allegedly breached France Titres, affecting up to 19 million people. In June, attackers claimed to have accessed 73,000 accounts on Tchap, the government's encrypted messaging platform. The DGFiP breach is the latest in this string.
SickKids has experienced cyber incidents before; in 2022, a ransomware attack disrupted its systems. The hospital has since invested in cybersecurity, but the latest breach via third-party software shows that supply chain vulnerabilities remain a challenge.
Apollo's breach comes amid a wave of attacks on financial firms. Google's Threat Analysis Group warned in July 2026 that hackers were targeting financial companies with sophisticated phishing and malware campaigns. Apollo's confirmation suggests those warnings were prescient.
Key Perspectives
Government and regulatory bodies: Expect increased scrutiny of data protection practices. The French data protection authority (CNIL) may investigate the DGFiP breach. Regulators will likely push for stronger encryption and access controls.
Affected individuals and taxpayers: They face heightened risk of phishing and social engineering. The French tax authority's warning about impersonation attacks is a stark reminder that stolen data can be weaponized for targeted scams.
Cybersecurity experts and critics: They point out that third-party software vulnerabilities are a recurring theme. The SickKids breach highlights the need for rigorous vetting of vendors. Some experts argue that organizations should adopt zero-trust architectures and limit data retention to reduce exposure.
What to Watch
- French authorities' investigation into the DGFiP breach: whether the attackers' claim of 2 million records is accurate, and whether the Vacant Successions Portal was also compromised.
- SickKids' notification to affected employees and applicants: the number of impacted individuals and any legal action against the third-party software provider.
- Apollo's disclosure of the breach's scope: whether customer or investor data was affected, and how the financial sector responds to the ongoing threat wave.