Back to Blog
high severity August 17, 2026 · 4 min read Unverified claim — what this is

French tax data stolen: 678,000 people affected — what it means for you

If you have an account with French tax, here’s what is being claimed, and what it would mean for you.

On 14 August 2026 France’s finance ministry confirmed that attackers used stolen staff logins to view and copy tax and property data on 678,000 people and businesses. Tax-website passwords were not taken. Official emails and letters to those affected were due to start the following week.

— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
French tax data stolen: 678,000 people affected — what it means for you

On 14 August 2026, France’s Ministry of the Economy and Finance confirmed that attackers had got into the tax authority’s systems — the DGFiP — in June and July 2026. They used stolen login details belonging to a tax-office employee and an authorised outside partner. The ministry says those logins were then used to consult and extract data on a total of 678,000 individuals and professionals.

Already exposed?
You can’t unleak a breach. You can take away what it’s worth.
Deep Sweep shows you every leak tied to you and exactly what to change. Then it strips your name, address and family off the look-up sites that turn a leaked record into somebody knocking on your door — $29 one-time, includes 30 days of Protection. We write to 582 companies. No subscription to start.
Scan free, then Deep Sweep — $29 →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

That data included tax figures such as reference tax income (the official income figure used for tax), family quotient and withholding-tax rate; for businesses, the company name or SIREN number; and land-registry details covering property addresses and sizes. Accounts on the tax portal, and users’ identifiers and passwords, were not compromised. The DGFiP notified the privacy regulator (the CNIL), added extra security measures, and said it would file a complaint. Starting the week after the announcement, it planned to contact each affected person and business by email or letter, saying what may have been viewed or copied.

The login is safe. That is not the same as the file being harmless.

Most coverage leads with two true points: 678,000 people, and your tax-site password was not stolen. Both matter. Nobody should be able to walk into your account on the tax portal because of this incident.

What that framing leaves sitting in the open is the combination that was taken. A stranger who has a name, a tax identifier, the income figure the state uses, a snapshot of the household (the family quotient), a withholding-tax rate, and a land-registry address with the size of the property does not need a password to make trouble. That package is enough to write a fake tax letter that cites real numbers, to sound official on the phone once a number is found somewhere else, or to sort people by apparent means and a known home address.

The land-registry piece is easy to skim past. It is not an abstract code. It is an address, and a surface area. Read next to income data, it is a short note on who lives where and what they might have.

The honest read is not that bank accounts will be emptied tonight. It is that, if you are in this group, a copy of that tax-and-property snapshot cannot be pulled back, and it is exactly the kind of detail tax-scam letters and calls are built from. The ministry did not list personal phone numbers among the extracted fields. Investigations are still trying to pin down the exact volume of data and the exact number of people, so 678,000 is the confirmed figure for now, not a final lock.

What to actually expect

  • If the DGFiP believes your data was viewed or copied, you should hear by email or letter, starting the week after 14 August 2026. That message should name the fields and any vigilance steps they recommend. That is how you find out. There is no public list to search.
  • The 678,000 figure can still move. The ministry itself said it is still establishing the precise nature and volume of data extracted and the exact number of people concerned.
  • Expect copycat messages that mention a tax leak and ask you to click, call, or “confirm” something. A genuine follow-up from the tax office about this incident should not ask for your password or for a payment.
  • Do not expect the stolen copy to be taken down. Telling the CNIL and filing a complaint does not put the data back.

What you can and cannot fix

If your name, tax identifier, income figures, family quotient, withholding rate, or property address and size were extracted, that copy is out. It cannot be recalled. A home address and a tax identifier do not expire, and nobody can delete the attacker’s file.

What actually helps, in order:

  • Treat the official DGFiP email or letter as the only reliable account of what was taken in your case. Keep it. Do not add extra personal details for anyone who contacts you first and claims to be following up on the breach.
  • Assume that a caller or a message who already knows your reference tax income or your withholding rate is not thereby proven to be the tax office. Those figures are part of what was confirmed stolen.
  • Cut back the extra public information that makes a leaked tax record usable. Directory and people-search listings often bolt a phone number, relatives, an employer and previous addresses onto a name and a home address. A bare tax file becomes much more dangerous once it can be joined to a working phone number or a family tree. Unlike the stolen tax data, those listings can actually be removed or suppressed — that is the lever that is still in your hands.
  • There is no reliable website check that can tell you whether you were in this incident. A “clear” result would not mean you were spared. The signal is the official letter or email — or not receiving one after a reasonable wait, knowing the count is still being refined.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
French tax is one breach. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed August 17, 2026
Affected Unconfirmed
Data exposed Full namesTax identifiersReference tax incomeFamily quotientWithholding-tax ratesCompany namesSIREN numbersHome addresses +1 more
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email