French tax authority admits data heist after crook touts 2M records
Government disputes claims of continued access as investigators measure damage
France's tax authority, General Directorate of Public Finances (DGFiP), has acknowledged a data breach that occurred in June. The incident involved an alleged cybercriminal who advertised a database containing information on over 2 million French taxpayers. Using the pseudonym ZeroBytes, the attacker claimed to have gained access through stolen credentials and a method that bypassed multi-factor authentication. ZeroBytes also stated they retained access to DGFiP's systems and were offering to sell the database.
Upon learning of the breach, DGFiP immediately severed the unauthorized access and implemented new security measures to prevent further unauthorized use. Ongoing investigations are underway to determine the exact data compromised and the number of individuals affected. The DGFiP intends to notify the affected users and report the incident to the French data protection authority, CNIL.
This security breach is part of a series of cyberattacks targeting France's public sector this year. In February, the Ministry of Finance admitted that hackers accessed a database with 1.2 million records containing bank details of French citizens. In a separate incident, France's Health Ministry reported a cyberattack on the healthtech supplier Cegedim Santé, resulting in the theft of approximately 15.8 million administrative files.
Around 165,000 of these files contained doctors' notes, revealing limited medical histories in rare instances. In April, the Interior Ministry confirmed a breach at France Titres, an agency responsible for identity documents, affecting up to 19 million people. The breach was disclosed by a 15-year-old who advertised the stolen data online, claiming the attack impacted between 18 and 19 million individuals.
In June, France's department responsible for the encrypted government messaging platform, Tchap, was also investigated following a suspected breach. The attackers reportedly accessed over 73,000 user accounts, along with 643,000 messages, nearly 60,000 media files, and numerous chat rooms.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.