French tax authority breach exposes 678,000 taxpayers and the land registry behind them
France's Directorate General of Public Finances has confirmed that attackers used compromised access points to extract tax and cadastral data on 678,000 individuals and businesses. The same seller claims to have held a live session on the central land registry platform covering roughly 20 million people.
Article record
Why it matters
What this means for organisations holding critical data
France's Directorate General of Public Finances has confirmed that attackers used compromised access points to extract tax and cadastral data on 678,000 individuals and businesses. The same seller claims to have held a live session on the central land registry platform covering roughly 20 million people.
The French Ministry of the Economy and Finance has confirmed a data breach at the Directorate General of Public Finances (DGFiP) after an attacker used compromised access points to consult and extract data on 678,000 individuals and professionals. The incident surfaced publicly on 12 August 2026, when a threat actor operating under the handle ZeroBytes listed a stolen database for sale on a criminal forum.
What was taken
According to the ministry, the extracted material includes tax data such as reference tax income, family quotient and withholding tax rate. For businesses it includes company names and SIREN numbers. Cadastral data covering addresses and property sizes was also accessed. The ministry states that user accounts were not compromised and that identifiers and passwords were not exposed. Affected individuals and professionals are being contacted directly by email or letter.
The land registry is the real prize
The seller also claims access to the Serveur Professionnel de Donnees Cadastrales, the professional platform that fronts the French central land registry. That portal is said to expose records relating to roughly 20 million citizens. By the attacker's own account the extraction was abandoned because the volume was impractical to scrape, with around 252,149 records taken covering data on more than 2 million people, and the session left open for a buyer to continue.
That detail matters more than the headline figure. The limit on this breach was not a security control. It was the attacker's patience.
A pattern across the French public sector
This is not an isolated failure. France Travail lost the personal information of 43 million people and was fined 5 million euros by the data protection authority in January. The Ministry of Finance disclosed a separate breach affecting more than 1.2 million accounts tied to the national bank account registry. France Titres disclosed a breach after a seller advertised 19 million records attributed to the national secure documents agency. Each case follows the same shape: a legitimate access path into a large retained dataset, used by someone who should not have had it.
Why tax and property data does not age out
Credentials can be rotated. Income bands, household composition, withholding rates, property addresses and plot sizes cannot. This is durable identity and wealth data, useful for fraud, coercion and targeted social engineering for years after the incident. A citizen has no ability to change it and no route to withdraw it.
The Firevault view
Every element of this breach depended on one precondition: the retained records were reachable from a network by whoever held a valid access point. No platform vulnerability was needed, and none was reported. The access was legitimate in form and hostile in use.
Offline Secure Storage® (#OSS) removes that precondition. A Firevault Vault holds retained records on physically disconnected storage inside a secure bunker, so there is no path to enumerate, no panel to stay logged into and no dataset to scrape. Access is opened deliberately by a named person, used, then removed again. Firevault Control governs the route into live systems so a compromised credential does not inherit standing reach.
Mark Fermor, co-founder of Firevault, said: "A public authority holding tax and land registry data on 20 million people should not be relying on the attacker running out of patience. The archive that carries the longest liability is the archive that has the least reason to be online."
The question for any organisation holding long-lived citizen or customer records is not whether the perimeter held. It is how much of that archive was reachable at all.
Source: BleepingComputer, French tax authority data breach affects 678,000 individuals.
How Firevault would handle this
Physical disconnection removes the path an attacker needs
Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.






