French Tax Authority (DGFiP) Data Breach by ZeroBytes

France Confirms Breach of 678,000 Taxpayer Records by Hacker 'ZeroBytes'

HIGH
August 16, 2026
6m read
Data BreachCyberattackThreat Actor

Impact Scope

People Affected

678,000

Industries Affected

Government

Geographic Impact

France (national)

Related Entities

Threat Actors

ZeroBytes

Other

France

Full Report

Executive Summary

On August 15, 2026, the French government confirmed that its tax authority, the Direction Générale des Finances Publiques (DGFiP), suffered a significant data breach affecting approximately 678,000 individuals and professionals. The breach was perpetrated by a threat actor known as ZeroBytes, who gained access to an internal search tool via stolen credentials for a professional account and a third party, possibly involving an MFA bypass. The actor exfiltrated a trove of sensitive taxpayer data, including names, addresses, birth dates, and tax information. While the DGFiP asserts that direct access to taxpayer accounts was not compromised, the leaked data poses a severe risk of sophisticated phishing, fraud, and identity theft campaigns.

Threat Overview

The threat actor, ZeroBytes, first advertised the stolen data on a criminal forum on August 12, 2026, claiming to possess records for over 2 million taxpayers. The French government and the monitoring platform FrenchBreaches later confirmed a lower but still substantial number of 678,000 affected parties (393,000 individuals and 286,000 professionals). The intrusion occurred between late June and early July 2026. The initial access vector was the compromise of legitimate login credentials, which gave the attacker access to an internal VPN and a powerful search tool that queries taxpayer databases. This method allowed the attacker to systematically exfiltrate data without breaching the main public-facing tax portal, impots.gouv.fr.

Technical Analysis

The attack chain relied on credential compromise rather than software exploitation. The actor, ZeroBytes, leveraged stolen credentials to impersonate an authorized user and gain access to internal resources.

Attack Chain:

  1. Initial Access: The attacker obtained valid credentials for an employee and an authorized third party. This likely occurred through phishing, infostealer malware, or purchase from a credential marketplace. The actor may have also employed an MFA bypass technique. This corresponds to MITRE ATT&CK T1078 - Valid Accounts.
  2. Defense Evasion & Persistence: Using the stolen credentials, the attacker connected to an internal company VPN. This is a classic example of T1133 - External Remote Services. This allowed them to appear as a legitimate user on the network.
  3. Discovery & Collection: Once inside the network, the attacker accessed an internal search application. This tool provided broad access to query and retrieve taxpayer data from both individual and business databases. This aligns with T1114 - Email Collection and data from local systems.
  4. Exfiltration: The actor systematically exfiltrated the collected data. The method is not specified, but it was likely done over the encrypted VPN tunnel, blending in with normal traffic, a form of T1567 - Exfiltration Over Web Service.

The stolen data is extensive, including:

  • Full names, addresses, dates of birth
  • Family situation
  • Reference tax income and withholding tax rates
  • Property cadastral data
  • Business SIREN numbers

Impact Assessment

The primary impact is the heightened risk of identity theft and highly targeted fraud against French taxpayers. With this detailed personal and financial information, criminals can craft extremely convincing phishing emails or vishing calls impersonating the DGFiP or other official bodies. They could trick victims into making fraudulent payments, revealing banking details, or providing further sensitive information. Businesses are also at risk, as their SIREN numbers and financial data could be used for corporate identity theft or business email compromise (BEC) scams. The French government faces significant reputational damage due to the delayed disclosure, which only occurred after the hacker publicized the breach.

IOCs — Directly from Articles

No specific Indicators of Compromise (IOCs) such as IP addresses, domains, or file hashes were mentioned in the source articles.

Cyber Observables — Hunting Hints

Security teams may want to hunt for the following patterns to detect similar activity:

Type
command_line_pattern
Value
*search_tool.exe* --query * --export *
Description
Suspicious command-line usage of internal data query tools, especially with export flags.
Type
network_traffic_pattern
Value
Unusual large data egress from internal tool IP to single external IP
Description
Monitoring for abnormal data transfer volumes from internal applications to unexpected destinations.
Type
log_source
Value
VPN Logs
Description
Look for logins from unusual geolocations, multiple rapid logins from different locations with the same credentials, or logins outside of normal business hours.
Type
log_source
Value
Application Logs
Description
Audit logs for internal search tools should be monitored for an unusually high volume of queries from a single user account.

Detection & Response

  • Monitor VPN and Remote Access Logs: Implement robust monitoring for all remote access services. Look for anomalous login patterns, such as logins from geographically impossible locations, multiple concurrent logins with the same credentials, or access from non-standard IP ranges. This aligns with D3FEND techniques like User Geolocation Logon Pattern Analysis (D3-UGLPA).
  • Audit Internal Application Usage: Critical internal applications, especially those with access to sensitive data, must have detailed audit logging. Security teams should establish a baseline of normal query behavior and alert on deviations, such as a single user account performing an unusually high number of searches or data exports.
  • Network Egress Monitoring: Monitor outbound network traffic for large, unexpected data transfers, particularly from internal servers to external destinations. This can be achieved through D3FEND's Network Traffic Analysis (D3-NTA).

Mitigation

  • Enforce Phishing-Resistant MFA: The most critical mitigation is to enforce phishing-resistant Multi-Factor Authentication (MFA) for all accounts, especially those with access to VPNs and sensitive internal systems. This is a key aspect of D3FEND's Multi-factor Authentication (D3-MFA).
  • Principle of Least Privilege: Ensure that user accounts, including those of third-party partners, only have access to the data and systems strictly necessary for their roles. An account should not have the ability to query the entire taxpayer database unless it is a core job function.
  • Network Segmentation: Isolate sensitive database systems and internal tools from the general corporate network. Access should be strictly controlled through internal firewalls and access control lists, following D3FEND's Network Isolation (D3-NI) principles.
  • Data Exfiltration Controls: Implement Data Loss Prevention (DLP) solutions to detect and block the unauthorized transfer of sensitive data patterns (like tax IDs or SIREN numbers) outside the network.

Timeline of Events

1
July 31, 2026
Intrusion and data exfiltration occurred during late June and early July 2026.
2
August 12, 2026
Hacker 'ZeroBytes' posts the stolen data for sale on a criminal forum.
3
August 15, 2026
The French government officially confirms the data breach.
4
August 16, 2026
This article was published

MITRE ATT&CK Mitigations

Enforce phishing-resistant MFA on all external-facing services, especially VPNs, to prevent access via stolen credentials.

Mapped D3FEND Techniques:

Implement the principle of least privilege. User accounts should not have broad access to query sensitive databases unless it is essential for their role.

Mapped D3FEND Techniques:

Audit

M1047enterprise

Enable and monitor detailed audit logs for VPN access and internal applications to detect anomalous query patterns or login behavior.

Mapped D3FEND Techniques:

Segment the network to isolate sensitive systems, preventing a single compromised account from accessing all internal data resources.

Mapped D3FEND Techniques:

Timeline of Events

1
July 31, 2026

Intrusion and data exfiltration occurred during late June and early July 2026.

2
August 12, 2026

Hacker 'ZeroBytes' posts the stolen data for sale on a criminal forum.

3
August 15, 2026

The French government officially confirms the data breach.

Sources & References

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Data BreachZeroBytesDGFiPTaxpayer DataFranceCredential CompromiseVPN

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.