A cyberattack on France’s tax authority, the Direction générale des Finances publiques (DGFiP), led to the theft of taxpayer data and prompted Prime Minister Sébastien Lecornu to order the creation of a new ANSSI-backed cyber intervention team. Lecornu said too few ministries meet required cybersecurity standards and called on SGDSN secretary general Nicolas Roche to rapidly define the unit’s organization, rules of engagement, resources, and leadership so it can intervene before, during, and after serious incidents affecting state information systems. He described the threat environment as massive, organized, and hybrid, involving rival states, criminal networks, and isolated hackers that may act in coordination.
The breach has also intensified political opposition to France’s mandatory electronic invoicing rollout, with critics arguing the state has not shown it can adequately protect sensitive data. DGFiP director Amélie Verdier said the stolen data is unrelated to the e-invoicing program and defended the reform’s security architecture, while the government kept the implementation timetable unchanged: all businesses must be able to receive electronic invoices from 1 September 2026, with issuance requirements starting the same day for large companies and mid-sized firms, then extending to SMEs and microbusinesses on 1 September 2027. A temporary grace period through the end of 2026 will spare good-faith companies from penalties, even as IT teams prepare integrations with one of 138 state-approved private invoicing platforms.

See the actors and campaigns active against you right now.
8 events from the most recent confirmed update back to the earliest known activity.
Franceinfo reported that the French tax administration, the Direction générale des Finances publiques (DGFiP), had suffered a cyber incident that resulted in data theft affecting taxpayers.
Lawyer Jeremy Roche organized a coordinated individual effort to seek compensation from the French state for people notified of either DGFiP-related data breach. Roche said more than 1,200 people had joined; the initiative may include CNIL and criminal complaints and, where applicable, administrative-court proceedings.
CGT, Solidaires Finances publiques, and Force ouvrière criticized DGFiP for prioritizing productivity, digital expansion, and interconnection over technical-debt remediation, cybersecurity staffing, and system security. DGFiP said it would assess processes for rapid security-patch deployment and establish alerts for unusually large volumes of data consultations.
Following the DGFiP compromise, the tax administration closed access for external partners and announced plans to generalize multi-factor authentication for its agents. The response followed concerns that compromised high-privilege functional accounts could expose large volumes of taxpayer data.
DGFiP director Amélie Verdier said the stolen DGFiP data had no connection to the electronic invoicing reform and defended the security of the reform's architecture.
Following the DGFiP data breach, critics including David Lisnard and Sarah Knafo called for immediate suspension of France's mandatory electronic invoicing rollout, while Jean-Luc Mélenchon criticized the privatized dematerialization model.
On X, Sébastien Lecornu said the cyber threat facing the French state was massive, organized, and hybrid, involving competitor states, criminal networks, and isolated hackers that may act in coordination.
In response to the DGFiP hack, Prime Minister Sébastien Lecornu sent a letter to SGDSN secretary general Nicolas Roche calling the ministries' cybersecurity posture unacceptable and requesting creation of a new ANSSI-backed "contact team" for serious state cyber incidents.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
5 references tracked. Mallory keeps watching after this page renders.
zdnet.fr
Open sourcezdnet.fr
Open sourcezdnet.fr
Open sourcezdnet.fr
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.