We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

Cybersecurity

Tax Agency Hack: What Leaked From the Corporate Side, and the 3 Checks to Perform This Week

The DGFiP has confirmed the theft of data belonging to 678,000 users—both individuals and businesses—following a breach of its information system in late June. For businesses, the scope of the data breach is limited (SIREN numbers, addresses), but this information is enough to make a phishing attempt or wire transfer fraud much more credible. Here’s what was actually leaked and the steps you should take this week.

Tax Agency Hack: What Leaked From the Corporate Side, and the 3 Checks to Perform This Week

In summary. The DGFiP’s information system was breached in late June 2026: 678,000 users—both individuals and businesses—had some of their tax data exposed. For an SME, the immediate risk is not the loss of the impots.gouv.fr account, but the use of this data to make a fraudulent email or phone call appear credible.

What Happened

An attacker gained unauthorized access to the information system of the Directorate General of Public Finance in late June 2026 by impersonating someone else. The agency initially reported that several hundred thousand users were affected, but later revised the figure to 678,000 individuals and professionals, as announced on August 14.

On August 15, the Paris Public Prosecutor’s Office opened an investigation and assigned it to the Cybercrime Unit. Prime Minister Sébastien Lecornu is chairing an interministerial crisis task force this Monday, August 17, primarily to organize the notification of those affected, which was scheduled to begin that same day.

The DGFiP is specific about the nature of the data. For individuals: name, family quotient, reference taxable income, and withholding tax rate. For businesses, the data is less sensitive: SIREN number, business address, and representative’s address. The administration states that this information does not grant access to the secure account on impots.gouv.fr.

Does this apply to me?

If your company is among the affected accounts, you will receive a notification from the DGFiP. Warning: this is exactly when scammers will strike. Campaigns of fake emails mimicking addresses ending in “@dgfip.finances.gouv.fr” are already circulating, promising a tax refund and asking you to fill out a form. Several thousand people have fallen for this scam in recent months, even before this incident.

Secondary exposure is a real risk, even if the stolen data seems innocuous. A SIREN number, a registered office address, and the name of the CEO make it possible to craft a message that no longer looks like spam: the right contact person, the right references, and the right tax context. This is the classic fuel for a wire transfer scam or an urgent “adjustment” request sent to your accountant.

Important note: There is no indication at this point that passwords or bank account information have been leaked. Therefore, there is no need to reset all your login credentials. The issue here is the credibility given to these attempts at manipulation.

What to Do Now

1. Notify anyone who handles money— accountants, executive assistants, and executives—and let them know in a single sentence that a wave of messages purporting to be from the tax authorities is likely in the coming days. A government agency never requests bank account information or payment via email or phone. Any refund request should be verified by logging in to impots.gouv.fr yourself; never through a link you’ve received.

2. Secure the wire transfer process. The best defense here isn’t technical. Establish this rule: any change to bank account information and any wire transfer above a defined threshold requires validation through a second known channel, using a number that has already been registered. This rule also protects against calls impersonating an executive, which are becoming increasingly common.

3. Strengthen authentication for your administrative accounts and email. Two-factor authentication on Microsoft 365 and on tax and social security portals remains the measure that blocks the most attacks with the least effort. Also check who still has access to these portals: accounts belonging to former employees or a former accounting firm often linger longer than you might think.

If you'd like to discuss this matter objectively with someone who is familiar with your Microsoft environment, our team can work with you on it—see the contact page.

Not sure about your exposure?

Get an update from an IT Systems expert

A quick assessment of your exposure and the steps you should take. No obligation.

Request an exchange

Frequently asked questions

Should I change my impots.gouv.fr password? According to the DGFiP, this isn’t necessary—the stolen data does not grant access to the secure account. If you use this same password elsewhere, change it everywhere—but for a different reason: reusing passwords is an ongoing risk.

How can I tell if my business is affected? Through the official notification from the DGFiP, which began being sent out on August 17. A message claiming that you have been targeted and asking you to “confirm your information” is almost certainly a scam.

Do you need to report this to the CNIL? No, the breach involves the government’s processing of data, not yours. Your obligation applies only if the data of your own customers or employees is affected.

In a nutshell

A breach of the tax information system has exposed the data of 678,000 users, including businesses, though the scope of the breach is limited to SIREN numbers and addresses. The danger does not lie in the data itself but in what can be done with it—namely, fraudulent messages and calls that will be significantly more convincing in the coming weeks.

Three simple steps are all it takes to mitigate most of the risk: notify your teams, require double verification for wire transfers, and enable two-factor authentication. These are easy to implement, and once in place, they provide protection far beyond this specific incident.

— Samir Amara, CEO — IT Systèmes

Our latest articles

See more
software
Development & automation

"I'm afraid to install software"

1996: my first steps with Excel, using it to organize cheat codes—the start of a passion for office software. But what happened next?
August 13, 2026
fishing
Cybersecurity

Phishing 2026: Definition, Examples, and Protection for Small and Medium-Sized Businesses (Comprehensive Guide)

Spear phishing, BEC, voice deepfakes: why training alone isn’t enough, the true cost of an incident (€275,000), and the security measures that will work in 2026
August 12, 2026
SaaS
Development & automation

What is SaaS?

SaaS (Software as a Service) is software accessible online via a subscription, without the need for installation or a local server. Definition, how it works, and examples.
August 17, 2026