
Hacker ZeroBytes claims theft of 678,000 French tax accounts as Paris prosecutor opens investigation
A hacker known as ZeroBytes claimed the theft of data from 678,000 accounts on the French tax authority's platform, prompting the Paris prosecutor to open a cybercrime investigation on August 15.
The breach
At the end of June 2026, a hacker penetrated the internal search tool of France's Direction générale des finances publiques (DGFiP), the agency running the country's tax system. The attacker gained access by stealing the identity of an employee, a method cybersecurity expert Damien Bancal described as common: an employee leaks information on the internet, voluntarily or involuntarily, and the hacker finds and exploits it. Access was blocked at the end of June during a verification check, but not before the intruder consulted and extracted data belonging to both private citizens and professional users. The French Finance Ministry issued a note on August 13 confirming the unauthorized access, and the DGFiP publicly announced the breach on August 14.
- Hacker accesses the DGFiP internal search tool using a stolen employee identity
- Access blocked at the end of June during a verification check
- French Finance Ministry issues a note confirming the breach
- DGFiP publicly announces 678,000 users affected by the cyberattack
- Paris prosecutor's cyber section opens an investigation, assigns case to Ofac
Scale of the theft
The DGFiP confirmed that 678,000 users, both individuals and businesses, had data stolen. For individuals, the compromised information includes names, family quotient, reference tax income and the withholding tax rate, as detailed by DGFiP director general Amélie Verdier. For businesses, the stolen data was described as less sensitive, comprising the Siren registration number, the business address and the mandate holder's address. The DGFiP stressed that the stolen data does not allow access to secured accounts on impots.gouv.fr.
The hacker, who uses the name ZeroBytes, claimed to French Breaches that his access was far broader than the administration has acknowledged. He asserted that a second attack affected more than 2 million French people, a claim the DGFiP had not confirmed as of August 15.
- Confirmed by DGFiP
- 678000 accounts
- Claimed by ZeroBytes (unconfirmed)
- 2000000 accounts
Investigation underway
On Saturday, August 15, the cyber section of the Paris prosecutor's office opened an investigation into the attack. The case was assigned to the Office anti-cybercriminalité (Ofac) and covers the fraudulent extraction of data from a state-managed personal data processing system, as well as participation in a criminal association for the preparation of a crime punishable by at least five years of imprisonment. The DGFiP said it will notify the Commission nationale de l'informatique et des libertés (CNIL), file a formal complaint and provide updates as the investigation progresses. Affected users are to be contacted individually at the start of the following week, with specific information about which data was consulted or extracted and precautions to take.
Hacker's motives
ZeroBytes told French Breaches that financial gain was his primary driver.
Money is the main motivation of any person as well as the desire for power. I do not have political motivations as some may think, I search, I find and I do.
ZeroBytes has previously claimed responsibility for attacks on Intermarché Drive, EVA and the Fédération Française de Handball.
Systemic concerns
The attack has renewed scrutiny of security across French government information systems. The DGFiP described the operation as more sophisticated than previous incidents. Recent weeks have seen other breaches affecting France Travail, the Agence nationale des titres sécurisés (ANTS) and Insee. Olivier Brunelle, secretary general of the FO-DGP union, pointed to years of chronic underinvestment.
What we have been warning about for a few years now is the IT debt that has built up over the years through chronic underinvestment. And we know very well that in IT, when you try to save money, it is often on security systems, which are particularly expensive.
The DGFiP said it immediately implemented new restrictions to block unauthorized access and prevent further breaches.


