← All articles

redaction

DGFiP: 600,000 tax records for sale — warning on stealth exfiltration

On 14 August 2026, France’s Finance Ministry confirmed a DGFiP breach with over 600,000 tax records exported. A stealth exfiltration via a spoofed VPN, fueling targeted fraud risks.

On 14 August 2026, France’s Finance Ministry (DGFiP) confirmed a cyberattack and data leak following a claim posted on a criminal forum on 12–13 August 2026. An actor allegedly accessed an internal tool via VPN, flagged “late June,” yet managed to extract data without immediate detection.

The dataset advertised for sale includes just over 600,000 records (individuals and companies). Samples reviewed reportedly contain addresses, phone numbers, tax reference income, tax rate, household parts and correspondence metadata (local office, handling agent). The ministry announced a criminal complaint and CNIL notification. No public ransom demand so far; the main impact is expected from targeted fraud leveraging these details.

The facts

Key dates: claim on 12–13 Aug 2026; official confirmation on 14 Aug 2026. Volume: >600,000 records. Authorities: DGFiP, ANSSI, CNIL. Risks: financial scams, tailored phishing, impersonation.

In context, 2026 advisories (e.g., FICOBA) warned about fraudulent SEPA debits and banking recourse, framing the “economic” exploitation risk after mass leaks.

Legal framework

  • GDPR — Articles 32 (security), 33 (supervisory notification within 72h), 34 (inform individuals if high risk). See the relevant GDPR obligations.
  • French criminal law — Complaint for unlawful access and data sale.
  • NIS 2 — Governance and reporting timelines (24h / 72h / 1 month) as resilience benchmarks, also informing public sector and suppliers. Reference: the NIS 2 requirements.

What this changes for Luxembourg companies

  • Immediate operational threat: expect more plausible emails/SMS/calls (real amounts, tax references) targeting finance, HR and executives.
  • French and cross‑border third parties: your payables processes may be weaponized (IBAN changes, public‑agent impersonation, targeted extortion).
  • Regulatory timelines: for LU essential/important entities, any significant incident tied to this leak may trigger NIS 2 sequencing (24h / 72h / 1 month), alongside possible GDPR notices (Arts. 33/34).

Immediate actions this week

Block “payment fraud” avenues

  • Freeze any IBAN/vendor change without out‑of‑band call‑back to a verified number.
  • Set ERP/TMS rules: alerts for new beneficiaries, atypical amounts, urgent international wires.

Harden remote access and detection

  • Enforce phishing‑resistant MFA (FIDO2/WebAuthn); revoke stale accounts/certs; role‑based access; logging with monthly reviews.
  • Deploy DLP/NDR/UEBA rules for “low‑and‑slow” exfiltration and enable 24/7 SOC alerts with isolation playbooks.

Protect executives and payables teams

  • Brief C‑suite, CFO, procurement, treasury and helpdesk: realistic scam scripts, do‑nots, single escalation channel.
  • Run a tax‑themed simulated phishing and awareness campaign; measure and document (GDPR Art. 32, NIS 2 Art. 21).

Be “notification‑ready”

  • Pre‑fill 24h / 72h / 1‑month (NIS 2) and GDPR (Arts. 33/34) templates; identify DPO/points of contact; list evidence (logs, timestamps, egress flows).
  • Test the call tree and external messaging to staff/suppliers upon detected attempts; align with cyber insurance.

Sources

  • Le Monde — 14 Aug 2026.
  • Banque de France — 20 Feb 2026.

Article generated by Luxgap regulatory watch. For tailored guidance on this topic, contact us.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →