France
Government / Tax Administration
Data for Sale
French Tax Administration Allegedly Breached via Internal VPN, 678,000 Taxpayer Records Offered
A group posting as ZeroBytes claims to have breached the French tax administration's public portal and is selling a partial database of 678,438 records dated to June 2026. The actors state they obtained VPN credentials from internal servers, used them to reach an internal search tool covering both individual and business taxpayers, and began extracting data before being disconnected. They claim access to multiple internal tools and estimate the reachable population at tens of millions, while acknowledging the extraction was never completed. A sample of 1,126 records is hosted publicly. The actors further allege the intrusion was detected but never publicly acknowledged. The claim is unverified.
▣Post details
France!Claimed access
- Internal VPN credentials
- Individual taxpayer search
- Professional taxpayer search
- Multiple internal tools
- Partial data extraction
◱Screenshot
⚠Potential impact
Tax records are among the most sensitive holdings any state maintains, combining verified identity with income, property, household composition, and address. A taxpayer cannot opt out of the relationship, and tax identifiers cannot be reissued. Because the data is authoritative, it is also unusually effective for fraud impersonating the tax authority, a scam already common in France, since a caller can quote details only the administration should hold. The claimed vector matters as much as the data: VPN access to internal search tools is a position, not a one-off extraction, and the actors say what they took was limited only by being disconnected. If credentials were reused or persist, the exposure is not bounded by the 678,438 figure.
iStatus
UnverifiedThe post publishes no field list and no visible sample, only a record count and mirrored download links, which Dark Web Informer is not reproducing. The data is dated to June, roughly six weeks before the listing. The allegation that the intrusion was observed but never disclosed is the actors' own and is uncorroborated; under GDPR a confirmed breach of this scale would carry notification duties. Nothing has been independently verified. The claim is unverified and the tax administration has not publicly addressed it.
DARK WEB INFORMER - THREAT INTELLIGENCE