CryptoReal
CASE FILE — Aug 24, 2026

French Tax Agency Data Breach Exposes Risks for Crypto Investors and Public at Large

Investigators at the Bobigny tax office discovered that Ghalia C., an employee of the French tax administration (DGFiP), had leveraged the Mira software to retrieve confidential financial details.

Her computer logs revealed she performed queries directed specifically at individuals involved in cryptocurrency, both specialists and investors. Authorities allege she supplied this sensitive data to criminal groups, facilitating physical assaults and extortion attempts.

An examination of her finances revealed unexplained cash deposits and Western Union transfers, which, according to investigators, signified compensation from an unidentified client in exchange for private information.

Prosecutors contend that she distributed data belonging to cryptocurrency professionals and investors to those orchestrating attacks and blackmail.

Among the cases she researched was a corrections officer from La Santé prison.

On September 26, 2024, three armed assailants attacked this officer at his home in Montreuil, witnessed by his spouse.

Prosecutors claim the attackers were acting on an address sourced by Ghalia from internal tax records.

The attackers reportedly received €800 for the assault, which was linked to a dispute involving mobile phones found in a prison cell.

Ghalia has been detained since June 30, 2025. She admitted to disclosing information but denied any knowledge of her client’s intent to instigate violence.

After declining to unlock her phone or identify associates, she has remained in custody.

In August 2026, another breach was claimed: a separate actor announced access to DGFiP systems.

The French Finance Ministry soon confirmed that intruders obtained data on 678,000 individuals and businesses.

The ingredients for a target list—names, addresses, and indications of wealth—have proven to be a potent combination in the hands of malicious actors, as demonstrated by these incidents within France’s tax authority.

The core risk wasn’t just the data itself, but the ease with which it could be transformed into a roadmap for targeting individuals.

What are the consequences when identifying potential victims becomes automated?

References: Imi Daily, FDS, Bleeping Computer, French Breaches, Jameson Lopp, International Cyber Digest, DGFiP, CertiK, Journal Du Coin, cyberdaily, CYBERATTAQUE, IT-CONNECT, Brussels Signal, euro.news, CNIL, Moneyvox, The Block, franceinfo, Boursorama, info.gouv.fr

On August 12, 2026, a user named ZeroBytes advertised a DGFiP database for sale on PwnForums.

According to FrenchBreaches, the dataset was offered for several thousand euros.

At the time, DGFiP had not yet made the breach public.

Later, the Ministry of Finance acknowledged that attackers had accessed and removed data tied to around 678,000 individuals and professionals.

The confirmed information types included reference tax income, withholding rates, business numbers, and details about properties and addresses.

FrenchBreaches reviewed the dataset and described its contents as including: names, tax IDs, home addresses, phone numbers, emails, family status, tax details, and records of interactions with the tax authorities.

The analysis indicated that 26,805 records showed reference income above €100,000, 386 above €1 million, and eight above €10 million.

These numbers have not been independently validated by the Finance Ministry.

The significance of these figures was highlighted by Jameson Lopp, while International Cyber Digest reported that ZeroBytes also claimed to have compromised France’s Education Ministry and land registry.

The official tally later changed.

DGFiP’s FAQ stated the breach involved slightly more than 350,000 individuals and 250,000 professionals—about 600,000 affected in total.

This figure differs from ZeroBytes’ claim of 678,438 records and the Ministry’s previous statement of roughly 678,000 people and businesses. Public explanations have not clarified whether these discrepancies are due to deduplication, a change in scope, or revised estimates.

The breach was already severe, but uncertainty around its true scope complicated efforts to assess the damage.

Which number is accurate, and what else remains unknown?

Home Field Advantage

Stepping back from Bobigny, the broader situation for France appears even grimmer.

CertiK’s Intel3D report documented 52 confirmed wrench attacks globally in the first half of 2026.

Of these, 33 occurred in France—accounting for 63.5% of the global total and a 33.3% increase over the previous year.

The total value at risk reached $124.1 million, nearly twelve times the $10.5 million recorded during the first half of 2025.

This figure encompasses ransom demands, actual payments, and assets frozen or recovered, not solely confirmed theft.

Home invasion incidents surged from one reported case in H1 2025 to 20 in H1 2026.

According to France’s interior minister, there were 77 kidnappings and extortion cases since January, compared to 45 in all of 2025.

The difference comes down to scope: CertiK includes only independently verified and public incidents, while government figures cover a broader range of reported and attempted crimes.

Importantly, CertiK’s H1 report was released in July, prior to the DGFiP breach making headlines.

CertiK’s analysis warned that leaked or mishandled data “can potentially be combined with publicly available information to identify individuals associated with significant crypto holdings.”

A previous CertiK report referenced the Ghalia C. affair as an example of how insider access in state agencies can be exploited by criminal groups.

Sums referenced in this case file

The risk was already acknowledged: personal financial information can be weaponized for physical targeting.

The DGFiP leak then put the information of hundreds of thousands more at risk.

While no public agency has attributed a physical attack to this breach, the precedent set by the Ghalia case demonstrates that the risk was not unforeseeable.

If the danger was clear from a single agency’s data, what happens when breaches span multiple organizations?

Domino Theory

ZeroBytes did not stop at claims about DGFiP; other institutions were also named as targets.

ZeroBytes asserted it had accessed the DGFiP land registry, extracting 252,149 records linked to over two million people.

The actor further claimed the system contained records on about 20 million individuals, though not all data had been exfiltrated.

The French tax authority stated it was continuing its investigation, with help from ANSSI, to determine the full consequences.

ZeroBytes also claimed a breach at SFR, obtaining data from the NOVA internal platform. SFR confirmed that a fiber-management tool had been compromised, and 2,104,093 records were reportedly extracted.

The Education Ministry was also cited: a fraudulent intrusion was detected on July 25, involving a compromised professional account and a staff training system. The ministry clarified that no bank details, passwords, or student data were contained on the implicated system, but ZeroBytes’ claim suggested a wider scope including student records and password hashes.

These incidents show a common vulnerability: attackers may not need sophisticated exploits if they can gain or mimic legitimate access, using internal tools to search and export sensitive data.

DGFiP reported that its breach was carried out by impersonating both a tax agent and an authorized third party.

Putting these incidents in context, France’s recent breach history includes: government email and police files, France Travail data (43 million people), Free and Free Mobile subscriber records (24 million), and FICOBA, the national bank account registry.

No single breach was designed to provide a complete picture, but a determined actor could combine information from several leaks to build detailed profiles—an address from one, income from another, phone data from a third, and evidence of crypto activity from a fourth.

How many fragmented leaks does it take before privacy is irretrievably lost?

Wrong Address

No physical attacks have been officially tied to the August 2026 DGFiP incident.

This is significant, as the breach was revealed publicly in August and DGFiP began notifying affected taxpayers by email on August 17.

If the stolen data has already resulted in targeting, no public report has confirmed it. But an absence of evidence is not proof of safety.

A case from the Somme region underscores the risk: a couple endured three attempted burglaries within a month after moving into a home previously owned by crypto millionaires.

The new residents did not possess the roughly €1 million in cryptocurrency the intruders sought.

During a second break-in, the couple was attacked and restrained, only for the assailants to realize their mistake and escape.

Reports attributed the error to outdated tax data and the former owners’ address circulating on dark web forums.

The lesson: even obsolete or incorrect address information can put innocent people in harm’s way.

If stale data can cause harm, what risks emerge when a leak provides current, accurate, and comprehensive financial and personal profiles for hundreds of thousands?

The Fine Print

The French government moved quickly following the disclosure.

Within days, Prime Minister Sébastien Lecornu called an interministerial crisis meeting.

Afterward, he requested that ANSSI carry out a thorough audit to determine how the DGFiP breach occurred, in parallel with an ongoing legal investigation.

The government announced that measures based on this audit would be presented in September.

DGFiP notified CNIL, the French data protection authority, after identifying the breaches.

It remains to be seen whether CNIL will launch a formal investigation or impose sanctions.

Earlier in the year, CNIL fined France Travail €5 million after attackers took over accounts belonging to CAP EMPLOI advisers using social engineering.

This breach exposed data on individuals registered with France Travail over two decades, as well as those with candidate accounts on the site.

CNIL concluded that France Travail lacked adequate technical and organizational safeguards that could have complicated the attack.

Specifically, CNIL cited insufficient authentication, poor event logging, and overbroad access rights for advisers.

Earlier that month, Free Mobile and Free were jointly fined €42 million after a breach involving 24 million subscriber contracts, with CNIL identifying weak VPN authentication and poor detection of unusual activity.

DGFiP now faces similar scrutiny over whether its controls, monitoring, and response measures were sufficient to protect sensitive tax and property records.

To date, CNIL has levied fines totaling €47 million across three organizations this year alone.

Will a government tax authority be held to the same standards it expects of private entities?

The chain is only as strong as its weakest link.

Swap DGFiP for a blockchain protocol and Mira for an admin key, and the story reads as a familiar one: one credential with too much power, a blast radius underestimated. Leaked private keys can drain wallets; misused admin access can empty treasuries.

A tax agent’s access, as this case illustrates, can endanger lives—not just account balances.

Ghalia C. remains in pretrial detention. Prosecutors allege she exploited legitimate access to share confidential data with an anonymous client; she has acknowledged providing information, denied knowledge of intended violence, and refused to unlock her phone or identify her contacts.

She did not need to circumvent security controls. She had legitimate access, an alleged criminal motive, and a system that trusted her searches.

Now consider this scenario at scale: ZeroBytes publicly listed what was claimed to be a DGFiP dataset for sale, reportedly seeking several thousand euros.

There is no independent confirmation of whether the data was sold or to whom.

The next person to exploit such information would not need a position in Bobigny or access to Mira—just a copy of the data and time to identify a target.

France has already witnessed the consequences of one insider’s actions. The potential impact of a stranger armed with a massive spreadsheet of sensitive data is still unknown.

The full content and scope of the leaked records remain under investigation.

The critical question is: who will discover their consequences first—the government’s auditors, or the next unsuspecting family to answer a knock at the door?

Data BreachFrance
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.