A data breach impacting impots.gouv.fr, the official portal of the Direction générale des Finances publiques, was claimed on a cybercriminal forum on August 12, 2026, according to information gathered by FrenchBreaches.
Data Breach Claims Involve Internal VPN and Search Tools on impots.gouv.fr
According to FrenchBreaches, the threat actor claims the intrusion occurred on June 26, 2026. ZeroBytes states that internal servers linked to impots.gouv.fr were compromised, yielding access to a VPN that connected to an internal search tool used for both private citizens and professionals. The attacker reportedly began automating data extraction before being disconnected, which cut short the operation and limited the exposed database to 678 438 lines. Of those affected, FrenchBreaches notes that 392 867 are private individuals and 285 570 are professionals.
Compromised Tax Records Expose High-Income Earners and Sensitive Data Fields
An observed sample of the leaked data contains granular financial and personal details. According to the data analysis, the exposed records include internal tax identifiers (spi), full civil names, dates and places of birth, postal addresses, family compositions, the number of tax dependents, reference tax income, and withholding tax rates. Among the individual records identified by FrenchBreaches, 26 805 taxpayers have a reference tax income of 100 000 € or more, 386 exceed €1 million, and 8 exceed €10 million. The dataset also includes telephone numbers, email addresses, and specific logs of requests sent to the tax administration, such as changes to mailing addresses.
Regulatory Response and Verification Status of the Alleged French Tax Breach
Despite the claims circulating on cybercrime forums where the database is reportedly offered for sale for several thousand euros, no public communication from the State has been issued regarding the incident. Under the General Data Protection Regulation (GDPR), severe data breaches trigger requirements to notify the CNIL and to inform affected individuals when a high risk exists. Independent security analysts note that while the sample details match legitimate administrative structures, the full authenticity, exact origin, and total scope of the breached database remain unconfirmed.
Keep reading