[REVISION HISTORY]
French tax authority and FICOBA data breach
Updated 24 times since CLSTR started tracking revisions of this situation.
What changed
2026-09-07 06:47 UTC → 2026-09-10 20:56 UTC ·
added
removed
In mid-August 2026, the French General Directorate of Public Finances (DGFiP) confirmed a series of cyberattacks occurring throughout the summer. The most significant breach, occurring between late June and early July, was facilitated by the identity theft of an employee and the impersonation of an authorized third party. This intrusion, claimed by the hacking group ‘ZeroBytes’, resulted in the unauthorized extraction of sensitive data belonging to approximately 678,438 individuals and businesses, as well as roughly 200,000 cadastral accounts. Stolen information includes names, birthdates, addresses, phone numbers, email addresses, family status, and fiscal details. As the government implements a major tax reform requiring electronic invoicing, new security mandates have been emphasized. Starting September 1, 2026, large and mid-sized enterprises must use state-approved platforms to issue and receive electronic invoices. To mitigate future risks, the government is requiring these platforms to use the SecNumCloud label to ensure data remains on European soil. However, reports indicate nearly half of the affected companies have not yet begun the compliance process. Legal and criminal developments have accelerated. An 18-year-old suspect, believed to be a member of ‘ZeroBytes’ with a prior criminal record for cyberattacks, has been placed in pre-trial detention in Paris. He faces potential charges including organized criminal association and fraudulent data extraction, which could carry a 10-year prison sentence and a 300,000 euro fine. A second suspect, under the age of 16, was also detained but has since been released. Investigators are currently analyzing seized computer equipment. French Foreign Minister Jean-Noël Barrot confirmed he is among the victims. In response to the incident, the French government has initiated a 200 million euro plan to bolster the security of state information systems. Additionally, a collective of victims has launched a class-action lawsuit against the state seeking damages for security failures.
Versions
- 2026-09-10 20:56 UTC French tax authority and FICOBA data breach
- 2026-09-07 06:47 UTC French tax authority and FICOBA data breach
- 2026-09-05 09:14 UTC French tax authority and FICOBA data breach
- 2026-09-04 16:48 UTC French tax authority and FICOBA data breach
- 2026-08-27 19:05 UTC French tax authority and FICOBA data breach
- 2026-08-27 07:22 UTC French tax authority and FICOBA data breach
- 2026-08-26 15:28 UTC French tax authority and FICOBA data breach
- 2026-08-24 13:03 UTC French tax authority and FICOBA data breach
- 2026-08-23 04:51 UTC French tax authority and FICOBA data breach
- 2026-08-19 15:51 UTC French tax authority and FICOBA data breach
- 2026-08-18 18:32 UTC French tax authority and FICOBA data breach
- 2026-08-18 02:33 UTC French tax authority and FICOBA data breach
- 2026-08-17 22:08 UTC French tax authority and FICOBA data breach
- 2026-08-17 17:55 UTC French tax authority and FICOBA data breach
- 2026-08-17 16:06 UTC French tax authority and FICOBA data breach
- 2026-08-17 16:05 UTC French tax authority and FICOBA data breach
- 2026-08-17 11:55 UTC French tax authority and FICOBA data breach
- 2026-08-17 06:58 UTC French tax authority and FICOBA data breach
- 2026-08-16 22:32 UTC French tax authority and FICOBA data breach
- 2026-08-16 19:11 UTC French tax authority and FICOBA data breach
- 2026-08-16 16:33 UTC French tax authority and FICOBA data breach
- 2026-08-16 12:54 UTC French tax authority and FICOBA data breach
- 2026-08-16 04:23 UTC French tax authority and FICOBA data breach
- 2026-08-15 17:21 UTC French tax authority and FICOBA data breach
- 2026-08-15 14:58 UTC French tax authority data breach
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.