Here is the email sent to the 678 000 victims of the cyberattack targeting France’s Directorate General of Public Finances.
Hello X Y,
Wednesday, August 12, 2026, a malicious actor claimed to have gained access, in June and July of this year, to data from the information systems of the French Directorate General of Public Finances (DGFiP), using the stolen credentials of a DGFiP employee combined with those of a third party authorized by the DGFiP.
You are receiving this message because you are affected by this malicious act.
What data may have been accessed?
Your tax identification number, civil status, contact details (postal address, telephone number and email address), your tax situation (family situation, number of dependents, number of tax shares, reference taxable income, withholding tax rate), and the list of messages you exchanged with the DGFiP through the messaging system on impots.gouv.fr.
Important: your password for accessing your Public Finances account on impots.gouv.fr has not been compromised. Your tax returns and tax notices were not accessed.
What is the main risk?
The main risk is that you may be targeted by fraud attempts, particularly through messages (“phishing”) or phone calls made more convincing by the use of the stolen personal information.
To a lesser extent, you could also be targeted by identity theft attempts. For this, however, the malicious actors would also need to have a copy of your identity documents or obtain them through another means.
In any event, your bank details are not affected by this data theft.
How can you protect yourself?
You should be particularly cautious about any contact — by phone call, email, SMS, instant messaging, social media, etc. — from people or organizations claiming to know you based on the stolen information and asking you to:
- provide confidential information (codes, passwords, bank card numbers, copies of identity documents, etc.);
- approve banking transactions (in particular, someone pretending to be your bank advisor); or
- provide your password to access your Public Finances account.
The DGFiP will never ask you to provide information outside your secure account.
You are also advised to remain vigilant and regularly check transactions on your bank accounts.
What measures has the DGFiP taken?
The access credentials used by the malicious actor were immediately disabled in June and then in July. Unfortunately, we did not detect the data theft at the time, as the data was stolen by bypassing the usual channels.
The security of your tax account is being strengthened immediately, including through particular monitoring of any changes that may be made to it over the coming months (postal address, bank account details, etc.).
Please be assured that our teams are fully mobilized. If you would like more information, you can consult our dedicated page on impots.gouv.fr:
https://www.impots.gouv.fr/actualite/acces-illegitimes-au-systeme-dinformation-de-la-dgfip
You can also contact us on 0809 401 401 or through your impots.gouv.fr secure messaging system. Alternatively, you can visit your local Public Finances office; its contact details are available in your secure account and on your tax notices.
This data theft will be subject to a lessons-learned review and additional security measures, which are being implemented without delay.
We sincerely apologize.
The Directorate General of Public Finances