France • 🌿 Progressive

France's Tax Hack Exposed Income Data of at Least 1 Million People — Workers and Benefit Recipients Most at Risk

France's Tax Hack Exposed Income Data of at Least 1 Million People — Workers and Benefit Recipients Most at Risk

Two cyberattacks in June and July exposed the tax records of at least 1 million people registered with France's DGFiP.

A pair of cyberattacks on the French tax authority between June and July left the financial details of at least 1 million people exposed, with workers, self-employed contractors, freelancers and families dependent on state aid facing the most immediate risk from what was stolen. --- THE CONTEXT --- France's General Directorate of Public Finance, the DGFiP, announced on Friday that two separate intrusions had occurred in its computer systems. Zerobytes, a group previously linked to hacks of French government computers, claimed responsibility on a dark-web forum, stating it had gained access through a VPN used by tax officials. --- THE FACTS --- The first attack, in June, compromised the records of at least 678,000 people registered on the French tax portal. The second, in July, targeted the professional land-registry server known as the SPDC and exposed an additional 200,000 accounts. Together, roughly one in five accounts in the system was breached. Stolen data includes full names, household tax quotient, the revenu fiscal de référence — the income figure used to determine eligibility for government financial aid — and the withholding tax rate. For businesses, the SIREN registration number, address and named tax representative were also taken. Passwords do not appear to have been compromised, according to the authorities. Prime Minister Sébastien Lecornu will chair an emergency meeting on Monday. --- THE POSITIONS --- The Finance Ministry said affected individuals will be notified by email or through an alert in their tax account at the start of the week. The tax authorities pledged additional guidance in coming days on what people should do. Zerobytes made no further public statements beyond claiming the attacks. --- WHAT REMAINS UNKNOWN --- The exact technical flaw in the VPN has not been disclosed, nor whether it was patched before the second attack occurred. The tax authorities have not published a complete list of what data categories were accessed or whether any data has already been sold or shared. --- UNANSWERED QUESTIONS --- • Why did a second successful attack occur weeks after the first, suggesting the initial breach was not fully contained? • How many of the 678,000 individuals affected receive state benefits calculated using the leaked revenu fiscal de référence? • Have the stolen records already been distributed or sold on dark-web marketplaces? • What recourse do affected people have if the leaked data is used against them in phishing or benefit fraud? --- EPM ANALYSIS --- The revenu fiscal de référence is not a neutral data point: it is the number that opens or closes the door to housing aid, scholarship eligibility and social support. Its theft creates a precise toolkit for social-engineering attacks aimed at people who are already financially exposed. That the second attack followed the first within weeks raises a concrete question about whether affected communities were warned early enough to protect themselves. 📌 📌 EPM Take: In EPM's view, the most dangerous element of this breach is not the scale but the specificity. Knowing someone's taxable household income, their benefit-eligibility threshold and their tax rate is enough to craft a convincing, personalised fraud against people who have little margin for financial error. EPM has previously covered France's public infrastructure under stress; this episode adds the digital layer to that pattern. Institutional accountability must be proportionate to the harm that a mandatory data submission system can inflict when it fails.

El fisco francés filtró datos de al menos 1 millón de personas: quiénes están expuestos y qué hacer

Dos ciberataques en junio y julio comprometieron datos de al menos 1 millón de personas en el sistema fiscal francés. Zerobytes reclamó la autoría.

Dos ataques en junio y julio dejaron al descubierto los datos fiscales de al menos 1 millón de personas registradas en el sistema de impuestos francés, una brecha que toca de cerca a trabajadores, arrendatarios, autónomos y familias que dependen de ayudas públicas calculadas con esos mismos datos. --- EL CONTEXTO --- La Dirección General de Finanzas Públicas (DGFiP) anunció el viernes la existencia de dos intrusiones separadas en sus sistemas informáticos. El grupo Zerobytes, vinculado a ataques anteriores contra organismos gubernamentales franceses, reclamó la autoría en un foro de la web oscura y aseguró haber tenido acceso a una VPN utilizada por funcionarios fiscales. --- LOS HECHOS --- El primer ataque, en junio, comprometió los datos de al menos 678.000 personas registradas en el portal tributario. El segundo, en julio, afectó al Servidor Profesional de Datos Catastrales (SPDC) y expuso 200.000 cuentas adicionales. En total, aproximadamente una quinta parte del total de cuentas del sistema fue vulnerada. La información robada incluye nombre completo, cociente familiar, renta fiscal de referencia —la cifra que determina el acceso a ayudas del Estado— y tasa de retención en la fuente. Para empresas se filtraron el número SIREN, la dirección y el nombre del responsable fiscal. Las contraseñas no habrían sido comprometidas según las autoridades. --- LAS POSICIONES --- El Ministerio de Finanzas informó que los afectados recibirán un aviso por correo electrónico o mediante una alerta en su cuenta fiscal «a principios de semana». El primer ministro Sébastien Lecornu presidirá una reunión de urgencia el lunes. Zerobytes no ofreció declaraciones públicas más allá de reclamar el ataque. --- LO QUE FALTA SABER --- Las autoridades fiscales prometieron más detalles «en los próximos días» sobre el alcance exacto de lo robado y las medidas de protección recomendadas. No se ha publicado la naturaleza del fallo en la VPN ni si existen vulnerabilidades aún abiertas. --- PREGUNTAS SIN RESPUESTA --- • ¿Qué fallo técnico específico en la VPN permitió el acceso a los sistemas de la DGFiP? • ¿Cuántas de las personas afectadas son beneficiarias de ayudas sociales calculadas con la renta fiscal de referencia filtrada? • ¿Se ha contenido completamente la brecha o persisten accesos no autorizados al sistema? • ¿Qué medidas de auditoría aplicó la DGFiP entre el primer y el segundo ataque? --- ANÁLISIS EPM --- La renta fiscal de referencia es el dato más sensible políticamente: es la cifra que el Estado usa para conceder o denegar subsidios, bonificaciones y becas. Su filtración no es solo un problema de privacidad; es una palanca de manipulación para quienes construyan ataques de ingeniería social dirigidos a familias vulnerables. El hecho de que el segundo ataque ocurriera semanas después del primero plantea dudas graves sobre la efectividad de la respuesta institucional inicial. 📌 📌 Conclusion EPM: A juicio de EPM, el dato más alarmante no es el volumen de cuentas comprometidas sino la calidad de la información robada. La renta fiscal de referencia y el cociente familiar permiten construir perfiles de fraude dirigidos con precisión quirúrgica hacia personas que ya dependen de prestaciones estatales. EPM ha cubierto cómo las infraestructuras públicas francesas muestran signos de fragilidad sistémica, desde el agua potable hasta el fisco. Este patrón exige una conversación honesta sobre inversión en ciberseguridad pública, no solo gestión de crisis.
📤 Share on Telegram

¿Te gustó este artículo? Recibe cobertura global en tu correo.

Suscríbete gratis / Subscribe free