ZeroBytes lists French tax agency data for sale: DGFiP breach confirmed at 678,000 affected
On August 12, 2026, a threat actor operating under the handle ZeroBytes posted a listing on the PwnForums hacking forum offering for sale a database allegedly stolen from France's Direction générale des Finances publiques (DGFiP), the agency that runs the country's tax administration. The seller claimed access to DGFiP infrastructure since late June, obtained through stolen credentials combined with a bypass of two-factor authentication, and offered both a static dump and what he described as still-live access to French tax systems. Days later, France's Ministry of Economy and Finance confirmed illegitimate access to DGFiP information systems affecting approximately 678,000 individuals and organizations.
What the ministry confirmed
The official statement is more measured than the forum post, and the gap between the two is worth keeping in view. According to the ministry, the compromised data covers income information, family composition, tax withholding rates, company names and SIREN registration numbers, cadastral addresses, and property surface areas. Crucially, the government emphasized that users' online accounts were not affected and that no usernames or passwords of individual or professional taxpayers were stolen. As soon as the illegitimate access was identified, DGFiP restricted access to its sensitive information systems and launched an investigation alongside ANSSI, France's national cybersecurity agency. The CNIL data protection authority has been notified, and victim notifications are going out by email and post, spelling out which categories of data may have been accessed and what precautions recipients should take. DGFiP has also filed a criminal complaint. The seller's claims, unverified
ZeroBytes tells a bigger story than the ministry does. In his forum posts, he claims to have reached the Serveur Professionnel de Données Cadastrales (SPDC), the professional portal providing access to France's centralized land registry, and says that portal held records covering roughly 20 million citizens. He states that he extracted 252,149 records touching more than two million people before abandoning full scraping as impractically slow, and that at the time of posting he was still logged into the panel and willing to sell that access along with the dump (ZATAZ). None of these figures have been independently verified, and they should be treated as marketing until forensics say otherwise. The number that carries official weight is 678,000. The discrepancy matters practically. If the true exposure were measured in millions rather than hundreds of thousands, notification volumes and phishing risk would scale accordingly. But underground sellers routinely inflate reach to raise prices, and a claim of live access cannot be tested by outsiders. It sits against the agency's account that every compromised account was cut off upon detection, with additional access controls imposed since. Why tax data sells
Tax records are among the most dangerous datasets that can circulate on criminal markets, precisely because of how ordinary they look. A name paired with reference taxable income, family composition and an exact withholding rate lets a fraudster impersonate the tax authority with devastating credibility. A call or email quoting your real income band and real prélèvement à la source rate does not sound like phishing; it sounds like Bercy. For businesses, company names plus SIREN numbers enable invoice fraud and convincing calls aimed at payroll and accounts-payable staff. Cadastral addresses and property surface areas add a physical dimension, identifying who owns large or valuable property and where they live. This is the same dynamic we noted when German credit bureau records appeared on an underground forum earlier this summer; see our coverage of the alleged SCHUFA database sale. National-scale financial and administrative datasets have become premium commodities in European-language markets, and state institutions are now regular targets rather than outliers. A serial actor with a familiar method
ZeroBytes is not a newcomer. Reporting in French and Russian outlets ties the same alias to a string of 2026 intrusions against French organizations, including a supermarket chain, a gaming platform and a sports federation, all following a consistent playbook: steal credentials belonging to an employee or authorized third party, log into an internal query tool through a VPN, then extract data record by record to stay under detection thresholds designed to catch bulk downloads (FrenchBreaches). Russian-language coverage summarizes the case for a wider audience (Xakep), while English-language reporting confirms the 678,000 figure and the SPDC claims (BleepingComputer). The method highlights a structural weakness shared by many large administrations: internal search tools built for legitimate administrative work become efficient extraction engines the moment their only control is a login. Query-by-query exfiltration defeats volume-based alerting almost by design. What to watch
Three things will shape how this story develops. First, whether ANSSI's investigation revises the 678,000 figure upward as forensics continue, or validates the seller's larger SPDC narrative. Second, whether any portion of the dump surfaces publicly, which would shift the incident from a controlled sale to open-season abuse. Third, what CNIL concludes about the timeline between the late-June intrusion and disclosure, given that GDPR breach-notification clocks start at awareness of the breach itself, not at confirmation that data left. For anyone notified, the practical advice is unchanged: treat tax-themed emails, calls and letters with heightened suspicion, verify any request through official channels independently, and never act on payment or bank-detail changes prompted by unsolicited contact. A database like this does not need to be resold to cause harm; one copy in the wrong hands is enough to power a very convincing phishing season.