
The French government has announced a reinforced response to the wave of hacking targeting its agencies. But data stolen from DGFiP and the Ministry of Education is already for sale on the dark web, and phishing campaigns have begun.
Two ministries hit, millions of data records exposed
The ZeroBytes group claimed on Tuesday, August 18, 2026, a massive hack of the Ministry of Education’s systems, following the attack on the Direction générale des finances publiques (DGFiP) in early August. According to its statements, 346 million lines of raw data were exfiltrated without immediate detection. The ministry had already acknowledged on July 31 an intrusion "a few weeks ago," without specifying the scale.
At DGFiP, the late June 2026 intrusion allowed the theft of tax data from 678,000 individuals and businesses, as well as cadastral information for 200,000 accounts. IDs and passwords are reportedly not compromised, but names, reference tax incomes, family quotients, and withholding tax rates are now circulating. The Ministry of Education, already hit by leaks in March (243,000 teachers) and April (3.5 million students), confirms its exposure once again.
Data already monetized, phishing on the rise
By August 12, DGFiP data was being sold on a cybercriminal forum, followed on August 17 by the Ministry of Education’s data. Samples were shared, and Avast experts confirm that ZeroBytes is trying to sell this information. "The real risk isn’t just the data itself, but what cybercriminals can do with it," explains Iskander Sanchez-Rola, an executive at Avast.
Fraudsters are already using this data for targeted phishing campaigns, impersonating government agencies. The messages, more credible due to real information, prompt users to click on links or share additional data. DGFiP has published a template of legitimate emails to help citizens distinguish real alerts from scam attempts.
The government’s response: crisis unit and audits
Facing the urgency, the government has activated an interministerial crisis unit chaired by Sébastien Lecornu. An audit on securing DGFiP systems has been requested. The CNIL, notified of the breaches, is checking compliance with security measures and could impose sanctions for GDPR violations.
The Paris prosecutor’s office has opened an investigation for "fraudulent data extraction" and "criminal association." The affected ministries claim to be reinforcing their systems, but the modus operandi remains the same: late detection, minimal communication, then public disclosure forced by the hackers.
RecommendedUS allows private cybersecurity firms to hack foreign cybercriminals
What to do if you are affected?
- Do not click on links or reply to suspicious emails, even if they appear official.
- Log in directly to impots.gouv.fr or the Ministry of Education’s website to verify alerts.
- Contact the official DGFiP number (0809 401 401) if in doubt.
- Monitor phishing attempts, which could exploit cross-referenced data (tax, cadastral, school-related).
“If you receive an unexpected request regarding your taxes, your child’s school, or any other public service, do not click on the link in the message.” — Iskander Sanchez-Rola, cybersecurity expert at AvastTranslated from French
The government’s counterattack is organizing, but the damage is already done. The data is for sale, and cybercriminals have enough to fuel fraud campaigns for months. The question is no longer whether systems are vulnerable, but how long it will take to secure them permanently.
Sources
Journal du Geek — Piratage massif de l’Éducation nationale revendiqué par ZeroBytes
CNIL — Piratage du système d’information des impôts : les vérifications sont en cours
Numerama — Piratage des impôts : la DGFiP montre à quoi ressemble le vrai mail légitime d’alerte
Numerama — Piratage du site des impôts : les signalements individuels ont débuté


Comments 0
Sign in to join the discussion.
Be the first to comment.