GoFirm
Back to Blog
Case Studies·4 min read

Why did the access controls at France's tax authority miss the theft of 678,000 taxpayer records?

By GoFirm

On 17 August 2026, France's Ministry of the Economy and Finance disclosed a data breach at the General Directorate of Public Finances (DGFiP), the country's tax authority, after a hacker using the alias ZeroBytes claimed the intrusion and listed a stolen database for sale on the PwnForums cybercrime forum on 12 August. ZeroBytes reportedly gained access using stolen login credentials combined with a multi-factor authentication bypass technique: no exploited software vulnerability, no zero-day, just a working login and a way past the second factor sitting behind it.

The access reportedly reached the Serveur Professionnel de Données Cadastrales (SPDC), the online platform DGFiP operates to give authorised users access to France's central land registry and property ownership records. ZeroBytes claimed the portal exposed data on roughly 20 million French citizens, and said they extracted 252,149 records covering more than 2 million people before abandoning the rest, describing the scrape as too slow to finish and stating they remained logged into the panel with standing access even while advertising the data for sale.

DGFiP's own account differs on scale but not on cause. Investigations opened after the forum posting on 12 August established that the compromised access points had been used to consult and extract data on 678,000 individuals and professionals: reference tax income, family quotient and withholding tax rate for individuals, company names and SIREN numbers (France's business registration identifier) for professionals, and cadastral data covering addresses and property sizes. DGFiP has confirmed that the online tax portals used by ordinary taxpayers were not touched, and that citizen usernames and passwords were not compromised. The exposure sat entirely on the professional access side of the system.

The damage extends beyond this single incident. The DGFiP breach is the latest in a run of attacks on French government data infrastructure this year: the national employment agency France Travail was fined 5 million euros in January after the personal data of 43 million people was stolen, the national bank account registry FICOBA disclosed a breach affecting 1.2 million accounts in February, and the National Agency for Secure Documents (ANTS) saw 19 million records offered for sale through France Titres. Four major national data holdings compromised inside eight months, each through a different point of access, each confirmed only after an attacker made the theft public.

The defences that failed here were not weak by conventional standards. DGFiP had access controls in place and used them the moment the intrusion was suspected, reviewing the accounts involved immediately. Those controls found nothing. DGFiP has said plainly that the sophistication of the attack meant the initial review did not reveal that data theft had occurred at all. The organisation looked directly at the evidence of its own compromise and, the first time, did not see it. It took a criminal advertising the database for sale to trigger the investigation that eventually did.

A stolen login and an MFA bypass are enough to open a session. They are not enough to authorise what happens inside it. Extracting hundreds of thousands of tax and cadastral records through a professional access portal is an execution event, a high-impact action with a specific, identifiable authority responsible for that system. Before an export of that scale and sensitivity can proceed, GoFirm sends a real-time push notification to that named authority's registered device, requiring biometric confirmation before the action executes. No confirmation, no export, regardless of whether the session reaching that point was opened with a legitimate password, a stolen one, or a bypassed second factor.

This is the distinction DGFiP's own account draws without naming it. The login and the alleged MFA bypass got ZeroBytes into the system. Nothing sat at the point where a session became an extraction of 678,000 people's records, asking whether a specific authorised person had actually approved that specific action. GoFirm sits precisely there, at the moment before the export runs, not at the login screen and not in the after-the-fact investigation that took DGFiP weeks to complete. A stolen credential and a bypassed second factor, however sophisticated, cannot produce a biometric confirmation on the named authority's own registered device. The execution boundary holds regardless of how the attacker got in.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.

References


1. Gatlan, S. 2026. French tax authority data breach affects 678,000 individuals. BleepingComputer, 17 August 2026.
2. Markovic, S. 2026. France's tax authority admits hackers made off with data on 678,000 individuals. Help Net Security, 17 August 2026.

Share this article