A significant data breach involving the French tax authority led to the theft and unauthorized sale of over 678,000 taxpayer records. The database, allegedly being sold by a hacker for several thousand euros, includes detailed information on 392,867 individuals and 285,570 professionals. Among these records, information on high-income earners is included, posing potential risks for scams and targeted attacks. This incident has raised serious concerns about data security and the potential implications for those affected in France.
The French tax authority experienced an intrusion in which attackers used stolen VPN credentials to gain access to internal systems. The intruder then employed an internal search tool to extract taxpayer data before officials cut off access. DGFiP officially confirmed the intrusion and said stolen credentials were used in late June to access and extract taxpayer data. Officials interrupted the attack after detecting the unauthorized activity.
The dataset reportedly comprises more than 678,000 taxpayer records and includes 392,867 records for individuals alongside 285,570 records for professionals. DGFiP has said the exact number of affected individuals remains under investigation. The published counts distinguish between individual and professional tax records within the file. Authorities have not yet provided a final tally while the inquiry continues.
DGFiP has officially acknowledged the breach and the ongoing investigation into its scope. Further updates will depend on outcomes of that inquiry.
The leaked database contains a wide range of personal and financial information drawn from taxpayer records. Sample fields include names, birth details, home and email addresses, phone numbers, income figures, withholding tax rates, family status, dependents, and tax-share information. The file covers records for both private individuals and professionals, with published counts of 392,867 individual records and 285,570 professional records within the dataset of more than 678,000 entries. The dataset also includes entries listing high reference tax incomes.
Security commentators warned that the presence of detailed tax information could make fraudulent messages more convincing. FrenchBreaches said that a scammer holding real tax information and aware of an old approach to the DGFiP could construct a fraudulent message that is much more credible than a simple generic email. The hacker offering the file for several thousand euros could expose more than 678,000 people and businesses in France to scams and targeted attacks. The combination of contact details and income and tax data increases the potential utility of the files for targeted fraud.
Chainalysis wrote that criminals view crypto holders as high-value targets because they possess wealth in an instantly and irreversibly transferable form. CertiK reported 52 attacks worldwide in the first half of 2026, including 33 in France. Chainalysis reported 46 attacks through June, including 30 in France, and said more than $30 million was stolen. These figures were presented in coverage of related attacks in France in 2026.
Jameson Loop, Chief Security Officer at Bitcoin security platform Casa, wrote on X: ‘More bad news for Bitcoiners living in the leading country for wrench attacks… The French tax authority has been hacked, and 678K records leaked.’
Chainalysis’ statement about crypto holders was included alongside the attack statistics. CertiK’s and Chainalysis’ numbers were cited in reporting on the prevalence of attacks through mid-2026. The combined commentary and statistics were part of expert and company insights published about the breach.
Chainalysis, CertiK and Jameson Loop contributed commentary and statistics to reporting on the incident. Those remarks appeared in coverage of the breach.
The France tax data leak covers a large set of taxpayer records and has exposed detailed personal and financial information that could be used for scams and targeted attacks. The breach underscores security concerns for taxpayers and for cryptocurrency holders, who have been identified in reporting as potential high-value targets in related attacks.


