Chronicle · Data security
Six Thousand Leaks
The tax office has acknowledged an intrusion dating back to late June. 678,438 lines of tax data, cross-checked by several newsrooms. The attacker, for his part, talks about twenty million people that can be looked up. Nobody settles the matter between the two, and that is not the most troubling part: what opened the door was not a flaw, it was an employee's credentials. With the real tally of French leaks, and the name of what really causes them.
August 15, 2026, updated on the 17th · Reading ≈ 16 min · Jules Thomas
A union warned the director general of Public Finances on 15 June: risk of identity theft and targeted phishing. He was told everything was under control and no data had leaked. Eleven days later, someone walked in with an employee's credentials, and 678,438 lines of tax data walked out. No wall gave way: a badge changed pockets, and nobody noticed for seven weeks.
You saw three headlines go by this week. The tax office, a supermarket, a sports federation. Each time the same impression: it is technical, it is far away, and in any case there is nothing to be done.
The first two impressions are wrong. So is the third, but not for the reason you think.
The two figures, and why neither is true
The Direction générale des Finances publiques confirmed on 14 August an illegitimate access to its information system, which occurred in late June, through identity theft.1 It confirms the access. It confirms neither the number of people concerned, nor the exact nature of what got out.
The figure going around, 678,438 lines, therefore does not come from it. It comes from the file itself, published on 12 August on a criminal forum, and cross-checked since by several newsrooms2: about 392,000 individuals and 285,000 businesses.
The attacker, for his part, announces much more: six million requests addressed to the tax services, two million property owners via the land registry, and twenty million people he says he can look up. None of this is confirmed.
And there was a sequel. Less than forty-eight hours after the first publication, on 14 August, the same attacker claimed a second intrusion, on another system: the land registry data server, the one used to consult property records. He announces 252,149 records, roughly two million people once co-owners are counted, with names, dates and places of birth, addresses and plot references.
Keep the nuance in mind, because it changes the reading: these two million are not an inflated version of the 678,438. It is another attack, on another machine. To date, it is confirmed by nobody.
An attacker has an interest in inflating, an administration has an interest in minimising. You are between the two, and nobody owes you a referee.
That is the first thing to understand about these affairs: there is almost never a neutral figure. There is a claim, a communication, and sometimes a file that journalists open to count the lines. When you read a number, always ask yourself who produced it and what they gain from its being large or small.
And this gap is not exceptional, it is the rule. In April, when the portal of the national agency for secure documents was plundered, the Interior Ministry announced 11.7 million accounts. The attacker, on the forums, claimed 18 to 19 million. Same affair, same week, two figures that never meet.
The national cybersecurity agency says so itself, and it is the most useful sentence in its whole annual report3: of all the data-theft claims brought to its attention in 2025, it was able to confirm only 80. It explains why: these claims regularly recycle public data, or already old leaks. A hacker who announces twenty million records is first of all selling his reputation to his customers.
Nobody forced a door
That is the real subject, and it is the one that plays worst on television.
We imagine an exploit, an exotic flaw, a pierced system. Nothing of the sort here: theft of employee credentials. Someone logged in with someone else's legitimate access, and the system showed them what it was allowed to show that employee.
It is not a wall that gave way. It is a badge that changed pockets.
One detail of the official communication deserves a pause. The administration specifies that this access had been cut off as early as late June, during routine checks. In other words: the door was indeed closed again at the time, without knowing who had come in or what they had taken away. It was only learned when the file appeared, six weeks later.
And that explains why the intrusion dates from late June and is acknowledged only in mid-August. A broken door can be seen. An employee consulting files is exactly what an employee does all day. You have to look for the anomaly inside the normal, and that is infinitely harder.
Look at the two other big French affairs of this year, and you find the same pattern. At the medical software publisher Cegedim Santé, one of whose tools equips 3,800 doctors, what was spotted was not an intrusion: it was, in the company's own words, abnormal behaviour of application requests. The software politely answered questions it was allowed to be asked. 1,500 doctors were concerned.
At the ANTS, it was sillier still: a file number in the web address, which merely had to be changed to see the neighbour's file. Eleven million seven hundred thousand accounts through a door nobody had locked, because nobody had imagined a visitor would try the number next door.
The person arrested at the end of April was fifteen years old. We tell ourselves stories of foreign outfits, dark rooms and engineers funded by a hostile state. Sometimes you have to settle for a teenager who was bored one Sunday and could count to eleven million.
The tax office attacker, when questioned, claims no cause. His words: he searches, he finds, he sells, and what the buyers do with it is none of his business. We would like an ideological adversary; we have a shopkeeper.
Someone had written it down, six weeks before
On 15 June, an in-house union, Solidaires Finances Publiques, wrote to the director general to flag a risk of "hacking, identity theft or targeted phishing", and warned of a risk of new attacks "in the very short term".4 The letter was not an intuition: it started from two leaks that had already occurred, Tchap and France Services.
According to this union, management replied that everything was under control and that no data had leaked. It is the union that reports this, and it is a party to the matter: keep the source with the information, that is the rule of this whole chronicle.
The official statement of 14 August adds in passing a detail the headlines rarely picked up. It does not describe an intrusion, but illegitimate accesses that occurred "during the months of June and July". Two months, not one night.
And that sentence sits uneasily with the other, the one announcing an access cut off as early as late June during routine checks. Both come out of the same house, on the same day. I give you both, and I do not settle it: I have no means to, and nobody outside does either.
What is "claimed" is claimed by the attacker and has been confirmed by nobody.
Look at the last line. Fifty-two days between the claimed intrusion date and the crisis meeting8, and that meeting falls on the very day victim notification begins. One can see coordination in it. One can also note that both come after the publication of the file, and not before.
This is not an accusation of laziness. It is the description of a mechanism: in this affair, the event that triggered public action was not the intrusion, nor the union's alert. It was the moment an unknown person put the file online.
And while I was proofreading, a third one
On the morning of 20 August, a hacker put up for sale the data of Alaxione, a French medical appointment booking platform: 6,835,489 profiles and more than ten million appointments claimed, about 70,000 social security numbers in the batch.11 Asking price: 5,000 dollars. Do the division: your health data, your social security number and your appointments with the cardiologist are worth, retail, less than a tenth of a cent.
The claimed way in deserves a pause, because it says everything about the adversary's real level: a poorly protected phpMyAdmin access. For non-specialists: phpMyAdmin is a database administration tool that every web developer used... around 2008. Leaving it reachable from the internet in 2026, in front of millions of medical records, is leaving the safe door open with the instructions taped to it. A developer summed it up the same day: "the last time I used that must have been in 2008".
A detail you could not make up: on the screenshot going around, you can see the intruder created in the system a database named VOUS_AVEZ_ETE_PIRATER, "you have been hacked", with the spelling mistake in the original. There is the adversary: not a state, not a genius, someone who tags the wall on the way out, and who found a door nobody was closing.
The usual discipline: all of this is claimed, nothing is confirmed, neither by Alaxione nor by an authority, and the exact initial vector remains undetermined. But note the pattern, it is the third in a week: the tax office, the school, healthcare. Three administrations of ordinary life, and not a single technical feat. Hijacked accounts and open doors.
How many, exactly, since January
Since everyone has the feeling that the country is leaking everywhere, we might as well look at the counter. It exists, it is public, and it says something more interesting than "it is going up".
A word about this counter, because everything else depends on it. A "data breach notification", in the vocabulary of the law, is the form an organisation fills in when it has lost your data. It fills it in. Nobody comes to check on it. So this counter measures declared leaks, which is not quite the same thing as leaks.
In 2025, the CNIL received 6,167 data breach notifications.5 Nearly sixteen a day, Sundays and public holidays included, which makes the data leak one of the rare French activities that never closes. That is 9.5% more than the previous year and about 50% more than three years ago. Half come from a hack. The leading sectors are those you entrust the most: public administration, health, banking and insurance.
For 2026, the CNIL indicated in May that it had already recorded more than 2,730 breaches in the first quarter alone, against about 2,500 a year earlier. Beyond that, one has to be honest about what is known: the last open data file published by the CNIL stops at 31 December 2025. Nobody, as I write, can give you the French total for the first eight months of 2026. Those who give it to you made it up.
It is not the number of attacks that is soaring. It is what they take away.
That is the real lesson, and it is counter-intuitive. The national cybersecurity agency handled 1,366 incidents in 2025, against 1,361 the year before. Its words, not mine: "a number that remains stable compared with 2024".6 After 1,112 in 2023 and 831 in 2022, the curve has flattened. Ransomware attacks, the ones that encrypt everything and demand a ransom, are even slightly down.
But data-theft incidents went from 130 to 196 in a year. Half again as many. They no longer lock your house to sell you the key, they photocopy what is inside and leave. It is less spectacular, it makes fewer headlines, and for you it is far worse: a ransom gets paid or not, a piece of data that has left never comes back.
It remains to understand why so many people at once. The answer is one word, and it is not a technician's word. It is subcontractor.
In the CNIL's 2025 review, 10% of all the country's notifications are the consequence of incidents that occurred at eight providers. Eight. Not eight hundred.
You have never heard their names, you have signed nothing with them, you could not place them on a map. They have your data because your doctor, your town hall or your health insurer entrusted them with its IT, and nobody asked your opinion, because nobody thought you had one.
I wanted to check the scale of this phenomenon rather than take it on trust, so I downloaded the raw file of notifications and counted them. For 2025, it contains 17,802 lines, almost three times the official figure of 6,167. The gap is not an error: the CNIL documents it at the top of its file. It comes from two incidents, at two subcontractors, which alone triggered 11,635 notifications in cascade, one per affected customer. Two accidents, almost twice the annual volume of the whole country.
In other words: France is not leaking everywhere at once. It leaks through a few shared pipes, and when one of them bursts, thousands of organisations discover the same morning that they have to notify their customers. It is also the morning many of them learn the name of their own IT provider.
One last thing, and it is the one that should concern you most directly: the time it takes for you to find out.
These three cases show there is no fatality. The ANTS detected on 15 April and spoke on 20 April. Cegedim, which had spotted the anomaly "late 2025", explained itself publicly on 26 February, the very evening France 2 covered it on its 8 o'clock news.
A remarkable coincidence. None of these houses takes two months to publish the press release for a prize it has just won. Transparency has opening hours, and they depend on who else is talking.
Why this data is worse than a card number
A stolen bank card is annoying and it is fixable. You call, you block it, the bank refunds, you receive a new piece of plastic within eight days.
What got out here cannot be replaced. Your name, your date of birth, your address, your family situation, your reference tax income, your withholding rate, your number of tax shares. You cannot block your date of birth. You cannot ask for a new reference income.
If these terms mean nothing to you, keep this one: the reference tax income is the figure that decides almost everything, from school grants to housing benefits to nursery fees. It is your solvency summed up in one number. And it is that number that got out, next to your address.
And it is precisely the fuel of a scam that works: the one where they call you already knowing your figures.
Think for a second about what the classic fake-adviser call becomes when the person on the line announces your reference income to the euro, the number of shares in your household and the name of your town. Your suspicion drops. It drops because, in your head, only the administration holds that information.
What you do on Monday morning
One rule, just one, and it costs nothing: nobody ever calls you back to ask you for anything.
A call, a message, an email that talks about your taxes and knows your figures: you hang up, and you yourself call back the number you found on your own, on your paper notice or by typing the site's address into the bar. Never the number they give you. Never the link they send you.
This rule looks simplistic. It blocks just about everything, because no scam survives a call back to a number it does not control.
Second reflex, for businesses: the 285,000 businesses in the file are not a detail. A request to change bank details that arrives with the right tax figures, in the right vocabulary, at the right time of year, is the scenario that empties whole treasuries. The countermeasure fits in one sentence: no change of bank details is validated without an outgoing call to a number already known.
Third, and it is the only one that takes a little work: look at who, in your organisation, can consult many files in a day without it seeming abnormal. That is exactly the account profile used here. The question is not whether your people are honest, it is what would happen if one of their accesses left their pocket.
And one thing you do not have to do: look for yourself whether you are in the file. The administration has referred the matter to the CNIL, filed a complaint, and announced that it would contact the people concerned; the Paris prosecutor's office opened an investigation on 15 August. The sites offering to "check whether your data has leaked" in exchange for your address and your tax number are exactly the second storey of the scam.
If you want to understand what these systems really do, and stop being on the receiving end of the vocabulary, the Atelier's course is free.
While I was writing, the same one did it again
On the evening of 17 August, the same pseudonym claimed another intrusion. This time at the Ministry of National Education: 43 gigabytes, about 2,500 files, and the figure that made all the headlines, 346,178,591 lines.9
Let us reuse the reflex from the start of this chronicle, it applies exactly here. 346 million lines is the raw count, before removing duplicates: the claim document itself says so, in capital letters. The number of people that same document announces is 1.22 million pupils. Between the two, a factor of two hundred and eighty.
It is not a lie, and that is what is interesting: one line per grade, per assessment, per skill, for each pupil, over twenty years, and you get hundreds of millions of lines without having touched one more pupil. The two figures describe the same theft. It is the first one that travels.
Same discipline as above: "claimed" means the attacker asserts it and nobody has confirmed it. The ministry, for now, has only confirmed a narrower perimeter.
Look at the second line, and compare it with the beginning of this chronicle. A hijacked professional account. Not a flaw, not an exploit: an identity that changed hands. Two administrations, two months apart, one pseudonym, and in both cases the door was open from the inside.10
And the second pattern repeats too, that of the perimeter gap. On 31 July, the institution draws the line: no passwords, no pupils. Seventeen days later, the attacker announces 600,000 passwords and 1.22 million pupils. Both may be accurate: they may be two distinct intrusions, and the technical link between the files is not established. The ministry says it has referred the matter to ANSSI and the CNIL and is continuing its investigations. But we know the shape: at the DGFiP too, the first official figure was "no data has leaked".
An institution announces one perimeter. A criminal announces another. Between the two, it is not the truth that decides, it is time.
And the feeling that "it never stops"
It is justified, and it has a boring explanation: these affairs resemble each other not because the attackers are getting stronger, but because the same method works everywhere.
A credential lying around, an account with more rights than it needs, and an organisation that cannot say what a normal day looks like on its own system. It is not an artificial intelligence problem, it is not even really a technical problem. It is a housekeeping problem.
Housekeeping, for an organisation, starts with a question almost nobody knows how to handle: where, exactly, is my data? Not in which software. At which company, on which servers, under which contract. The eight providers that caused a tenth of last year's French leaks were not chosen at random by the attackers: that is where everyone's data is, and that is often where the smallest teams are.
The good news, if you like: what housekeeping can fix can be fixed without a war budget.
The bad news, for balance: housekeeping has never made anyone's career. A digital sovereignty plan gets presented at a press conference. The review of privileged accounts in a regional directorate does not. Yet it is the second that would have changed something here, and a union had written it down six weeks before.
Sources
- DGFiP, Accès illégitime au système d'information de la DGFiP, statement of 14 August 2026. This is the text that speaks of accesses "during the months of June and July" and specifies that impots.gouv.fr and users' personal spaces were not compromised. ↩
- Clubic, a hacker says he stole the tax data of more than 670,000 French people. The count of 678,438 lines comes from the file, not from the administration. ↩
- ANSSI / CERT-FR, Panorama de la cybermenace 2025, published 11 March 2026. Of the data-theft claims, the agency was able to confirm only 80. ↩
- Solidaires Finances Publiques, Cyberattack at the DGFiP: we had warned of the risks as early as June. A direct source, and a source that is party to the case: it is the union that reports management's reply. ↩
- CNIL, 2025 annual report: 6,167 breach notifications, one in two linked to a hack, and 10% of the total attributable to eight providers. ↩
- Same report as note 3, page 7: "In 2025, of all security events, 1,366 incidents were brought to ANSSI's attention, a number that remains stable compared with 2024 (1,361), after growth in previous years (1,112 in 2023 and 831 in 2022)." Data thefts, for their part, go from 130 to 196 (page 13). ↩
- franceinfo, Sébastien Lecornu will chair an interministerial crisis unit. This is the article that places the start of victim notification on the Monday. Other newsrooms write "from the week of the 18th": I give the most precise version and flag the discrepancy. ↩
- CNEWS, the Paris prosecutor's office opens an investigation, entrusted to the Ofac on 15 August. The crisis unit of the 17th meets by secure video call. ↩
- The claim is dated the evening of 17 August and relayed by the cybersecurity researcher Clément Domingo (@_SaxX_) as well as by the watcher FrenchBreaches. None of these figures is confirmed: 43 GB, 2,500 files, 346,178,591 raw lines, 1.22 million pupils, 4.35 million I-Prof identifiers, about 602,000 academic accounts. The claim document itself specifies that the total is raw and not deduplicated, which is the reason for the paragraph above. The attacker places the intrusion on 15 July and says he came in through a VPN access, citing the Créteil and Versailles education authorities. ↩
- The ministry's statement is dated 31 July and concerns an intrusion on the night of 25 July, "from a hijacked professional account", into the staff training system. Coverage and comparison with the claim by Tom's Guide. The same pseudonym is associated with the claims targeting the DGFiP and Intermarché Drive. I was not able to reread the 31 July statement on a ministry site: I have it from newsrooms that quote it, and I say so rather than let it pass for a primary source. ↩
- Claim published on 20 August 2026, documented by the watcher FrenchBreaches: 6,835,489 profiles, 10,145,988 appointment lines, ~70,000 social security numbers, 12.8 GB, for sale at $5,000. The hacker says he warned Alaxione two days before publishing. None of these figures is confirmed, and FrenchBreaches underlines it itself. The "VOUS_AVEZ_ETE_PIRATER" database is visible on the screenshot shared by the same watcher; the "in 2008" quote comes from a developer commenting on the affair on X the same day. ↩
The national figures come only from documents 5 and 6, plus the open dataset of notifications, which I downloaded and counted myself. A methodological precaution: several secondary sites announce an 18% drop in ANSSI incidents in 2025. The report says "stable". I opened the PDF to settle it, and the report is right. On a numbers story, a rewrite gets it wrong more often than the source.