In the midst of the summer, French citizens were met with the unpleasant news that their personal and confidential data had once again been hacked. The incident, which occurred on the tax administration’s servers, took place in June but was not made public until mid-August.
The recurring leaks of sensitive data are causing considerable concern among the public, even as the government seeks to launch all sorts of digitization initiatives for both individuals and businesses. France has indeed become one of the most vulnerable countries in Europe.
Is the French government capable of protecting the ever-increasing amount of data it requires from its citizens?
A Series of Attacks
The first major incident dates back to late January 2026. A hacker managed to steal the login credentials of a government official with access to the Fichier des Comptes Bancaires (FICOBA), the national database that tracks bank accounts opened in France. The Direction Générale des Finances Publiques (DGFiP) announced the incident on 18 February.
Approximately 1.2 million accounts were affected, representing less than 1% of the database. The data accessed included the account holders’ identities and addresses, as well as their banking details, notably their IBAN numbers. However, tax identification numbers were reportedly not accessed, and the FICOBA database does not contain account balances or details of banking transactions.
The official response consisted of immediately restricting access, notifying the National Cybersecurity Agency (ANSSI) and the National Commission on Informatics and Liberties (CNIL) and filing a complaint. The banks were also alerted. The tax administration then individually notified the affected individuals.
The incident is nonetheless telling: the hacker did not need to break into the government’s banking database. All it took was gaining control of an authorized official’s login credentials.
Six months later, the same scenario played out again, this time on a potentially much more serious scale. In late June, a malicious actor gained access to the DGFiP’s information system after impersonating someone else. Access was cut off by the end of the month, but the administration did not immediately detect that data had been accessed and extracted.
The incident only became public on 12 August, when the hacker claimed responsibility for the attack and offered the data for sale online. The DGFiP confirmed the following day that a data breach had indeed occurred. Initial estimates indicate that approximately 678,000 people were affected. The exposed data includes in particular names, dates and places of birth, addresses, email and phone numbers, tax information and details regarding family status.
Cybersecurity and Transparency at Stake
The delay in reporting the incident is politically embarrassing. The administration claims to have blocked access as early as the end of June, but the public was not informed until after the hacker had published the data. However, data protection regulations stipulate that a breach posing a risk to rights and freedoms must be reported to the CNIL as soon as possible and, if possible, within 72 hours; any delay must be justified. When the risk is high, the individuals concerned must also be notified promptly.
The scandal raises a major issue not only of cybersecurity but also of transparency: how long can a government agency investigate before citizens’ right to know that they are at risk takes precedence?
The French Ministry of Education also experienced several incidents in 2026. In March, a breach linked to the compromise of an external account led to the exfiltration of data concerning approximately 243,000 staff members, including interns and tenured employees. In April, the ministry also acknowledged a cyberattack that compromised the data of certain students: last names, first names, login credentials for the ÉduConnect system, school, class, email addresses and – for some accounts – activation codes.
The attack originated from the compromise of an authorized staff member’s account and the exploitation of a vulnerability in the account management service. Information is now circulating about a possible new breach attributed to the same hacker involved in the June attack against the DGFiP.
Another particularly alarming claim is currently circulating: it reportedly concerns a file containing information that could identify more than two million property owners, including names, dates of birth, addresses, property identification numbers, cadastral parcels and information regarding real estate holdings.
The hacker even claims to still have access to the system and states that he halted the data extraction himself because it was deemed too slow. If these claims were confirmed, the scope of the incident would be considerable. The DGFiP’s land registry files do indeed make it possible to link property owners to their properties, parcels and property characteristics.
In the world of cyberattacks, there are sometimes significant discrepancies between hackers’ claims and the actual scale of data breaches. The ANSSI reports that only 42% of the 460 incidents reported in 2025 as potential data breaches were ultimately confirmed as actual breaches. However, silence or ambiguity in communications from government agencies automatically fuels suspicion.
Every Leak Makes the Next Attack More Dangerous
The recurrence of hacks exacerbates the problem because the databases – which are then resold online – continue to grow. A password can be changed, but an address, date of birth, net worth or tax history cannot. The data can be resold, cross-referenced with older hacked databases and used to orchestrate scams with frightening precision.
The danger is therefore cumulative: each data breach adds to the previous ones and contributes, piece by piece, to building an increasingly comprehensive digital profile of every French citizen. A fraudster who knows their victim’s name, address, tax status or bank details can make a fake bank or government call seem much more credible. The CNIL specifically warns of the risks of phishing and identity theft, which are likely to increase following data breaches.
France is not necessarily an isolated case of IT vulnerability. It is, however, a particularly attractive target. A study published by the website Surfshark estimates that half of hacked accounts in Europe are French. Its government is highly digitized and centralizes enormous volumes of data: identity, taxation, health, education, social benefits and property.
The situation is not likely to improve anytime soon, as the government is working on various projects to accelerate the digitization of its services for both individuals and businesses. Digital invoices will be compulsory from 1 September for French companies. Concern is growing, as the state does not seem to be willing to fully assess the associated risks: the sheer size of the attack surface, the complexity of legacy systems, the difficulties in recruiting cybersecurity experts in the public sector and, finally, human errors: two of the year’s most high-profile incidents involved the theft of legitimate login credentials.
Today, the government is asking citizens to entrust it with ever more information to help administer the country. In return, it must be able to guarantee three things: the security of this data, effective access controls and immediate transparency when the data is compromised. For now, none of these pillars is guaranteed for citizens.