The French tax authority, the Direction générale des Finances publiques (DGFiP), has confirmed that an attacker gained unauthorized access to its information systems in late June 2026, extracting data belonging to both private individuals and professional users. The disclosure, made on August 13, came one day after a threat actor operating under the alias ZeroBytes publicly claimed responsibility for the intrusion and asserted that more than two million property owners had their cadastral records compromised. The breach strikes at the heart of France’s digital tax infrastructure, raising urgent questions about the security of systems that handle sensitive financial, identity, and property data for tens of millions of citizens.
DGFiP Confirms Unauthorized Access Through Identity Impersonation
The DGFiP disclosed that the attacker breached its systems through an identity impersonation scheme, a method that involves assuming the credentials and privileges of a legitimate user. The connection was severed during routine security controls at the end of June, but by that time the unauthorized session had already allowed the attacker to view and extract data. The agency has not yet disclosed the specific types of information taken or the total number of individuals affected, stating that an initial investigation is still underway.
This breach is particularly significant because the DGFiP is the central government department responsible for collecting taxes, managing public finances, maintaining property and cadastral information, and operating the online tax services that millions of French residents and businesses rely on each year. Any compromise of its systems carries implications that extend far beyond a single data spill — it undermines trust in the digital infrastructure of the state itself.
ZeroBytes Claims 2.04 Million Victims in Cadastral Data Theft
Separately, the hacker ZeroBytes claimed to have obtained records from the DGFiP’s Serveur Professionnel de Données Cadastrales (SPDC), a professional cadastral data system accessible through the apexappliext.dgfip.finances.gouv.fr domain. According to the hacker’s claims, 252,149 records were extracted from the system, corresponding to 2,041,778 individuals because each record can contain multiple property holders. The sample data reportedly includes names, gender, dates and places of birth, mailing addresses, MAJIC property identifiers, municipalities, cadastral sections and parcel numbers, property rights information, and links between co-owners of the same property.
ZeroBytes also claimed to have authenticated to the service after bypassing multi-factor authentication (MFA) and maintained access for an extended period. The attacker stated that the extraction was stopped voluntarily because retrieving the records was slow, and alleged that the complete system could contain information on roughly 20 million people. These figures, the claimed MFA bypass, the duration of access, and the potential exposure of 20 million individuals remain unverified by the DGFiP or independent security researchers.
The Scale of the Potential Exposure
If the hacker’s claims are accurate, the breach represents one of the largest known exposures of cadastral and identity data in French history. The relationship between 252,149 records and 2,041,778 people reflects the reality that French property records often list multiple co-owners, joint tenants, or family members associated with a single parcel. The inclusion of MAJIC property identifiers — the internal codes used by the French land registry — and links between co-owners means that the stolen data could enable sophisticated profiling of property ownership networks, family relationships, and asset portfolios.
FrenchBreaches, a breach-monitoring site that reported on the incident on August 14, noted that the same actor previously claimed to have extracted 678,438 records from systems associated with impots.gouv.fr. That earlier claim, if substantiated, would indicate that ZeroBytes has been systematically probing and exploiting French tax systems over an extended period, potentially refining their techniques and escalating their targets.
What Is the SPDC and Why Does It Matter?
The Serveur Professionnel de Données Cadastrales (SPDC) is a specialized system within the DGFiP that provides professional users — such as notaries, real estate agents, surveyors, and local government officials — with access to cadastral data. Cadastral records are the official register of property boundaries, ownership, and land use, forming the backbone of France’s property taxation and land administration systems. The SPDC is distinct from the public-facing cadastral portal and is designed for authenticated professional users who require bulk or detailed access to parcel-level information.
Compromise of the SPDC is particularly damaging because the data it contains is both highly structured and highly sensitive. Unlike the public cadastre, which provides limited information, the SPDC includes detailed ownership records, links between co-owners, and internal identifiers that can be used to cross-reference with other government databases. For criminals, this data is a goldmine for identity theft, property fraud, phishing campaigns, and social-engineering attacks targeting wealthy individuals, business owners, and public figures.
MFA Bypass Claim Raises Serious Security Questions
One of the most alarming aspects of ZeroBytes’s claim is the assertion that they bypassed multi-factor authentication to gain access to the SPDC. If true, this would represent a significant failure in the DGFiP’s authentication architecture. MFA is widely considered a critical control for protecting sensitive systems, and its bypass often indicates one of several scenarios: a sophisticated phishing attack that captured both primary credentials and one-time codes, a session cookie theft that allowed the attacker to reuse an authenticated session, a vulnerability in the MFA implementation itself, or a compromise of the underlying identity provider.
Bypassing MFA on a government tax system that processes cadastral data is not a trivial achievement. It suggests that the attacker either possessed advanced technical capabilities, had inside knowledge of the system’s architecture, or exploited a configuration weakness that should have been identified during security assessments. The DGFiP’s statement that the attack involved an “identity impersonation scheme” could be consistent with any of these scenarios, but the agency has not provided technical details about how the impersonation was accomplished or how the MFA was circumvented.
What Data Was Stolen and What Are the Risks for Victims?
Based on the sample data released by ZeroBytes and reported by FrenchBreaches, the stolen records contain a combination of personally identifiable information (PII) and property-specific data that can be used in multiple types of attacks. The fields include:
- Names — enabling direct identification of individuals
- Gender — adding a data point for profiling
- Dates and places of birth — classic identity verification data used in account recovery and fraud
- Mailing addresses — enabling physical-world targeting and phishing
- MAJIC property identifiers — internal codes that link to the broader land registry
- Municipalities — geographic context
- Cadastral sections and parcel numbers — precise property location and boundaries
- Property rights information — ownership type, shares, and legal interests
- Links between co-owners — revealing family and business relationships
For the affected individuals, the risks are multifaceted. Criminals can use the combination of name, address, and property ownership data to craft highly convincing phishing emails that reference specific properties, tax bills, or cadastral updates. The inclusion of co-owner links means that attackers can map relationships between individuals and target them with coordinated social-engineering campaigns. Property fraud — where criminals use stolen identity data to transfer ownership or take out loans against a property — is a growing concern in jurisdictions where cadastral data is compromised.
The DGFiP has stated that affected users will be contacted individually once investigators determine what information was exposed. However, the agency has not provided a timeline for these notifications, leaving victims in a state of uncertainty. In the meantime, individuals who believe they may be affected should monitor their property records, watch for suspicious correspondence, and be cautious of any unsolicited communications that reference tax or property information.
How Did the Attack Happen? A Timeline of Events
Based on the DGFiP’s disclosure and the hacker’s public statements, the following timeline can be reconstructed:
- Late June 2026 — The attacker gained unauthorized access to the DGFiP’s information systems through an identity impersonation scheme. The exact method of initial access has not been disclosed.
- End of June 2026 — The DGFiP’s security controls detected anomalous activity and cut the unauthorized connection. However, the attacker had already viewed and extracted data during the session.
- Prior to August 12, 2026 — ZeroBytes claimed to have extracted 252,149 records from the SPDC system, corresponding to over 2 million individuals, and also claimed to have bypassed MFA.
- August 12, 2026 — ZeroBytes publicly claimed responsibility for the intrusion, posting about the breach on forums and sharing sample data.
- August 13, 2026 — The DGFiP disclosed the incident, confirming unauthorized access and data extraction. The agency stated that additional access restrictions had been implemented to terminate unauthorized activity and prevent further intrusions.
- August 14, 2026 — FrenchBreaches reported on the ZeroBytes claims and the sample data, linking the breach to the SPDC system and noting the actor’s previous claim of 678,438 records from impots.gouv.fr.
This timeline suggests that the DGFiP had a window of approximately six weeks between the breach occurring and the public disclosure. During that period, the agency’s security teams, along with France’s economic and finance ministries, the Haut fonctionnaire de défense et de sécurité (SHFDS), and the national cybersecurity agency ANSSI, have been conducting an investigation. The DGFiP also plans to notify France’s data protection regulator, the CNIL, and file a criminal complaint.
What Is the DGFiP Doing in Response?
In its public statement, the DGFiP outlined several response measures. The agency has implemented additional access restrictions to prevent further unauthorized access and is conducting a forensic investigation alongside the SHFDS and ANSSI. The economic and finance ministries are also involved, reflecting the high-level concern about the breach’s implications for public finances and national security.
The DGFiP will notify the CNIL, as required under French data protection law, and will file a criminal complaint to initiate legal proceedings against the perpetrators. Affected individuals will be contacted directly once investigators have completed their analysis of what data was exposed. For the millions of people potentially affected, this notification process could take weeks or months, depending on the complexity of the investigation and the volume of data involved.
The agency’s response appears to follow standard incident response protocols for a breach of this magnitude, but the lack of immediate transparency about the number of victims and the types of data stolen is a concern. In an era where cybercriminals move quickly to exploit stolen data, delayed notifications can leave victims vulnerable to attacks that could have been prevented with earlier warnings.
What Should Affected Individuals Do Now?
For anyone who receives a notification from the DGFiP — or who believes they may be affected based on their property ownership in France — the following precautions are recommended:
- Be extremely cautious of unsolicited communications — Emails, phone calls, or text messages that reference tax or property information should be treated with suspicion, even if they appear to come from official sources. Stolen identity and cadastral data can be used to craft highly convincing phishing campaigns.
- Verify requests through official channels — If you receive a message asking you to click a link, download an attachment, or provide personal information, navigate directly to the official government website (impots.gouv.fr) rather than using any links or contact details provided in the message.
- Monitor your property records — Regularly check your property’s cadastral record for any unauthorized changes, such as transfers of ownership, new liens, or modifications to boundaries.
- Enable fraud alerts and credit monitoring — While the stolen data is primarily property-related, the identity information included in the breach could be used for financial fraud. Consider placing a fraud alert with the major credit bureaus and monitoring your financial accounts for suspicious activity.
- Report suspicious activity — If you suspect that your data has been used fraudulently, report it to the DGFiP, the CNIL, and local law enforcement. Keep records of any communications and transactions related to the breach.
The DGFiP has stated that it will contact affected individuals directly, but it is important to note that the agency will not ask for sensitive information such as passwords, bank details, or tax identification numbers in these notifications. Any communication that requests such information should be treated as a phishing attempt, even if it references the breach.
The Broader Implications for French Digital Infrastructure
This breach is not an isolated incident. It is part of a broader pattern of sophisticated attacks targeting government tax and property systems worldwide. The DGFiP’s systems are particularly attractive to attackers because they hold a unique combination of identity data, financial information, and property records — all of which have high value on the black market and can be used for a wide range of criminal activities.
The fact that the attacker claimed to have bypassed MFA on a professional cadastral system is deeply concerning for other government agencies that rely on similar authentication mechanisms. If the DGFiP’s MFA implementation had a vulnerability that could be exploited by an external attacker, it is likely that other agencies using the same or similar technology are also at risk. The investigation by ANSSI will be critical in determining whether this is a systemic issue or a targeted exploit.
France’s digital tax infrastructure has been a target for cybercriminals for years, and this breach is a reminder that the sophistication of attacks continues to outpace the defenses of even well-resourced government agencies. The DGFiP processes millions of tax returns and property transactions each year, and its systems are a critical component of the French state’s digital transformation. A breach of this scale erodes public confidence in the security of those systems and raises questions about the adequacy of the agency’s cybersecurity investments.
What ZeroBytes’s Claims Mean for the Cybersecurity Landscape
ZeroBytes is not a well-known actor in the broader cybersecurity community, and the claims made by the hacker should be treated with caution until independently verified. However, the pattern of behavior — targeting government tax systems, claiming MFA bypass, releasing sample data, and referencing previous breaches — is consistent with a threat actor who is focused on maximizing reputational damage and demonstrating technical capability.
If ZeroBytes is able to substantiate the claim of having extracted 2 million records from the SPDC and 678,438 records from impots.gouv.fr, the actor would be responsible for one of the largest data breaches in French government history. The combination of identity data and property information is particularly potent because it enables both digital and physical-world attacks. Real estate professionals, high-net-worth individuals, and public figures who own property in France are at elevated risk of targeted attacks.
The hacker’s claim that the extraction was stopped voluntarily because of slow retrieval speeds is a typical boast in the cybercriminal community, but it also suggests that the attacker may have had more data available than they chose to exfiltrate. The allegation that the full system could contain 20 million records is a red flag that the DGFiP and ANSSI will need to investigate thoroughly. If the attacker had access to query the entire SPDC database, the potential exposure could be far greater than the 2 million individuals already identified.
Questions That Remain Unanswered
Several critical questions remain unanswered as the investigation continues. The DGFiP has not disclosed the specific vector of the identity impersonation attack — whether it involved stolen credentials, a phishing campaign, a vulnerability in a web application, or a compromise of a third-party vendor. The agency has also not confirmed or denied the MFA bypass claim, leaving the security community to speculate about how the attacker gained access to the SPDC system.
Another key question is whether the breach is limited to the SPDC system or whether the attacker had access to other DGFiP systems. The initial disclosure states that the attacker accessed the DGFiP’s information systems broadly and extracted data concerning private individuals and professional users. If the attacker had access to multiple systems, the scope of the breach could be significantly larger than the cadastral data alone.
The timeline of the breach also raises questions. If the DGFiP detected and cut off the unauthorized connection at the end of June, why did the agency wait until August 13 to make a public disclosure? While it is standard practice to delay disclosure during an investigation, the six-week gap between detection and disclosure is longer than what many cybersecurity experts would consider optimal for a breach of this scale. The delay may have been necessary to allow investigators to understand the full scope of the intrusion, but it also gave the attacker time to use or sell the stolen data before victims were notified.
The DGFiP’s confirmation of the breach is a necessary first step, but the agency’s response will be judged by how quickly and transparently it communicates with affected individuals and the public. The investigation is ongoing, and the DGFiP has promised to contact affected users once the data exposure is fully understood. In the meantime, the millions of people who own property in France must navigate a period of uncertainty, unsure whether their personal information has been compromised and what steps they should take to protect themselves.
For the broader cybersecurity community, this breach serves as a stark reminder that government systems — even those protected by MFA and subject to regulatory oversight — are not immune to sophisticated attacks. The combination of identity impersonation, MFA bypass, and prolonged access to a sensitive cadastral database represents a significant escalation in the threat landscape facing European tax authorities. As the investigation unfolds, the lessons learned from this breach will likely inform security improvements across government systems in France and beyond, but for the two million individuals whose data may already be in the hands of criminals, the damage may already be done.