French Tax Authority Breach Exposes Tax & Property Data of 678,000 Individuals
What Happened — Attackers accessed the DGFiP systems and exfiltrated personal tax records for 678,000 individuals and business data, including income references, family quotient, withholding rates, and cadastral information. The breach was publicly claimed on PwnForums and the stolen database was offered for sale.
Why It Matters for Compliance & Audit Readiness —
- Demonstrates the need for robust data‑classification, encryption, and access‑control policies required by SOC 2 CC6 (Confidentiality) and GDPR/CCPA obligations.
- Highlights the importance of having documented breach‑response procedures and audit‑ready evidence of notification to regulators (CNIL) and affected data subjects.
- Aligns with Verisq’s CookiePLUS privacy suite, which helps organizations maintain consent records, DSAR readiness, and privacy‑impact evidence for audits.
Who Is Affected — Government & public‑sector agencies; tax authorities; any organization handling large volumes of personal fiscal or cadastral data.
Recommended Actions —
- Map the incident to SOC 2 CC6 and GDPR/CCPA controls; verify encryption, least‑privilege access, and continuous monitoring are in place.
- Collect and preserve logs, access records, and notification evidence for audit trails.
- Review and test DSAR processes and consent‑management workflows to ensure rapid, compliant responses.
Source: BleepingComputer
Technical Notes — Attack vector undisclosed; threat actor “ZeroBytes” claimed access to the Serveur Professionnel de Données Cadastrales (SPDC) portal. No user credentials were leaked, but the attacker extracted tax and property records. Source: same link.