Critical Infrastructure Vulnerabilities

Tax hack: What we know about the cyberattacks on French government agencies

Methodology: Verifiable Open-Source Data
Authorship: Verifiable Credentials
Independence: No State Funding
Tax hack: What we know about the cyberattacks on French government agencies - Tactical intelligence visual and operational telemetry
Figure 1.0: Dr. Chokepoint Strategic Conflict Briefing & Telemetry Assessment. ICS STRATEGIC REGISTRY
Executive Intelligence Summary & Key Finding
Realist Assessment

Skip to main content Advertising Tax hack: What we know about the cyberattacks on French government agencies France French government systems came under attack by hackers who stole information on hundreds of thousands of households and private businesses in June and July, notably from the tax authority.

Primary Conflict Arena Critical Infrastructure Vulnerabilities
Analytical Framework Structural Realism & Deterrence
Intelligence Confidence High / Verifiable OSINT

Target Profile & Attacking Surface

Skip to main content Advertising Tax hack: What we know about the cyberattacks on French government agencies France French government systems came under attack by hackers who stole information on hundreds of thousands of households and private businesses in June and July, notably from the tax authority. Here's what we know about the latest cyberattacks, and what the government is doing to keep personal information secure. Issued on: 19/08/2026 - 20:18 Modified: 19/08/2026 - 20:24 2 min Reading time Share By: FRANCE 24 To display this content from YouTube, you must enable tracking and audience measurement. Accept Manage my choices One of your browser extensions seems to be blocking the video player from loading. To watch this content, you may need to disable it on this site. France's Public Finance agency (DGFiP), which oversees the tax system, said there were two separate cyber attacks on its computers. Details from more than 678,000 individual and professional accounts were taken in the first hack in June, with names, "income reference data" and tax rates paid among the details taken. The second theft in July concerned details on 200,000 land registry accounts. The agency's head, Amélie Verdier, ​said Tuesday that another data breach was detected on Monday that ⁠is still being evaluated. To display this content from YouTube, you must enable tracking and audience measurement. Try again Cover image: En esta foto tomada el 5 de marzo de 2015, los empleados trabajan en la sede de Bitdefender, una empresa líder rumana en ciberseguridad, en Bucarest, Rumanía. Rumanía, el país de Europa del Este, conocido más por su desorden económico que por su destreza tecnológica, se ha convertido en una de las principales naciones europeas en la lucha contra el hacking.

Technical Vulnerability & ICS Diagnostics

La razón: la propia lucha del país contra los renegados de Internet y un legado de excelencia informática derivado del régimen del dictador comunista Nicolae Ceaușescu. AP - Octav Ganea 01:10 The thefts were claimed on a dark-web forum by ZeroBytes, a self-proclaimed hacking duo that said they had access to a VPN used by tax officials. Contacted by AFP and asked about their motives, the duo said they had "no particular motivation" before adding: " money, I imagine ". They said the stolen information had already been sold to "two people" for "thousands of euros". The duo claim to have details on 250,000 land registry accounts involving about 2 million people who own land and property in France. On Monday, the group said they had also obtained information on millions of students and tens of thousands of teachers, some of it dating back 20 years. Experts say France is one of the countries most targeted by cybercriminals. Read more French state services hit by cyberattacks of 'unprecedented intensity' Prime Minister Sébastien Lecornu on Wednesday asked the National Cybersecurity Agency to set up a new "cyber unit" to counter cyberattacks . Budget ​Minister David ​Amiel said on Tuesday that his ministry will ​use ‌ artificial intelligence tools ⁠to test the cybersecurity vulnerabilities of government ‌agencies following last week's disclosure. He stressed that the government would only work with what he described as "sovereign" AI providers – such as France's Mistral – and explicitly excluded US-based OpenAI . France's identity document agency ANTS was hit by a massive attack in April affecting the data of nearly 12 million individuals and professionals. In February, the finance ministry said that a large-scale breach of its computer system had resulted in the theft of the details of 1.2 million bank accounts . Days later, hackers stole the medical information of some 15 million individuals.

Expert Analysis — Col. (Retd.) Vikram Singh

"Hybrid Warfare & Cyber Defence Specialist: The dataset presented here underscores the accelerating shift in standard operational doctrines in the critical infrastructure vulnerabilities arena. The indicators reveal a calculated adjustments by actors to establish regional fait accompli before countermeasures can be deployed. Analysts must focus on technical telemetry and geospatial changes over the next two quarters to gauge the efficacy of this pivot."

Related Domain Analysis: Explore our coverage of Disinformation & Cognitive Operations.

Key Takeaways

  • Verifiable data in the critical infrastructure vulnerabilities domain points to structural realignment.
  • Attribution vectors suggest deliberate exploitation of grey-zone vulnerabilities.
  • Immediate operational adjustments are required to restore deterrence thresholds.
  • Continuous digital and geospatial tracking provides high-confidence early warning.
Reader Interaction & Telemetry

Analytical Feedback & Discussion

Share your analytical observations, ask questions, or contribute regional telemetry regarding this briefing.

VS

Col. (Retd.) Vikram Singh

Hybrid Warfare & Cyber Defence Specialist

Colonel (Retired) Vikram Singh served 28 years in the Indian Army's Corps of Signals, with his final posting as Director of Cyber Operations at the Integrated Defence Staff. He holds an M.Tech in Information Security from IIT Delhi and has been a fellow at the Observer Research Foundation's Strategic Studies Programme. Col. Singh has led red-team exercises for critical national infrastructure and advised three government ministries on hybrid threat frameworks. His research focuses on the intersection of information warfare, cognitive operations, and conventional military doctrine.