Skip to content

News with true faith

Technology

France tax agency data breach hits 700,000 taxpayers

France apologised after a massive tax data breach exposed 700,000 citizens, triggering debate over claims that the nation is a top cyberattack target.

France tax agency data breach hits 700,000 taxpayers

The French tax authority confirmed a massive data breach affecting roughly 700,000 users, forcing the government to issue an official apology.

The Directorate General of Public Finances, known as the DGFiP, acknowledged a second data leak on Tuesday, August 18, although officials described the second incident as less sensitive. The consecutive breaches have renewed public concern across France, fueling online assertions that the nation has become a primary target for cybercriminals.

Public debate escalated after a video clip circulated widely on the social network X, showing a masked man speaking in front of a camera. The video segment was taken from a longer recording produced by a YouTuber known as Rabbin des Bois, who describes himself as a hacker.

In the full recording, the speaker claimed that France is currently one of the most hacked countries in the world. He further asserted that the country is already the most hacked nation in Europe and is probably the most hacked country globally.

Official statistics indicate that France has seen a substantial rise in security incidents in recent years. Data recorded by CNIL, the French data protection authority, shows that 6,100 data breach notifications were filed in 2025, marking a 50 percent increase over the previous three years.

Cybersecurity rankings and leak counts

The viral claims relied on studies published by Surfshark, a cybersecurity company headquartered in the Netherlands, which have been frequently cited in recent days. Surfshark recorded nearly 20 million French accounts compromised in the second quarter of 2026 alone.

That quarterly total placed France as the second most affected country in the world, behind only the United States. The findings have been widely shared across media outlets following the tax administration leak.

Other digital security reports also place France high in global rankings. According to a 2023 report by F5 Labs Threat Research, France was the second most targeted country worldwide for Distributed Denial of Service, or DDoS, attacks. These attacks aim to block server access and disrupt online services.

A separate report by the European Union Agency for Cybersecurity, or ENISA, found that France was the European country whose public administration was most affected by DDoS attacks. The ENISA study analyzed nearly 5,000 incidents recorded across the 27 EU member states between July 2024 and June 2025.

Expert warnings on data limitations

Despite these high rankings, cybersecurity experts emphasize that the figures must be interpreted with caution. Rayna Stamboliyska, a cybersecurity specialist and director of consulting firm RS-Strategy, told TF1info that no reliable global ranking exists because different reports do not measure the same criteria.

Stamboliyska explained that each study relies on a specific methodology and cannot be used to draw general conclusions. Surfshark identifies compromised accounts from thousands of publicly accessible databases and aggregates the data by email address.

However, Surfshark noted that data identified as accessible in 2025 did not necessarily leak during that specific year. Stamboliyska emphasized that the figures represent an accumulated stock of past leaks resurfacing over time rather than new breaches.

The compiled data includes credentials gathered by infostealers, which are malicious software programs installed on personal devices. Stamboliyska noted that an infected home or employee computer reveals nothing about the security of public administration systems. She added that larger, more connected populations with high online activity naturally generate higher numbers in these tallies.

Stamboliyska also urged caution regarding reports based on breach notifications. She explained that a high ranking primarily reflects strong, enforced reporting obligations rather than greater fragility. Under the European Union General Data Protection Regulation, or GDPR, organizations must report data breaches within 72 hours. Countries with less strict rules or lower enforcement may appear lower in rankings without being safer.

DDoS disruptions versus ransomware threats

Experts also highlight that different types of cyberattacks have vastly different impacts. Mathieu Cunche, a professor and researcher at INSA-Lyon and the National Institute for Research in Digital Science and Technology, or Inria, noted that DDoS attacks accounted for about 77 percent of incidents recorded by ENISA.

Cunche explained that while DDoS attacks aim to damage an organization's image, they do not pose a direct risk to user data like the DGFiP breach. Stamboliyska added that most DDoS campaigns have low impact and are reversible.

In contrast, ransomware attacks, which block IT systems to demand payment, remain the most damaging cyber threat. ENISA data places France in the top five EU member states cited in ransomware claims. However, France accounted for 9.5 percent of reported cases, ranking far behind Germany, which accounted for 23.4 percent.

Stamboliyska criticized the practice of combining all cyber attack types into a single metric, warning that it smooths over and obscures real impact. She noted that global rankings fail to capture how a single compromise of a strategic identity can permanently expose hundreds of thousands of people.

Economic and geopolitical targets

France's frequent appearance in cyber attack reports is also linked to its economic standing. Cunche noted that as a wealthy country, France presents an attractive target that offers additional financial incentives for cybercriminals.

ENISA's analysis aligns with this view, noting that countries targeted most by ransomware operators are likely singled out because they are major economic actors in the European Union and represent high-value targets.

Geopolitical factors also influence attack patterns. France's diplomatic choices make it a target for digital destabilization campaigns. ENISA reported that Russia-linked cyberattacks concentrated heavily on French public administration, as well as government systems in Poland and Germany.

Cunche concluded that while France often ranks high in specific studies, this does not mean the country has a poor cybersecurity culture. Stamboliyska added that nothing indicates France is structurally more vulnerable or less prepared than neighboring European countries or comparable digital economies, though French authorities still face major work in improving incident transparency.

Related

Leave a comment

Your email address will not be published. Required fields are marked *