France’s Directorate General of Public Finances (DGFiP) has disclosed a data breach impacting approximately 680,000 individuals.
The incident was disclosed after a threat actor boasted on a hacking forum about accessing DGFiP’s internal systems and exfiltrating data.
According to DGFiP, the threat actor accessed its systems in June and July, and the unauthorized access was suspended immediately upon detection. However, the public tax authority did not discover evidence of data exfiltration at the time.
Last week, DGFiP confirmed that the attackers used compromised credentials for an employee and a third-party account to access its systems and steal the information of 678,000 users.
According to the finance agency, reference tax income, withholding tax rate, company names and unique identifiers, and cadastral data on real estate addresses and surfaces were compromised.
No other information, including usernames and passwords, was compromised in the attack, which was immediately reported to France’s data protection authority CNIL.
DGFiP says it continues to investigate the nature and scope of the data breach, as well as the exact number of potentially affected individuals. The tax authority says it will contact each affected individual directly.
The incident came to light roughly one month after another European government agency, Romania’s National Agency for Cadastre and Property Registration (ANCPI), fell victim to a disruptive cyberattack.
ANCPI was reportedly hacked by a threat actor known as ByteToBreach, who stole information including employee credentials and internal documents and attempted to extort the agency.
When the extortion attempt failed, the hacker reportedly wiped the encrypted data, disrupting official applications, sites, and email services, and bringing Romania’s real estate market to a standstill.
The central database of the cadastral system, containing property and real estate rights records, was not affected. Still, ANCPI scrambled for roughly three weeks to rebuild its servers and restore the affected applications.
Related: 40,000 Impacted by SafePal Data Breach
Related: Fortune 500 Companies Hit in Azure Data Theft Campaign
Related: Trivy, Not LiteLLM Behind the 2,500 Org Compromise
Related: Irregular Details How a Naming Error Let AI Models Attack a Real Company


