Key Points:
- The French Ministry of the Economy and Finance confirmed that sensitive taxpayer data belonging to individuals and professionals was stolen in a cyberattack.
- A malicious actor gained unauthorized access to systems at the Directorate General of Public Finances in late June.
- Official figures released show that personal and professional records belonging to roughly 678,000 users were compromised during the security breach.
- Authorities are collaborating with national cybersecurity agencies to notify affected taxpayers and investigate the full scope of the incident.
Government cybersecurity defenses faced a major test in Europe following a security breach within national financial administration systems. The French Ministry of the Economy and Finance officially confirmed that data belonging to both individual and professional taxpayers was stolen during a targeted cyber attack. The incident highlights growing digital vulnerabilities across public sector databases and sparks renewed scrutiny regarding the protection of sensitive citizen records.
According to official statements, the security compromise took place within the Directorate General of Public Finances, the division responsible for managing public tax collection and administration. Investigators determined that a malicious actor exploited an identity theft loophole to breach internal networks in late June. While internal audits detected the unauthorized entry and cut off access before the end of June, malicious actors had already viewed and extracted substantial volumes of confidential records.
The security breach came to light after an anonymous online entity claimed responsibility on a cybercrime forum. Subsequent administrative confirmations revealed that approximately 678,000 user accounts were compromised. The exposed database includes personal and professional details such as full names, residential addresses, dates of birth, reference tax income figures, withholding tax rates, family situations, and specific property records.
Government officials emphasized that national cybersecurity teams, alongside technical experts from cybersecurity agencies, are conducting deep forensic investigations. While the initial unauthorized route was shut down immediately upon discovery, specialized teams continue working to determine the full extent of the extracted information. Officials stated that every taxpayer whose records were accessed will receive individual notifications detailing the compromised fields and outlining necessary safety precautions.
This security lapse arrives amid heightened scrutiny over public sector data protection standards. Data protection authorities have been formally notified, and formal criminal complaints have been lodged with judicial prosecutors. As digital threats target high-value government administrative networks, officials face mounting pressure to upgrade infrastructure security and prevent future leaks of personal financial information.





