In summary. The DGFiP’s information system was breached in late June 2026: 678,000 users—both individuals and businesses—had some of their tax data exposed. For an SME, the immediate risk is not the loss of the impots.gouv.fr account, but the use of this data to make a fraudulent email or phone call appear credible.
What Happened
An attacker gained unauthorized access to the information system of the Directorate General of Public Finance in late June 2026 by impersonating someone else. The agency initially reported that several hundred thousand users were affected, but later revised the figure to 678,000 individuals and professionals, as announced on August 14.
On August 15, the Paris Public Prosecutor’s Office opened an investigation and assigned it to the Cybercrime Unit. Prime Minister Sébastien Lecornu is chairing an interministerial crisis task force this Monday, August 17, primarily to organize the notification of those affected, which was scheduled to begin that same day.
The DGFiP is specific about the nature of the data. For individuals: name, family quotient, reference taxable income, and withholding tax rate. For businesses, the data is less sensitive: SIREN number, business address, and representative’s address. The administration states that this information does not grant access to the secure account on impots.gouv.fr.
Does this apply to me?
If your company is among the affected accounts, you will receive a notification from the DGFiP. Warning: this is exactly when scammers will strike. Campaigns of fake emails mimicking addresses ending in “@dgfip.finances.gouv.fr” are already circulating, promising a tax refund and asking you to fill out a form. Several thousand people have fallen for this scam in recent months, even before this incident.
Secondary exposure is a real risk, even if the stolen data seems innocuous. A SIREN number, a registered office address, and the name of the CEO make it possible to craft a message that no longer looks like spam: the right contact person, the right references, and the right tax context. This is the classic fuel for a wire transfer scam or an urgent “adjustment” request sent to your accountant.
Important note: There is no indication at this point that passwords or bank account information have been leaked. Therefore, there is no need to reset all your login credentials. The issue here is the credibility given to these attempts at manipulation.
What to Do Now
1. Notify anyone who handles money— accountants, executive assistants, and executives—and let them know in a single sentence that a wave of messages purporting to be from the tax authorities is likely in the coming days. A government agency never requests bank account information or payment via email or phone. Any refund request should be verified by logging in to impots.gouv.fr yourself; never through a link you’ve received.
2. Secure the wire transfer process. The best defense here isn’t technical. Establish this rule: any change to bank account information and any wire transfer above a defined threshold requires validation through a second known channel, using a number that has already been registered. This rule also protects against calls impersonating an executive, which are becoming increasingly common.
3. Strengthen authentication for your administrative accounts and email. Two-factor authentication on Microsoft 365 and on tax and social security portals remains the measure that blocks the most attacks with the least effort. Also check who still has access to these portals: accounts belonging to former employees or a former accounting firm often linger longer than you might think.
If you'd like to discuss this matter objectively with someone who is familiar with your Microsoft environment, our team can work with you on it—see the contact page.
Not sure about your exposure?
Get an update from an IT Systems expert
A quick assessment of your exposure and the steps you should take. No obligation.
Frequently asked questions
Should I change my impots.gouv.fr password? According to the DGFiP, this isn’t necessary—the stolen data does not grant access to the secure account. If you use this same password elsewhere, change it everywhere—but for a different reason: reusing passwords is an ongoing risk.
How can I tell if my business is affected? Through the official notification from the DGFiP, which began being sent out on August 17. A message claiming that you have been targeted and asking you to “confirm your information” is almost certainly a scam.
Do you need to report this to the CNIL? No, the breach involves the government’s processing of data, not yours. Your obligation applies only if the data of your own customers or employees is affected.
In a nutshell
A breach of the tax information system has exposed the data of 678,000 users, including businesses, though the scope of the breach is limited to SIREN numbers and addresses. The danger does not lie in the data itself but in what can be done with it—namely, fraudulent messages and calls that will be significantly more convincing in the coming weeks.
Three simple steps are all it takes to mitigate most of the risk: notify your teams, require double verification for wire transfers, and enable two-factor authentication. These are easy to implement, and once in place, they provide protection far beyond this specific incident.
— Samir Amara, CEO — IT Systèmes



