ZeroBytes Breaches French Tax Authority (DGFiP): Stolen Credentials and MFA Bypass Expose Tax Data of 678,438 Taxpayers and Businesses

ZeroBytes Breaches French Tax Authority (DGFiP) (TL-2026-2026) is a high-severity data breach, first published 2026-08-16. It is attributed to ZeroBytes with low confidence, affects Direction Générale des Finances Publiques (DGFiP) / French Ministry of, maps to 8 MITRE ATT&CK techniques (T1078, T1119, T1133), and is covered by 9 detection rules and 19 indicators of compromise.

Key facts for TL-2026-2026

Threat ID
TL-2026-2026
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
2026-08-16
Last reviewed
2026-08-16
Attribution
ZeroBytes
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
government administration, public-sector, tax-and-revenue-administration
Target regions
france, Europe
Detection rules
9
Indicators of compromise
19

In late June 2026, a threat actor using the alias 'ZeroBytes' used stolen credentials and an MFA bypass on the SPDC (Serveur Professionnel de Données Cadastrales) cadastral platform to access France's Direction Générale des Finances Publiques (DGFiP), extracting fiscal and identity records for 678,438 individuals and businesses before the intrusion was severed during a routine security audit. ZeroBytes publicly advertised the data on a cybercrime forum on August 12, 2026, claiming over 2 million records and offering continued system access for sale; DGFiP confirmed the breach on August 13-14, and the Paris Public Prosecutor's cybercrime unit (via OFAC) opened a criminal investigation.

How ZeroBytes Breaches French Tax Authority (DGFiP) works

France's tax administration (DGFiP), part of the Ministry of Economy and Finance, suffered an unauthorized access incident in late June 2026 that DGFiP itself described as more complex than prior attacks it had faced. According to DGFiP's own account, the access followed 'usurpation d'identité' (identity theft) and allowed the intruder to consult and extract data belonging to individuals and businesses; the access was cut off at the end of June 2026 during a routine internal audit. The threat actor's own account, given in an August 15 interview with the breach-tracking outlet FrenchBreaches, adds technical detail DGFiP did not confirm: ZeroBytes says the access chain used stolen credentials belonging to a DGFiP tax agent ('agent de la DGFiP') and an authorized third party ('tiers habilité'), connected via the agency VPN, and bypassed multi-factor authentication protecting the SPDC — the Serveur Professionnel de Données Cadastrales (Professional Cadastral Data Server), DGFiP's cadastral (property-registry) subsystem, reachable via the internal application host apexappliext.dgfip.finances.gouv.fr. From there, ZeroBytes accessed an internal search/export tool named 'Suivi des demandes par usager' (User Request Tracking) — an environment the actor claims contains 6,366,056 fiscal requests addressed to tax services — and used it to pull taxpayer and property-owner records. The actor states extraction activity continued into July 2026 and included an automated component, but that the automated retrieval was voluntarily throttled and ultimately halted because the pace was too slow to exhaustively harvest the environment within a reasonable time.

DGFiP confirmed 678,438 total records exposed — 392,867 individual taxpayer accounts and 285,570 professional/business accounts — spanning names, dates of birth, postal addresses, email addresses, phone numbers, family/dependent status, tax reference income, and source-withholding tax rates, plus internal fiscal-request administrative history (dates and subjects of prior contacts with tax services). Business records additionally include SIREN registration numbers, business addresses, and authorized-representative contact details. DGFiP disclosed that 26,805 exposed individuals report income over €100,000, 386 over €1 million, and 8 over €10 million, making the dataset attractive for targeted spear-phishing, business email compromise, and identity-fraud schemes. Critically, DGFiP states the stolen data does NOT grant access to taxpayers' secure impots.gouv.fr accounts, and no payment-card or banking-credential data was exposed.

ZeroBytes' claims exceed DGFiP's confirmed figures on two fronts. First, from the SPDC cadastral environment specifically, the actor claims 252,149 extracted lines corresponding to 2,041,778 individuals (multiple titleholders per parcel), including names, sex, birth date/place, addresses, MAJIC land-parcel identifiers, department/commune data, cadastral section and parcel numbers, property rights, and multi-titleholder associations — and asserts the underlying system could hold records on roughly 20 million citizens in total (an unconfirmed, cybercriminal-supplied estimate). Second, the actor claims to have retained ongoing access after the June cutoff and offers to sell continued access alongside the dataset. DGFiP disputes the retained-access claim, stating the access 'had been severed at the end of June as part of the audit' and that additional restrictions have since been implemented. The scale discrepancy (678k confirmed vs. 2M+/20M claimed) is unresolved as of publication and should be treated as an open question pending forensic confirmation — the technical account of the MFA-bypass mechanism, VPN specifics, and extraction tooling comes solely from the actor and is independently unverified.

ZeroBytes describes a financially motivated, opportunistic modus operandi ('un peu de tout: l'erreur humaine, les failles, la stupidité, le manque de sérieux' — human error, vulnerabilities, negligence), operating as a two-person team that sells stolen databases to third-party buyers without visibility into end use. The same alias has claimed responsibility for breaches at grocery chain Intermarché Drive, an entity referred to as 'EVA' (EVA GG), and the French Handball Federation (FFHandball), though FrenchBreaches notes the actor's documentation for those claims does not support the same level of precision as the DGFiP claim. This indicates a pattern of serial opportunistic intrusions against French organizations through 2026 rather than a single targeted DGFiP campaign.

Separately, several other French government-linked or government-adjacent systems suffered major 2026 breaches that source reporting explicitly frames as part of a wider pattern worth tracking for correlation: ANTS/France Titres (the national secure-identity-document agency), breached via an IDOR vulnerability by an actor using the alias 'breach3d,' with DGFiP confirming 11.7 million of an alleged 19 million exposed accounts (April 2026); INSEE (the national statistics agency), where an intrusion detected June 19, 2026 and confirmed June 26, 2026 exposed an internal staff directory of roughly 12,800 current/former employees (not the national census/statistical databases); and, most directly comparable in mechanism, the February 2026 FICOBA (Fichier des comptes bancaires) breach — also at the Ministry of Economy and Finance — in which a threat actor used stolen credentials belonging to a government official, exploiting a lapse in multi-factor authentication, to access the centralized French bank-account registry and expose roughly 1.2 million bank-account records. The FICOBA incident is the closest TTP match to the DGFiP breach (same ministry, stolen government-official credentials, MFA weakness) and should be treated as a directly relevant precedent for remediation scoping, not merely a loosely correlated headline. These incidents are attributed to different actors and are tracked as separate threats, but together form a corroborating pattern of credential/access-control failures across interconnected French public-sector finance and identity systems through 2026.

France's Economy Ministry confirmed the breach publicly on August 13-14, 2026, pledged to individually notify all 678,438 affected people/businesses starting the following Monday, and stated it would file a criminal complaint. The ministry said its investigation is being conducted in coordination with ANSSI (Agence nationale de la sécurité des systèmes d'information — France's national cybersecurity agency) and the SHFDS (Service du Haut Fonctionnaire de Défense et de Sécurité), the ministry's own high-defense-and-security-official function, to establish precisely which data were compromised and how access was obtained. The Paris Public Prosecutor's Office cybercrime unit opened a formal investigation, handled by OFAC (Office Anti-Cybercriminalité), France's national cybercrime-fighting office; CNIL (the French data protection authority) has been notified per breach-notification obligations. No CVE, malware family, or C2 infrastructure has been publicly disclosed — this is a credential/identity-based intrusion, not a software-vulnerability exploit.

MITRE ATT&CK techniques used in TL-2026-2026

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1199 Trusted Relationship

Persistence

T1078 Valid Accounts

Defense Evasion

T1078 Valid Accounts

Collection

T1119 Automated Collection; T1213 Data from Information Repositories

Credential Access

T1556.006 Multi-Factor Authentication

Reconnaissance

T1589.001 Credentials

Impact

T1657 Financial Theft

Affected products and versions in ZeroBytes Breaches French Tax Authority (DGFiP)

  • Direction Générale des Finances Publiques (DGFiP) / French Ministry of Economy and Finance — DGFiP taxpayer information system, including the SPDC (Serveur Professionnel de Données Cadastrales) cadastral platform (host apexappliext.dgfip.finances.gouv.fr) and the internal 'Suivi des demandes par usager' fiscal-request search/export tool
    Vulnerable versions: Production DGFiP/SPDC systems as accessed in June-July 2026
    Fixed in: Unauthorized access revoked end of June 2026; DGFiP states additional VPN/internal-tool access restrictions implemented as of August 2026

Remediation for ZeroBytes Breaches French Tax Authority (DGFiP)

Immediate actions

  • Force credential reset and MFA re-enrollment for the DGFiP tax-agent account and third-party (tiers habilité) account implicated in the June 2026 access, and audit all SPDC/DGFiP accounts with cadastral or fiscal-request-history access — including the 'Suivi des demandes par usager' tool and the apexappliext.dgfip.finances.gouv.fr application host — for anomalous VPN logons and bulk-export or automated-query activity since June 2026.
  • Individually notify all 678,438 affected individuals and businesses per CNIL/GDPR breach-notification obligations, with guidance on phishing, spear-phishing, and identity-fraud risk given the exposed income, family-status, and cadastral property data.
  • Independently verify or refute ZeroBytes' claims of a larger (2M+/20M-record) exposure scope and retained ongoing access to DGFiP systems; DGFiP's public statement that access was severed in June should be validated with forensic evidence, not taken solely on the ministry's word — coordinate this validation with ANSSI and SHFDS, who are already engaged.

Longer-term hardening

  • Deploy phishing-resistant, bypass-resistant MFA (FIDO2/hardware security keys) for DGFiP staff and any third parties with access to cadastral (SPDC) and fiscal-request systems, replacing MFA factors implicated in this bypass — apply the same fix across the Ministry of Economy and Finance given the near-identical stolen-credential/MFA-gap root cause in the February 2026 FICOBA breach.
  • Implement anomaly-based and rate-based monitoring (volume, off-hours access, automated/scripted query patterns) on internal data search/export tools across DGFiP and SPDC, specifically tuned to detect the throttled/automated bulk-retrieval pattern ZeroBytes describes using against 'Suivi des demandes par usager.'
  • Extend a coordinated security review to other interconnected French public-sector systems (ANTS/France Titres, INSEE, FICOBA) given the pattern of credential- and access-control-related intrusions against French government systems observed through 2026.

Timeline of ZeroBytes Breaches French Tax Authority (DGFiP)

  • Separately, France's INSEE statistics agency detects an intrusion into an internal staff directory (unrelated actor), part of a broader 2026 pattern of French public-sector intrusions later cited alongside this breach.
  • Per the actor's account, multi-factor authentication protecting the SPDC (Serveur Professionnel de Données Cadastrales) cadastral platform is bypassed, and access is obtained to the internal 'Suivi des demandes par usager' fiscal-request tool via the apexappliext.dgfip.finances.gouv.fr application host, used to search and export taxpayer and cadastral records.
  • Threat actor 'ZeroBytes' gains unauthorized access to DGFiP's information system using stolen credentials belonging to a DGFiP tax agent and an authorized third party ('tiers habilité'), obtained via identity theft ('usurpation d'identifiants'), connecting via the agency VPN. DGFiP's own statement gives only 'late June 2026'; CyberInsider's review of the FrenchBreaches structured alert dates the intrusion to June 26, 2026.
  • DGFiP detects and cuts off the unauthorized access at the end of June 2026 during a routine internal security audit/control.
  • ZeroBytes claims extraction activity extended into July 2026 and included an automated retrieval component against the 'Suivi des demandes' environment (claimed at 6,366,056 fiscal requests), but that the automated retrieval was voluntarily throttled and ultimately halted because retrieval speed was too slow to exhaustively harvest the dataset.
  • ZeroBytes publicly advertises the stolen DGFiP dataset on a cybercrime forum, claiming 678,438 core taxpayer/business records plus a separate SPDC cadastral extraction of 252,149 lines covering 2,041,778 individuals, and offering to sell continued system access alongside the data; the actor further claims the underlying environment could hold records on roughly 20 million citizens.
  • France's Ministry of Economy and Finance / DGFiP confirms the unauthorized access occurred and that data on individuals and businesses was consulted and extracted, stating the investigation is being conducted in coordination with ANSSI (national cybersecurity agency) and the ministry's SHFDS (Service du Haut Fonctionnaire de Défense et de Sécurité).
  • The Paris Public Prosecutor's Office cybercrime unit opens a formal criminal investigation, handled by OFAC (Office Anti-Cybercriminalité); DGFiP disputes ZeroBytes' claim of retained access and states additional restrictions have been implemented; CNIL is notified per breach-notification obligations.
  • ZeroBytes gives an interview to breach-tracking outlet FrenchBreaches detailing the DGFiP intrusion methodology and disclosing prior claimed breaches of Intermarché Drive, 'EVA' (EVA GG), and the French Handball Federation, though FrenchBreaches notes the actor's supporting documentation for those additional claims is less precise than for DGFiP.
  • DGFiP states individual victim notifications for all 678,438 affected people/businesses will begin the following Monday; international media coverage frames the breach alongside the 2026 ANTS/France Titres, INSEE, and February 2026 FICOBA (1.2M French bank accounts, also stolen government-official credentials/MFA gap at the same ministry) incidents as a pattern affecting French government-linked systems.

Sources cited for ZeroBytes Breaches French Tax Authority (DGFiP)

Threats related to ZeroBytes Breaches French Tax Authority (DGFiP)

Detection coverage for TL-2026-2026

As of 2026-08-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2026 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats