What happened
France's Economy Ministry confirmed on August 14 that attackers breached systems at the Directorate General of Public Finances, the DGFiP, and extracted data on individuals and businesses. The intrusion happened in late June, when someone gained access by stealing or misusing a legitimate identity, and was detected and cut off that same month. It became public only after a hacker using the alias ZeroBytes claimed the attack on August 12 and listed a database for sale on a hacking forum, claiming records on more than 600,000 individuals. The stolen data reportedly includes names, tax identification numbers, email addresses, family circumstances, and tax status details, plus company names and registration numbers for businesses. The DGFiP says affected people will be contacted individually, and it has notified France's data protection regulator and filed a criminal complaint.
Why it matters for your business
Two lessons travel well across the Atlantic. First, the way in was not exotic malware; it was a stolen or misused identity, the same credential-abuse playbook that works against small businesses every day. Whatever your size, the accounts with access to sensitive records are the target, and MFA plus prompt offboarding of old accounts is the defense. Second, breaches of tax agencies reliably fuel a wave of tax-themed phishing far beyond the affected country, because criminals know the headlines make official-looking messages believable. Expect IRS, state-tax, and refund-status lures in the coming weeks even if your business has no French connection, and remind your bookkeeper that tax agencies do not initiate requests for credentials or payment details by email. Notice, too, that the agency learned the full scope was public when the criminal advertised the data; knowing what data you hold, and who can touch it, is what makes your own incident response faster than that.
