What DGFiP actually lost

The intrusion into France's Direction Generale des Finances Publiques began on June 26, 2026, when an attacker used stolen credentials belonging to a DGFiP employee and a separate authorized third party to access the agency's systems. Internal controls cut off that access before the end of June, and the Ministry of Finance's official communique states the exposed data covers roughly 678,000 individuals and businesses - close to the 678,438 lines the attacker himself later claimed. For individual taxpayers, the exposed fields are full names, family quotient classification, reference taxable income and withholding tax rate; for businesses, the SIREN registration number, business address and the address of the authorized representative.

DGFiP has stated that no secure taxpayer accounts on the impots.gouv.fr portal were compromised, so the data does not by itself grant access to anyone's live tax filings. But the agency itself described the intrusion as more sophisticated than anything it had previously faced, and the exposed fields - income level, tax rate, family situation, business registration and address data - are precisely the kind of detail that makes a follow-up phishing call or fraudulent email convincing.

Forty-eight days from cutoff to public disclosure

The timeline that matters here is not the intrusion itself but the silence afterward. DGFiP cut off the attacker's access at the end of June, and the breach stayed unannounced until August 12, when the attacker posted his own claim of the data theft. Only the following day, August 13, did the Ministry of Finance issue an official communique confirming the intrusion, stating that DGFiP would notify the CNIL, France's data protection authority, and file a criminal complaint with the Paris prosecutor's office, which has since opened an investigation involving OFAC, the national cybercrime unit.

That 48-day gap is legal under the letter of GDPR: the regulation's 72-hour clock applies only to notifying the supervisory authority, not to notifying the individuals affected, who are owed disclosure only 'without undue delay' when a breach presents a high risk - a standard with no fixed number attached. Public Accounts Minister David Amiel has since asked DGFiP to notify the affected taxpayers directly and to propose reinforced security procedures, but that request came after the attacker's own post forced the agency's hand, not before it.

The fine that does not apply to the fine-payer

Here is the asymmetry a private-sector operator should sit with: under the French law that implements GDPR, a company that handled a breach the way DGFiP did - compromised third-party credentials, weeks of silence, disclosure only after the attacker went public - could face CNIL fines of up to 10 million euros or 2 percent of global annual revenue for failing to notify affected individuals without undue delay. The same legislation explicitly excludes 'treatments implemented by the State' from those administrative penalties. The mechanism that is supposed to make fast disclosure a matter of financial self-interest for every company DGFiP regulates simply does not exist for DGFiP itself.

A public-sector union raised exactly this question once the breach became public: without the attacker's own disclosure, when and how would affected taxpayers and businesses ever have learned what happened. That is not a hypothetical for the roughly 678,000 people and companies now holding a piece of information they did not have two months ago - and it is a direct governance lesson for any owner who assumes a government counterparty's data-handling incentives mirror the ones regulation imposes on their own company. They do not, and the gap only closes when the attacker decides to talk. Any business whose SIREN and registered address sat inside this exposure should treat the coming weeks as a live impersonation-fraud window, not a closed incident, regardless of how long DGFiP itself took to say so.