Skip to content

French Cadastral Data Server Allegedly Breached, 2 Million Property Holders Exposed and Access Still Claimed

Breach Report France flagFrance Government / Land Registry Reported Live

French Cadastral Data Server Allegedly Breached, 2 Million Property Holders Exposed and Access Still Claimed

The group posting as ZeroBytes claims a second intrusion at France's Direction générale des Finances publiques, this time against the professional cadastral data server that holds land and property registry information. They describe 252,149 extracted rows covering 2,041,778 individuals, since each row can list several property holders, and estimate that around 20 million citizens were reachable through the system although extraction was never completed. Access is attributed to valid credentials combined with a multi factor authentication bypass, with no VPN required. The actors state they remain logged in and are offering that access for sale alongside the data. The claim is unverified.

People affected2,041,778
AccessClaimed ongoing
Rows252,149
ActorZeroBytes

Post details

TargetDGFiP cadastral data server
CountryFrance flagFrance
SectorGovernment / Property registry
ListingPartial database and access
Extracted252,149 rows
Breach dated29 July 2026
Observed
ActorZeroBytes

!Claimed access

  • Cadastral property records
  • Property holder identities
  • Multiple holders per parcel
  • Valid account credentials
  • Multi factor bypass
  • Continuing panel access
  • Wider unextracted population

Screenshot

Potential impact

Cadastral records establish who owns which property and where it is, which links named individuals to real assets at fixed addresses. That supports wealth profiling and physical targeting in a way ordinary contact data does not, and because several holders can appear against one parcel, it also exposes family and co ownership relationships. The more urgent element is the claim of continuing access. If accurate, the exposure is not bounded by the 252,149 rows taken so far, and the actors state the constraint was extraction effort rather than any control stopping them. A multi factor bypass would indicate the authentication layer did not hold.

iStatus

Unverified

This is the second claim against the same French tax authority from this group in two days. The 20 million figure is their estimate of what was reachable, not what was taken, and should not be read as a record count. A sample is hosted across three mirrors, which Dark Web Informer is not reproducing along with the contact channels. The assertion that the intrusion has gone publicly unacknowledged is the actors' own and is uncorroborated. The claim is unverified and the DGFiP has not publicly addressed it.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest