DGFiP data breach: 285,570 businesses’ tax data exposed — what it means for your SME
On August 13, 2026, France’s Ministry of Economy and Finance confirmed an illegitimate access to the DGFiP’s information system, after a hacker claimed to have extracted 678,438 lines of tax data — 285,570 of them belonging to businesses. What is confirmed so far, and the concrete precautions your SME should take now, whether or not you get an individual notification.
On August 13, 2026, the French Ministry of Economy and Finance confirmed an illegitimate access to the information system of the Direction générale des Finances publiques (DGFiP), France’s tax authority. The day before, an individual using the handle “ZeroBytes” had claimed, on a dark-web forum specialized in reselling stolen data, to have extracted 678,438 lines of tax records. The administration’s own checks confirm that unauthorized access, dating back to late June 2026 and obtained through identity theft, did allow consultation and extraction of data on individuals and businesses — the access was cut off at the end of June through operational controls, but the extraction had already happened by then. Of the 678,438 claimed lines, around 285,570 reportedly concern businesses: this is not only a private-citizen story, it is a leak that touches companies directly — potentially yours.
What is confirmed at this stage
- →Initial intrusion: late June 2026, via identity theft, according to the ministry’s official statement.
- →Public claim: August 12, 2026, on a dark-web forum.
- →Official confirmation: August 13, 2026, in a statement from the Ministry of Economy and Finance.
- →Claimed volume: 678,438 lines, of which roughly 392,867 reportedly concern individuals and 285,570 businesses.
- →Data reportedly exposed: name, postal and email address, phone number, family situation, reference taxable income, withholding-tax rate — a set of details precise enough to build a credible phishing message.
- →The DGFiP says it will notify the CNIL, file a criminal complaint, and individually inform the people and businesses whose data may have been consulted or extracted.
Why this is more than a news item
A tax-data leak is not just an abstract confidentiality problem — it is ammunition for targeted phishing. A now-classic 2007 study from Indiana University, published in Communications of the ACM by Tom Jagatic, Nathaniel Johnson, Markus Jakobsson and Filippo Menczer, Social Phishing, found that a phishing email containing real, contextual information about its recipient more than quadrupled the click-through rate compared to a generic message. An exact address, phone number or withholding-tax rate is enough to tip a fraudulent “tax authority” email from the spam folder into a message read and trusted. A separate study published in 2011 in the Journal of Policy Analysis and Management by Sasha Romanosky, Rahul Telang and Alessandro Acquisti, Do Data Breach Disclosure Laws Reduce Identity Theft?, establishes a statistical link between personal-data leaks and a rise in identity-fraud cases in the months that follow.
What it means for your SME
If your business is among the 285,570 professional accounts affected, you should receive an individual notification from the DGFiP — but there is no reason to wait for that letter before acting. The real risk for every SME, notified or not, is the use of this authentic data in CEO-fraud attempts, fake tax-regularization reminders, or requests to update bank details that impersonate the tax administration. The more accurate the details cited in a fraudulent message — a real address, a real withholding-tax rate — the harder it becomes for even a careful employee to tell, in a few seconds, a legitimate email from a well-informed scam.
Concrete steps to take now
- →Check whether your business has received, or is likely to receive, a notification from the DGFiP — without waiting for that letter to raise your team’s vigilance in the meantime.
- →Remind everyone who handles accounting or dealings with the administration of a simple rule: no change to bank or payment details is ever made on the strength of an email alone, even one signed “tax office” — a verification call to the usual, official contact number is always required.
- →Never click a link inside an email to reach your impots.gouv.fr account — always type the address directly into the browser.
- →If inbound email volume justifies it, an email-triage agent can filter out the crudest phishing attempts before they reach an employee’s inbox — a useful watchdog, but never a substitute for the human verification reflex on financial requests.
- →Follow upcoming communications from the CNIL and the DGFiP on this case — the exact scope of the leak is still, at this stage, under investigation.
This incident creates no new regulatory obligation for your SME — you are not responsible for the compromised system. But heading into September and the September 1 e-invoicing deadline, it is a reminder of a simple rule: the more sensitive data the administration and its providers handle about your business, the more vigilance about what lands in an inbox “from the administration” needs to stay a team reflex, not just a line in an IT policy.
Frequently asked questions
How many French businesses are affected by the DGFiP data leak?+
Of the 678,438 lines of data the hacker claims to have extracted from the DGFiP’s information system, around 285,570 reportedly concern businesses, based on information available as of August 14, 2026. The Ministry of Economy and Finance confirmed an illegitimate access on August 13, 2026, but the exact scope remains under investigation.
What will the DGFiP do for the businesses affected?+
The DGFiP says it will notify the CNIL of the incident, file a criminal complaint, and individually inform the people and businesses whose data may have been consulted or extracted, along with recommended precautions.
What is the real risk for an SME that is not directly notified?+
Even without an individual notification, every SME is exposed to targeted phishing that uses authentic details from this leak to make fake tax-administration messages more convincing — regularization demands, requests to change bank details, and similar scams.
What should an SME verify before acting on an emailed request to change bank details?+
Never process a change of bank or payment details on the strength of an email alone, even one signed by the tax administration — a verification call to the usual, official contact should always precede any change.
Free resource
The self-assessment grid: 20 tasks AI can automate
Sales, admin, support, operations: the 20 tasks AI agents already handle in SMEs — with, for each one, the tell-tale sign that your team is concerned.
Read next
Business & compliance
EU AI Act: what became mandatory on August 2, 2026 — and what it means for your SMB
19 August 2026·5 min read
Business & compliance
Claude now watermarks its text: what Anthropic’s move changes — and doesn’t — for your SMB’s AI content
18 August 2026·5 min read
Business & compliance
Computer History: ChatGPT now remembers your activity — except in France (for now)
17 August 2026·5 min read