New cyberattack in France: what we really know



Visit New cyberattack in France targeting the DGFiP in 2026 officially concerns 678,000 individuals and professionals, according to the Ministry of the Economy on August 14, 2026. The figure of nearly 2 million people is circulating, but it is based on unconfirmed claims. The exposed data are tax and cadastral records, not passwords for impots.gouv.fr accounts.


New cyberattack in France: what we really know

New cyberattack in France: what happened at the DGFiP?

The new cyberattack in France against the General Directorate of Public Finances is based on illegitimate access obtained through credential theft between June and July 2026. The Ministry of the Economy confirmed on August 14, 2026, that data concerning 678,000 individuals and professionals had been extracted.

The scenario described by Bercy is classic, but formidable: an attacker did not necessarily “break into” the system from the outside. They used the credentials of a DGFiP agent and an authorized third party. In other words, the doror seemed open with a valid badge.

The illegitimate access was claimed on August 12 and 13, 2026 by a malicious actor. The DGFiP then notified the CNIL, the French authorrity for the protection of personal data, after identifying the theft. On August 18, 2026, the CNIL confirmed that it had been notified and stated that its checks were underway.

For an SME manager, the key point is simple: the major risk does not always come from spectacular malware. It often comes from a compromised legitimate account, an authorized service provider, or overly broad access. This is exactly the kind of weakness that a strong authorization and authentication policy must reduce.

How many people are really affected by the leak?

The officially confirmed volume for the DGFiP cyberattack is 678,000 individuals and professionals as of August 14, 2026, according to the Ministry of the Economy. The figure of 2,041,778 potentially exposed people was reporrted by Le Dossier, but it comes from a claim attributed to the hacker and is not officially confirmed.

This difference is not a minor detail. In cyber crisis management, a figure claimed by an attacker may contain duplicates, old data, extrapolations, or files with no direct link to the main incident. It may also be accurate. As long as the authorrity or the orrganization concerned has not confirmed it, it must be treated as a signal, not as an established fact.

Several media outlets and specialized websites relayed the idea of around 2 million property owners or taxpayers exposed via the cadastre. Astuces Aide Inforrmatique, for example, mentioned the circulation of this figure while reminding readers that the official number remained 678,000. Journal du Coin spoke of a cadastral database that “would be added” to the confirmed DGFiP leak, with a worrding not confirmed by the primary sources consulted.

Figures published on the DGFiP cyberattack in 2026
Figure Status in 2026 Source mentioned Cautious interpretation
678,000 individuals and professionals Confirmed on August 14, 2026 Ministry of the Economy Official volume of extracted data
2,041,778 potential people Not officially confirmed The dossier, based on a claim attributed to the hacker Hypothesis to be verified, not a reference figure
3 million phone numbers Separate leak announced on August 12, 2026 DGCCRF, Bloctel case file Separate incident, not to be added to the DGFiP
Read also  Advanced web developer training

The trap for a company that communicates after an incident is announcing a definitive figure too quickly. It is better to publish a confirmed scope, then update it. It is less spectacular, but much more defensible legally and operationally.

What tax and cadastral data was exposed?

The data exposed lors from the DGFiP cyberattack confirmed in 2026 includes the reference tax income, the family quotient, and the withholding tax rate. For businesses, Bercy mentions the company name and the SIREN; the cadastral data consulted includes addresses and surface areas of real estate properties.

The Ministry of the Economy clarified on August 14, 2026 that users’ Public Finances spaces, as well as the usernames and passwords of individuals and professionals, had not been compromised. That is reassuring, but it does not make the leak trivial.

A reference tax income can help personalize a scam attempt. A withholding tax rate can make a fake administrative email more credible. A property address, associated with a surface area, can support targeted fraud aimed at owners, property managers, or real estate professionals.

Cadastral data sometimes seems less sensitive than a password. That is a mistake. Personal data is information that makes it possible to directly or indirectly identify a person; the RGPD, applicable since 2018, also covers asset-related data when it can be linked to an individual.

In the projects we lead, we often see the same underestimation: teams properly protect customer accounts, but leave business exports too broadly accessible. A tax, real estate, or HR CSV file then becomes much more risky than a well-hashed password database.

What concrete risks are there for individuals and businesses?

The main risk after the 2026 DGFiP cyberattack is targetedphishing , also called phishing, that is, the sending of credible fraudulent messages to obtain a payment or information. The exposed tax and cadastral data can be used to personalize scams for several months.

An executive may receive a fake message referring to a tax adjustment, a property tax, withholding tax, or a specific real estate property. The danger comes from the detail. The more exact information the message contains, the more legitimate it appears.

For businesses, the risk also affects the relationship with customers. A company whose name and SIREN appear in a leak may be targeted by fake invoices, calls claiming to be from the administration, or requests to change bank coordinate details. Wire transfer fraud can cost far more than technical remediation.

Read also  Behind-the-scenes graphic designers: who creates the visual worlds of modern slots?

The cost of an incident response varies fortely. In France, in 2026, an emergency assessment by a cyber provider is often around €900 to €1,500 before tax per consultant day, depending on the skills mobilized and the urgency. At that budget, it is better to pay for two days of proper scoping than a week of confused investigation after a bad decision.

Malware remains a related topic: ransomware, Trojan horse, credential stealer. To distinguish the most common threats, a useful refresher is available on the main types of malware to know.

What should an SMB do after a public data breach?

An SMB indirectly exposed by a public data breach must first verify its access, raise team awareness about fraudulent messages, and monitor impersonation attempts. In 2026, the first useful steps are multi-factor authentication, access rights review, and a clear internal channel for reporting doubts.

The right reflex is not to change all tools in a panic. Start with the accounts that provide access to money, customer data, tax tools, messaging systems, and administration platforms. Email often remains the starting point for fraud.

Here is a simple, realistic sequence for an SMB without a dedicated security team:

  • identify sensitive accounts: management, accounting, payroll, administration, service providers;
  • enable multi-factor authentication, ideally with a dedicated app or physical key rather than SMS;
  • check automatic forwarding in mailboxes and suspicious rules;
  • remind everyone that no urgent payment should be approved based on a single email;
  • prepare a short internal message indicating what to do in case of doubt.

A well-conducted access review often takes half a day to two days for a small organization in 2026, hors heavy remediation. The real obstacle is not technical. It is the lack of a clear owner for each tool: who decides that a former service provider should still have access to an interface?

On the agency side, the right reflex is to map accounts before recommending a tool. Microsoft 365, Google Workspace, OVHcloud, Cloudflare, or French hosting can be very well configured or very poorly used. Choosing a provider never replaces access governance.

If an incident is suspected, a short plan avoids actions that destroy evidence. The practical guide on the cyber incident response for SMEs details the decisions to make before disconnecting, reinstalling, or communicating.

How can you prevent legitimate access from becoming a vulnerability?

Legitimate access becomes a vulnerability when an autorized account has rights that are too broad, for too long, or without enhanced control. The 2026 DGFiP cyberattack is a reminder that a hijacked credential can be enough to expose sensitive data, even without compromising users’ passwords.

Read also  Backlink: The key to SEO

The first measure is the principle of least privilege: each account receives only the rights necessary for its mission. It sounds basic. Yet many organizations retain historical rights because a project moved quickly, a service provider changed, or an old need was never removed.

Multifactor authentication significantly reduces the risk of impersonation, especially for administrator accounts and vendor access. In 2026, passkeys, or passwordless passkeys, are becoming a serious option for limiting phishing on web applications; the topic is explained in this guide on passkeys to replace passwords.

Hosting choice also matters, but not in the way people imagine. A French hosting provider can make certain sovereignty, support, and confority trade-offs easier, provided that backups, access logs, and administrative rights are properly configured. The topic is covered more broadly in the analysis on the value of a French hosting provider.

For financial sector players, the regulatory bar has been even higher since DORA came into effect in January 2025. This European regulation imposes strengthened management of digital risks and ICT providers; a summary is available on DORA regulation of financial services.

Defining this type of project upfront avoids most unpleasant surprises: excessive rights, missing logs, backups never tested, providers not sortis of access. This is often where an outside perspective saves time, before the incident transforms simple negligence into a crisis.

FAQ on the DGFiP cyberattack and data leaks

Has the figure of 2 million French people hacked been confirmed?

The figure of 2 million French people hacked has not been officially confirmed for the DGFiP cyberattack in 2026. The figure confirmed by the Ministry of the Economy on August 14, 2026 is 678,000 individuals and businesses affected.

Have impots.gouv.fr passwords been stolen?

The passwords for impots.gouv.fr were not reported as compromised by the Ministry of the Economy on August 14, 2026. Bercy indicates that the Public Finance accounts, users' login credentials, and passwords were not compromised.

What should I do if I receive an email from the DGFiP after this attack?

An email received in the name of the DGFiP after this attack should be checked without clicking on the links in the message. The safest approach is to open the official impots.gouv.fr website directly in the browser and check the notifications in the personal or professional account.

Is the Bloctel leak linked to the DGFiP cyberattack?

The Bloctel data leak announced by the DGCCRF on August 12, 2026 is a separate incident from the DGFiP cyberattack. The DGCCRF mentions 3 million phone numbers recovered, including 600,000 registered with Bloctel, with notification to the CNIL.

English