France’s Tax Agency Hacked: A State That Demands Everything and Protects Nothing

In late June 2026, someone logged into the information system of France’s Directorate General of Public Finances using the credentials of a civil servant, then those of an authorized third party. He browsed. He extracted. An internal control eventually cut off the access, and then nothing happened: no one thought to ask what had left the building. It would take until August 12, when a hacker calling himself ZeroBytes claimed the haul on a criminal forum, for the Finance Ministry to understand what had hit it. France’s data protection authority, which should have been notified within seventy-two hours, learned of the breach nearly two months late. Detection did not work here. The thief’s bragging did.

The official toll, revised upward day after day: 678,000 individuals and businesses in the first wave. Names, addresses, reference taxable income, family quotient, withholding rates, company registration numbers. Then came the professional land registry server, where the tax agency announced 200,000 affected accounts before correcting itself to 1.8 million, a figure suspiciously close to the hacker’s own count. Then the portal for unclaimed estates, where a vulnerability flagged by the LunarisSec collective reportedly exposed personal data with no authentication required at all.

Back in May, I wrote that France was suffering one data breach per hour and that the state kept refusing the architectures that would render those breaches harmless. Three months later, the demonstration has arrived under live conditions, and it is the country’s single largest data holder that volunteered for the experiment.

A Museum of Horrors

Look at the remediation plan the Finance Ministry announced on August 18. It is worth more than any audit. Multi-factor authentication to be extended to all staff by year’s end. Consultation quotas to be generalized, having until now applied only to the national bank account registry. Detection sensors to be deployed on systems that still lack them. A complete overhaul of anomaly detection on valid accounts.

Read that list backward and you have the state of play as of June 2026. No MFA. No consultation caps. Systems running blind. No behavioral monitoring on staff accounts. In plain terms: a stolen username and password were enough to roam through French tax records, with no ceiling, no alarm, no second factor.

Director General Amélie Verdier has explained that the attack was sophisticated: no mass automated querying, no detectable anomaly in the volumes consulted. Let us take her at her word, because the claim is unfalsifiable by construction. You cannot detect an anomaly with tools you do not own. That leaves exactly two readings. Either the monitoring existed, the access was flagged as suspicious enough to be severed, and no one pushed the investigation far enough to find the exfiltration, in which case detection worked and incident response collapsed. Or the monitoring never really existed, and “no detectable anomaly” means “nothing in place to detect one.” Both readings are damning. Behavioral analytics on user accounts, least privilege, correlated logging: all of it has existed for fifteen years, all of it can be bought and deployed. Elsewhere.

As for NIS 2, the European directive meant to raise the cybersecurity floor for public administrations, France still has not transposed it, nearly two years past the deadline set in Brussels. The state penalizes in others what it tolerates in itself. Any private health data host would be stripped of its certification for a tenth of this record.

The Asymmetry Is the Scandal

This breach would be a minor administrative embarrassment if it had not landed at the worst possible moment for official doctrine. Because while the tax agency was being emptied by a man with two passwords, the same state was putting the finishing touches on the largest economic surveillance apparatus in its history.

Mandatory electronic invoicing means real-time tax auditing: every business-to-business invoice, every cash flow, every margin of every French company, centralized and transmitted. I have already described what that system creates: 115 targets for the price of one once you count the certified platforms, and an intelligence goldmine handed to anyone with the wit to mine it. On the household side, DAC8 will require the declaration of crypto holdings, and I have shown what such files become when they leak: target lists for kidnappers. Thanks to this breach, the fraudster who calls you now knows your exact income, your family quotient and your address. Tomorrow, with land registry data loose for 1.8 million property owners, he will know what you own as well.

There is the asymmetry: a duty to hand over everything on one side, a demonstrated inability to safeguard it on the other. The state demands total transparency from the governed while granting itself total opacity about its own failures, to the point of waiting for a criminal to publish the loot before informing the regulator. Every centralized file is a breach waiting to happen, and the only data whose security is guaranteed is the data never collected. The cryptographic architectures that let you prove a fact without revealing the underlying record already exist. I have described them. The state does not want them, because its goal was never verification. It was possession.

Who Builds It, and Who Profits

Which leaves the question no one will ask at a press conference: who designs, builds and operates these systems?

Not the ministry’s own engineers alone, that much is certain. French public sector IT has run on outside contractors for twenty years, inside an ecosystem whose habits I have documented at length: the McKinsey nexus, the revolving door the Senate will never inventory, the agencies that fatten the consultancies. Major programs are carved into public contracts captured by a handful of the same integrators. The code is written by juniors billed at senior rates, supervised by project managers who rotate out every eighteen months, against specifications drafted by people who will never see production. This is my thesis and I own it: cascading subcontracting produces systems that no single person understands end to end, and therefore systems that no one knows how to defend. Security is an engineering culture, and a culture cannot be outsourced.

The news cycle has offered a fitting symptom. At the very moment the ministry was managing its crisis, the ransomware group Everest claimed to have compromised a data repository tied to Capgemini Engineering: 13 GB and more than 720,000 files, largely historical archives from Altran, source code, recruitment files and public sector project documents included. Let us be precise: the claim is unconfirmed by the company, the data is mostly old, and nothing links it to the tax agency breach. But the broader picture stands. The consulting giants that bill the French state for its digital transformation cannot always protect their own archives. The cobbler’s children go barefoot, and the cobbler is the one shoeing the Republic.

Paper Sovereignty

We are told about sovereign cloud, sovereign AI, commissions for digital sovereignty. A state that cannot tell who is querying what inside its own databases is not sovereign. It is a tenant in its own information system, and the landlord’s name is now ZeroBytes.

So no, the answer is not another remediation plan. The answer is a principle: until the state can prove it knows how to protect what it already holds, it has no legitimate claim to more. Suspend the electronic invoicing vacuum. Freeze DAC8. Minimize collection. Deploy, at last, the architectures that prove without revealing. The 678,000 affected taxpayers will receive an advisory email. Those responsible will most likely receive a promotion. It is the one mechanism of the French state that never fails.


Écrivez quelques éclats d'âme...

Dans l'ombre vacillante d'une chandelle, où les murmures du vent se mêlent aux secrets d'un vieux parchemin, je vous invite à tisser une toile de mots. Écrivez quelques éclats d'âme – rêve, étoile, abîme, étreinte, brume – et laissez-les danser sur la page, comme des lucioles dans une nuit d'encre. Que diriez-vous de les entrelacer dans une phrase, un souffle, une histoire ?

Subscribe
Notify of
guest
0 Commentaires
Oldest
Newest Most Voted