Skip to content

French Tax Administration Allegedly Breached via Internal VPN, 678,000 Taxpayer Records Offered

Breach Report France flagFrance Government / Tax Administration Data for Sale

French Tax Administration Allegedly Breached via Internal VPN, 678,000 Taxpayer Records Offered

A group posting as ZeroBytes claims to have breached the French tax administration's public portal and is selling a partial database of 678,438 records dated to June 2026. The actors state they obtained VPN credentials from internal servers, used them to reach an internal search tool covering both individual and business taxpayers, and began extracting data before being disconnected. They claim access to multiple internal tools and estimate the reachable population at tens of millions, while acknowledging the extraction was never completed. A sample of 1,126 records is hosted publicly. The actors further allege the intrusion was detected but never publicly acknowledged. The claim is unverified.

Records678,438
VectorInternal VPN
Breach datedJune 2026
ActorZeroBytes

Post details

TargetFrench tax administration portal
CountryFrance flagFrance
SectorGovernment / Taxation
ListingPartial database for sale
Records678,438 extracted
Sample1,126 records, public host
Observed
ActorZeroBytes

!Claimed access

  • Internal VPN credentials
  • Individual taxpayer search
  • Professional taxpayer search
  • Multiple internal tools
  • Partial data extraction

Screenshot

Potential impact

Tax records are among the most sensitive holdings any state maintains, combining verified identity with income, property, household composition, and address. A taxpayer cannot opt out of the relationship, and tax identifiers cannot be reissued. Because the data is authoritative, it is also unusually effective for fraud impersonating the tax authority, a scam already common in France, since a caller can quote details only the administration should hold. The claimed vector matters as much as the data: VPN access to internal search tools is a position, not a one-off extraction, and the actors say what they took was limited only by being disconnected. If credentials were reused or persist, the exposure is not bounded by the 678,438 figure.

iStatus

Unverified

The post publishes no field list and no visible sample, only a record count and mirrored download links, which Dark Web Informer is not reproducing. The data is dated to June, roughly six weeks before the listing. The allegation that the intrusion was observed but never disclosed is the actors' own and is uncorroborated; under GDPR a confirmed breach of this scale would carry notification duties. Nothing has been independently verified. The claim is unverified and the tax administration has not publicly addressed it.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest