NewsMacroFrance Tax Agency Cyberattack Exposes Data of 678,000 Taxpayers

France Tax Agency Cyberattack Exposes Data of 678,000 Taxpayers

Author: CryptoMeter io·

Key Takeaways

  • The breach affected personal data linked to about 678,000 taxpayers in France.
  • Authorities said attackers gained unauthorized access to an internal system at the tax agency.
  • Reports indicate the intrusion happened in June and the stolen information surfaced publicly in August.
  • Officials have limited access to affected systems and are investigating the type of data taken and the access method used.
  • The incident could increase the risk of phishing and other fraud targeting taxpayers.
France Tax Agency Cyberattack Exposes Data of 678,000 Taxpayers

France's tax agency suffered a cyberattack that exposed personal data linked to about 678,000 taxpayers, authorities confirmed this week. The breach affected both individuals and professional taxpayers and has triggered an investigation into how attackers accessed government systems.

The incident adds to growing cybersecurity concerns across France's public sector. State employment agency France Travail disclosed in March 2024 that a breach had exposed data on roughly 10 million current and former jobseekers, and French hospitals, including facilities in Dax and Corbeil-Essonnes, have been hit by ransomware in recent years. Authorities are now working to determine exactly which information attackers obtained and whether the stolen data could support further fraud or identity-theft attempts.

Investigation Underway

The General Directorate of Public Finances, France's tax authority, detected the incident after attackers gained unauthorized access to an internal system. Reports indicate that the breach occurred in June, while the stolen information surfaced publicly in August.

French authorities have restricted access to affected systems and launched technical investigations. They are also assessing the scope of the stolen information before notifying affected taxpayers about specific risks and protective measures. As a public body, the tax authority falls under the EU's General Data Protection Regulation, which requires qualifying breaches to be reported to the CNIL, France's data protection authority, within 72 hours and requires that affected individuals be informed directly when the risk to them is high.

The incident comes months after another security breach involving the tax authority's national bank-account database. That earlier incident potentially exposed information linked to about 1.2 million accounts after an attacker used stolen credentials belonging to a government employee.

Cybersecurity Risks Grow

The latest breach could increase the risk of phishing, impersonation and other financial scams targeting taxpayers. France's cybersecurity authorities have already warned that criminals commonly exploit tax-related events by sending fake messages that request personal or banking information, and taxpayers can verify genuine communications through their personal space on the official impots.gouv.fr portal.

For businesses and individuals, the incident highlights the financial risks created when government databases become targets. Stolen tax information can provide criminals with credible details for highly convincing fraud attempts.

Authorities have not yet disclosed the full nature of the compromised information or the exact access method the attackers used. The ultimate financial impact remains unclear as investigations continue.