Cybersécurité

3 min de lecture

Lucas Mercier

French government issues apology after massive tax authority data breach affects 678,000

Budget Minister David Amiel apologized following a cyberattack on France's tax authority that compromised data of 678,000 individuals and businesses. The breach is part of an unprecedented wave of attacks on French government systems in 2026.

fbb5b1a_upload-1-2fs3dskw4ykb-jmug260818030.jpg

French government issues apology after massive tax authority data breach affects 678,000

France's Budget Minister David Amiel issued a public apology on Tuesday, August 18, following a major cyberattack on the country's tax authority that exposed sensitive data belonging to 678,000 individuals and businesses. The breach, which occurred in June and July 2026, has intensified scrutiny of the government's cybersecurity measures and sparked anger among the French public.

"What has happened is unbearable for the French people. We understand their anger and we share it," Amiel said at a press conference, denouncing the breach as "serious acts" that "undermine the trust" of citizens in the state. The minister emphasized principles of "transparency," "consideration" for affected users and "toughness" in response, insisting he refused to "sweep the dust under the rug."

The attack on the Direction Générale des Finances Publiques (DGFiP) was carried out using stolen login credentials belonging to a tax agency employee and an authorized outside party. Hackers gained access to systems containing names, dates of birth, home addresses, telephone numbers, reference taxable income and withholding tax rates. The breach was revealed publicly on August 13, after a hacker using the handle 'ZeroBytes' advertised the stolen data on a cybercrime forum on August 12, claiming to have accessed the systems via a compromised VPN used by tax officials. The data was reportedly sold to buyers for thousands of euros.

The same hacker group also claims responsibility for a separate attack in June targeting France's cadastral system, stealing data from approximately 200,000 land registry accounts involving property and land ownership information potentially affecting around 2 million people.

Government response and institutional measures

The damage control effort came after Prime Minister Sébastien Lecornu, who has served as France's fifth prime minister in less than two years amid ongoing political instability, chaired a crisis meeting on the issue. Following the meeting, Lecornu ordered France's National Cybersecurity Agency ANSSI to establish a new 'cyber unit' dedicated to countering cyberattacks.

France's data protection authority CNIL has been notified of the breach, and the DGFiP will file a criminal complaint. The Paris prosecutor's office has launched an investigation into the incident. ANSSI is conducting a full investigation with authorities having restricted access to affected systems.

Amiel, 33, who was appointed as France's Minister of Public Action and Accounts in February 2026 after previously serving as Delegated Minister for Civil Service and State Reform, announced concrete measures in response to the crisis. The government will deploy artificial intelligence tools to test cybersecurity vulnerabilities across government agencies, working exclusively with 'sovereign' AI providers such as France's Mistral while explicitly excluding US-based OpenAI.

Part of unprecedented wave of attacks

The tax authority breach represents the latest in an unprecedented series of cyberattacks targeting French government institutions throughout 2026. In February, the FICOBA bank account database was compromised, affecting 1.2 million accounts. Medical information belonging to 15 million individuals was stolen days later. In April, the ANTS identity document agency suffered a breach affecting nearly 12 million people. The Interior Ministry was also targeted in December 2025.

France has a history of suffering major government cyberattacks. In 2011, hackers used poisoned emails to infiltrate the Finance Ministry, stealing numerous sensitive documents from 150 computers over three months in what was then called a "spectacular" attack. In March 2024, cyberattacks of "unprecedented intensity" struck several government institutions using familiar technical means but at a scale never before seen.

Amiel stressed that "our worst enemy would be normalization, getting used to sensitive data leaks, simply bowing down." The minister's comments reflect growing concern that France's government infrastructure remains vulnerable despite repeated high-profile breaches, raising questions about the adequacy of current cybersecurity measures and the government's ability to protect citizen data.

Données personnellesCybersécurité
← Retour à Cybersécurité

À lire aussi