678,000
On August 15, 2026, the French government confirmed that its tax authority, the Direction Générale des Finances Publiques (DGFiP), suffered a significant data breach affecting approximately 678,000 individuals and professionals. The breach was perpetrated by a threat actor known as ZeroBytes, who gained access to an internal search tool via stolen credentials for a professional account and a third party, possibly involving an MFA bypass. The actor exfiltrated a trove of sensitive taxpayer data, including names, addresses, birth dates, and tax information. While the DGFiP asserts that direct access to taxpayer accounts was not compromised, the leaked data poses a severe risk of sophisticated phishing, fraud, and identity theft campaigns.
The threat actor, ZeroBytes, first advertised the stolen data on a criminal forum on August 12, 2026, claiming to possess records for over 2 million taxpayers. The French government and the monitoring platform FrenchBreaches later confirmed a lower but still substantial number of 678,000 affected parties (393,000 individuals and 286,000 professionals). The intrusion occurred between late June and early July 2026. The initial access vector was the compromise of legitimate login credentials, which gave the attacker access to an internal VPN and a powerful search tool that queries taxpayer databases. This method allowed the attacker to systematically exfiltrate data without breaching the main public-facing tax portal, impots.gouv.fr.
The attack chain relied on credential compromise rather than software exploitation. The actor, ZeroBytes, leveraged stolen credentials to impersonate an authorized user and gain access to internal resources.
Attack Chain:
T1078 - Valid Accounts.T1133 - External Remote Services. This allowed them to appear as a legitimate user on the network.T1114 - Email Collection and data from local systems.T1567 - Exfiltration Over Web Service.The stolen data is extensive, including:
The primary impact is the heightened risk of identity theft and highly targeted fraud against French taxpayers. With this detailed personal and financial information, criminals can craft extremely convincing phishing emails or vishing calls impersonating the DGFiP or other official bodies. They could trick victims into making fraudulent payments, revealing banking details, or providing further sensitive information. Businesses are also at risk, as their SIREN numbers and financial data could be used for corporate identity theft or business email compromise (BEC) scams. The French government faces significant reputational damage due to the delayed disclosure, which only occurred after the hacker publicized the breach.
No specific Indicators of Compromise (IOCs) such as IP addresses, domains, or file hashes were mentioned in the source articles.
Security teams may want to hunt for the following patterns to detect similar activity:
command_line_pattern*search_tool.exe* --query * --export *network_traffic_patternUnusual large data egress from internal tool IP to single external IPlog_sourceVPN Logslog_sourceApplication LogsUser Geolocation Logon Pattern Analysis (D3-UGLPA).Network Traffic Analysis (D3-NTA).Multi-factor Authentication (D3-MFA).Network Isolation (D3-NI) principles.Enforce phishing-resistant MFA on all external-facing services, especially VPNs, to prevent access via stolen credentials.
Mapped D3FEND Techniques:
Implement the principle of least privilege. User accounts should not have broad access to query sensitive databases unless it is essential for their role.
Enable and monitor detailed audit logs for VPN access and internal applications to detect anomalous query patterns or login behavior.
Segment the network to isolate sensitive systems, preventing a single compromised account from accessing all internal data resources.
Intrusion and data exfiltration occurred during late June and early July 2026.
Hacker 'ZeroBytes' posts the stolen data for sale on a criminal forum.
The French government officially confirms the data breach.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.