French Tax Data Taken in Impersonation Breach
Attackers used impersonated professional access to view or extract tax and property data tied to 678,000 people and businesses, while personal tax portals and passwords were not compromised.
The 60-second version
Impersonated professional access exposed selected tax, company, and cadastral data tied to 678,000 people and businesses during June and July.
Key points
- Exposed fields included reference taxable income, family quotient, withholding rates, company names, SIREN numbers, and property addresses and areas.
- Personal tax portals, usernames, and passwords were not compromised, according to the ministry.
- The CNIL has been notified, affected users are being contacted, and the final scope remains under investigation.
- Authentic exposed details could make later phishing or impersonation more convincing.
Verdict. This is a confirmed breach of sensitive records through trusted professional access, not a confirmed takeover of taxpayers' online accounts.
France's tax authority says unauthorized professional access in June and July allowed data tied to 678,000 individuals and businesses to be viewed or extracted. Selected tax, company, and property fields were exposed, but taxpayer portals, usernames, and passwords were not compromised.
Confirmed scopeWhat the investigation established
The Finance Ministry said an attacker impersonated both a DGFiP agent and an authorized third party. That identity context enabled access to the information system during June and July.
Data involvedThe exposed fields were sensitive but bounded
| Individual tax data | Reference taxable income, family quotient, and withholding-tax rate. |
|---|---|
| Business data | Company names and SIREN registration numbers. |
| Cadastral data | Property addresses and surface areas. |
| Not reported compromised | Personal tax portals, usernames, and passwords. |
Combined tax, business, and property information can support convincing impersonation or fraud because a malicious message can contain facts normally associated with a trusted institution.
Security modelWhy professional impersonation changes the risk
Systems may block an unknown outsider while giving broad visibility to someone who appears to be an employee or approved partner. Safeguards need narrow permissions, anomaly detection for unusual lookups or exports, rapid revocation, and auditable records.
Secure customer logins do not by themselves secure the professional channels that can reach customer data.
ResponseNotification has begun while the inquiry continues
The DGFiP notified the CNIL and is contacting affected users. The scope remains under investigation, so the current account is a confirmed interim boundary rather than a final forensic report.
Practical responseWhat affected users should watch for
- Confirm notices through the official tax website or a known DGFiP contact channel.
- Be cautious when a caller cites a real withholding rate, business identifier, address, or property area.
- Review official account activity and report suspicious communications, while recognizing that portal credentials were not reported stolen.
- Retain the official notification because later guidance may change as the final scope is established.
The evidence supports a serious data breach caused by misuse of trusted access. It does not support claims of universal taxpayer-account takeover.