Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 9 sources · 28 days · First seen · Last updated
Cybersecurity breaches targeting French fiscal data
Overview
In September 2026, a sophisticated phishing campaign was identified in France targeting cryptocurrency holders. The scam utilized fraudulent physical mail impersonating the Direction générale des Finances publiques (DGFiP) to instruct recipients to scan QR codes via fake digital asset portals. These fraudulent documents used official logos and administrative language to threaten fines, potentially leveraging personal information linked to a January 2026 Colis Privé data breach.
By October 2026, the situation escalated as the DGFiP itself was hit by a cyberattack. This breach compromised the personal and fiscal data of approximately 700,000 individuals and businesses, including tax references and property information. An investigation by Anssi revealed that the agency had not consistently implemented strong authentication measures. During this same period, the e-commerce retailer LDLC also reported a cyberattack that exposed customer names and contact details, further highlighting cybersecurity vulnerabilities in the region.
Entities
ANSSI · Colis Privé · LDLC · Direction Générale des Finances Publiques · CNIL
Timeline
-
[TECHNOLOGY] 7 sourcesCyberattacks hit French tax authority and LDLC retailer
Cyberattacks on France's DGFIP and e-commerce retailer LDLC have exposed personal and fiscal data, highlighting critical vulnerabilities in authentication and cybersecurity protocols.
-
[TECHNOLOGY] 3 sourcesFrance: Fake DGFiP mail targets crypto holders via phishing
Fraudsters in France are using fake DGFiP paper mail to target cryptocurrency holders. The scam uses QR codes to steal data and may be exploiting a massive Colis Privé data breach from January 2026.
Sources
actusen.com · cryptoast.fr · emarketerz.fr · entrevue.fr · la-thierache.fr · Lalsace.fr · mondediplomatique.fr · upday.com · votre-actualite.com