Skip to content

DGFiP hack: the 5 reflexes to adopt right now (even if you are not affected)

In short: On August 14, 2026, the DGFiP confirmed the theft of tax data affecting 678,000 users, claimed by the ZeroBytes group. The compromised data (tax number, reference tax income, contact details) enables ultra-targeted scams. Five reflexes are enough to remove most of the risk: never click on any link received by email that claims to be "from the tax office", access your account by typing the address yourself, refuse any incoming RIB change, enable strong authentication, and keep the evidence in case of an incident. The CNIL recommends filing a complaint even without proven loss.

On August 13, 2026, the DGFiP, the French tax authority, announced an intrusion into its systems; the next day, the damage was confirmed: 678,000 tax accounts exposed, and bank data (Ficoba) potentially affected since February. For the first time, cybercriminals are claiming access to mass tax data in France. If you are an SME or a freelancer, you are the preferred target: your tax data is precise, recent and actionable. Here are the 5 reflexes that really matter, explained simply.

Reflex no. 1: never click on a link claiming to be from the tax office

In short: The first scam after this type of leak is hyper-personalized phishing.

The first scam after this type of leak is hyper-personalized phishing. The attacker holds your tax number, sometimes your reference tax income and your withholding rate: their messages look credible.

The reflex: never click on any link in an email or text message supposedly sent by the tax office. Always access your account by typing `impots.gouv.fr` yourself in the browser. If a refund is announced, it will appear in your account, not in an email.

Reflex no. 2: refuse any incoming RIB change

In short: This is the most dangerous scenario for businesses: an email that seems to come from your bank, your accountant or a partner asks you to update your bank details for a payment.

This is the most dangerous scenario for businesses: an email that seems to come from your bank, your accountant or a partner asks you to update your bank details for a payment.

The reflex: refuse any incoming request to change a RIB, especially by email. Always verify through a channel you choose yourself (a direct call to the official number, a secure portal) before changing any bank details. Fraudsters cross-reference tax and property records to target solvent organizations.

Reflex no. 3: enable strong authentication everywhere

In short: After a personal data leak, the risk is not only about your taxes: credentials reused across services become keys.

After a personal data leak, the risk is not only about your taxes: credentials reused across services become keys. The ANSSI and the CNIL keep repeating it: password reuse is the leading cause of account compromise in France.

The reflex: enable two-factor authentication (2FA) on your email, your banking services and your tax account. Use a password manager to generate a unique password for each service. Ten minutes are enough and cover 90% of the risk.

Reflex no. 4: monitor and keep the evidence

In short: Stolen data is resold in cascades: fraud attempts can arrive months after the hack is announced.

Stolen data is resold in cascades: fraud attempts can arrive months after the hack is announced. Vigilance therefore has to last.

The reflex: check your bank statements and your tax account every month. Keep all suspicious exchanges (emails, texts, screenshots): they are essential if you file a complaint or claim compensation. The CNIL recommends reporting any scam on `signal-spam.fr` or `17cyber.gouv.fr`.

Reflex no. 5: know your rights and exercise them

In short: The RGPD (GDPR) also applies to public authorities.

The RGPD (GDPR) also applies to public authorities. The DGFiP must notify the people concerned and document the breach (articles 33 and 34 of the RGPD). A dedicated hotline has been opened by Bercy, and a criminal investigation is underway (Paris public prosecutor's office).

The reflex: if you are affected, exercise your rights of access and rectification with the DGFiP. File a complaint, even without proven loss: it will build a useful case if fraud occurs later. In case of damage (fraud, identity theft), contact the CNIL and hold the State liable before the administrative court.

Conclusion

In short: The DGFiP hack marks a turning point: for the first time, cybercriminals hold mass tax data in France, with a level of precision that lets them target solvent households and businesses.

The DGFiP hack marks a turning point: for the first time, cybercriminals hold mass tax data in France, with a level of precision that lets them target solvent households and businesses. The good news is that the 5 reflexes above neutralize most of the risk: do not click, refuse any incoming RIB change, enable two-factor authentication, keep the evidence, know your rights. These actions take less than an hour to put in place, and they also protect you against every future leak.

Frequently asked questions

Am I affected by the DGFiP hack?

On August 14, 2026, the DGFiP confirmed that 678,000 tax accounts were exposed. The people affected are informed individually by letter or by a notification in their personal account on impots.gouv.fr.

What should I do if I receive an email from the tax office after this hack?

Do not click on any link. Type `impots.gouv.fr` yourself in your browser and check your account. The tax office never asks for bank details by email.

Can I file a complaint without being a victim of fraud?

Yes. You can file a complaint against persons unknown for theft of personal data, even without proven loss (CNIL recommendation).

Can the DGFiP be held liable?

Yes, the State can be held liable before the administrative court if direct and provable damage results from the leak (articles 33 and 34 of the RGPD).

What is the Ficoba file?

It is a DGFiP file listing the bank accounts and savings accounts of French taxpayers (article 1649 A of the French General Tax Code). A Ficoba leak dated February 2026 may have exposed the bank data of 1.2 million people.