Total Exposure



At the Bobigny tax office, investigators found that Ghalia C. had used the (DGFiP) French tax administration’s Mira software to access sensitive financial information.

Her workstation showed searches specifically targeting cryptocurrency specialists and investors, whose personal data she allegedly sold to criminals for physical attacks and extortion.

Police also found cash deposits and Western Union transfers in her accounts, which investigators say indicated payment from an anonymous client for confidential information.

Prosecutors allege that she sold cryptocurrency specialists’ and investors’ personal data to criminals for physical attacks and extortion.

One of those searches concerned a prison guard from La Santé.

On September 26, 2024, three armed men attacked him at his Montreuil home in front of his wife.

Prosecutors allege they were working from an address Ghalia had obtained through the tax system.

The attackers were reportedly paid €800 for the assault, which stemmed from a dispute over mobile phones discovered in a prison cell.

Ghalia has been detained since June 30, 2025. She admits passing on information but denied knowing her client’s violent intentions.

After refusing to provide her phone passcode or identify her contacts, she remains in custody.

In August 2026, another actor claimed access to the DGFiP.

The French Finance Ministry later confirmed that attackers accessed and extracted data on 678,000 individuals and businesses.

A target list needs a name, an address, and a reason to believe there is money behind the door. France’s tax administration has already shown how dangerous that combination can be.

The danger was never just the data. It was who could turn it into a target list.

What happens when the shopping list writes itself?

Credit: Imi Daily, FDS, Bleeping Computer, French Breaches, Jameson Lopp, International Cyber Digest, DGFiP, CertiK, Journal Du Coin, cyberdaily, CYBERATTAQUE, IT-CONNECT, Brussels Signal, euro.news, CNIL, Moneyvox, The Block, franceinfo, Boursorama, info.gouv.fr

August 12, 2026, a hacker using the name ZeroBytes posts on PwnForums, claiming to sell a DGFiP database.

The asking price, according to FrenchBreaches, was a few thousand euros.

At that point, the DGFiP had not publicly acknowledged the intrusion.

When the French Finance Ministry later confirmed the breach, it said attackers had accessed and extracted data concerning roughly 678,000 individuals and professionals.

The confirmed categories included reference tax income, withholding rates, business identifiers, and cadastral data relating to addresses and property sizes.

FrenchBreaches' analysis of the alleged dataset described a trove: Names, tax identifiers, addresses, phone numbers, email addresses, family information, tax data, and the history of some requests to the tax administration.

It also reported that 26,805 records showed reference income above €100,000, 386 above €1 million, and eight above €10 million.

Those figures have not been independently confirmed by the Finance Ministry.

That last figure reached the people most likely to understand its stakes: Jameson Lopp highlighted the breakdown, while International Cyber Digest reported that ZeroBytes had also claimed intrusions at France’s Education Ministry and national land registry.

Then the public count appeared to shift.

In its own FAQ, the DGFiP said the breach affected just over 350,000 individuals and 250,000 professionals: Roughly 600,000 people and professionals in all.

That sits uneasily beside the 678,438 records first claimed by ZeroBytes and the Finance Ministry’s August 14 figure of approximately 678,000 individuals and professionals.

The available public accounts do not make clear whether the differences reflect deduplication, changed scope, or a corrected estimate.

The breach was already serious. The uncertainty about its scale made it harder to judge how serious.

So which number are taxpayers supposed to believe, and what else remains undisclosed?

Home Field Advantage

Zoom out from Bobigny, and the picture gets worse, not better.

CertiK's Intel3D report recorded 52 verified wrench attacks worldwide in the first half of 2026.

33 took place in France alone, 63.5% of CertiK's global dataset, and a 33.3% year-over-year (YoY) increase.

Recorded financial exposure reached $124.1 million, nearly 12 times the $10.5 million recorded in the first half of 2025.

That figure includes ransoms demanded, transfers made, and funds frozen or recovered, not just confirmed theft.

Home invasions rose from one publicly reported case in H1 2025, to 20 in H1 2026.

France's interior minister put the broader total higher: 77 kidnappings and extortions recorded since January, compared to 45 for all of 2025.

The apparent gap reflects scope: CertiK counts only verified and public incidents it independently verified, while the government's figure encompasses a wider class of reported and attempted crimes.

But one detail matters most here.

CertiK published its H1 report in July, weeks before the DGFiP breach became public.

CertiK’s Intel3D report said information exposed through data breaches, leaks, or unauthorized disclosure “can potentially be combined with publicly available information to identify individuals associated with significant crypto holdings.”

An earlier CertiK overview named the Ghalia C. case as an example of alleged state-insider data access feeding criminal networks.

The warning was already on paper: Personal financial records can become material for physical targeting.

Then the DGFiP breach exposed data concerning hundreds of thousands more people.

No public authority has linked a physical attack to that breach. But after Ghalia's case, it would be difficult to argue the risk was unforeseeable.

So if one agency's data was already enough to make the warning obvious, what happens once it's not just one agency anymore?

Domino Theory

DGFiP was not the only organization ZeroBytes claimed to have accessed, and it was not the last target the actor publicly named.

ZeroBytes later claimed access to the DGFiP’s land-registry platform, saying it had taken 252,149 records containing data on more than two million people.

The actor also claimed the system contained records relating to roughly 20 million people, while acknowledging that it had not completed extraction.

The French tax administration said it was continuing to investigate the breach, with ANSSI’s assistance, to assess its full impact.

ZeroBytes also claimed access to an internal SFR tool known as NOVA. The telecom operator confirmed a breach involving an internal fiber-management tool.

ZeroBytes claimed it had extracted 2,104,093 data lines.

The actor further claimed access to the Ministry of National Education systems.

The ministry confirmed that it detected a fraudulent intrusion on the night of July 25, involving a compromised professional account and a system used for staff training.

The ministry said that data potentially exfiltrated concerned ministry agents who had worked in regional education authorities since 2001, and that the specific system involved did not contain bank details, passwords, or pupil data.

That confirmed incident is narrower than ZeroBytes’ later claim, which extended to pupil registers and password hashes from academic directories.

The details differ, but they illustrate the same basic danger: Attackers may not need a novel exploit to defeat a system outright.

They can obtain or impersonate legitimate access, then use trusted internal tools to search, view, and extract data.

DGFiP said its breach involved the impersonation of identifiers belonging to a tax agent and an authorized third party.

Widen the lens further, and France's breach history becomes a catalog of exposed databases: Interior Ministry email accounts and sensitive police files; France Travail data concerning 43 million people; Free and Free Mobile data relating to 24 million subscriber contracts; and FICOBA, the national bank-account registry.

These breaches were not designed to work together.

But a criminal buyer patient enough to collect them would not need one perfect database.

They could attempt to assemble a target profile from several imperfect ones.

Income from one leak, an address from another, phone data from a third, and evidence of crypto activity from a fourth.

So how many partial leaks does it take before there is nothing left to protect?

Wrong Address

No physical attack has been publicly reported as linked to the August 2026 DGFiP breach.

That distinction matters, because the intrusion became public in August, and the DGFiP began notifying affected taxpayers by email on August 17.

If stolen data has already been used to target someone, no such case has been documented publicly. But the absence of a confirmed case is not the same as an absence of risk.

A nearby example makes that clear.

A couple in France's Somme department reportedly endured three attempted home invasions in less than a month after buying a house formerly occupied by crypto millionaires.

The new owners did not possess the roughly €1 million in cryptocurrency the attackers sought.

During the second incident, intruders restrained and assaulted the couple before realizing they had targeted the wrong people and fleeing.

Reporting linked the misidentification to leaked tax information and the former owners' address appearing on the dark web.

The key point is not that the attack was connected to the DGFiP breach, it has not been reported as such.

It is that leaked or stale address information can still direct violence at people with no crypto holdings at all.

If bad or outdated data can cause that much damage, what happens when information is fresh, accurate, and linked to hundreds of thousands of names, addresses, and income profiles?

The Fine Print

France's response moved quickly, at least on paper.

Within days of the disclosure, Prime Minister Sébastien Lecornu convened an interministerial crisis cell.

After that meeting, he asked ANSSI, France's national cybersecurity agency, to conduct an "in-depth audit" to establish the circumstances and causes of the DGFiP incident, alongside the ongoing judicial investigation.

The government said operational measures resulting from this audit will be presented to the Minister in September.

DGFiP notified the CNIL, France's data-protection authority, after identifying the breaches.

Whether the regulator opens a formal investigation or reaches a sanction decision remains to be seen.

There is recent precedent. In January, the CNIL fined France Travail €5 million after attackers used social engineering to hijack accounts belonging to CAP EMPLOI advisers, organizations that support people with disabilities in employment.

The intrusion exposed data on people registered with France Travail during the previous 20 years, as well as people with candidate accounts on its website.

The CNIL found that France Travail had not implemented technical and organizational measures that could have made the attack more difficult[.

It specifically cited insufficiently robust authentication procedures, inadequate logging to detect abnormal behavior](https://www.cnil.fr/en/data-breach-5million-fine-france-travail), and overly broad access authorizations for CAP EMPLOI advisers.

Earlier that month, the CNIL fined Free Mobile and Free a combined €42 million after an attacker accessed data connected to 24 million subscriber contracts.

It found inadequate security measures, weak VPN authentication, and ineffective anomalous-behavior detection.

DGFiP now faces similar questions: Whether its authentication, access controls, monitoring, and incident response were adequate for systems holding sensitive tax and property data.

CNIL has already fined France Travail €5 million and Free and Free Mobile €42 million combined this year, €47 million total across three organizations.

Will a government tax authority face the same standard it applies to everyone else?

All it takes is one broken link in the chain.

Swap DGFiP for a protocol and Mira for an admin key, and this reads like every other story here.

One credential carrying more weight than it should, one blast radius nobody sized correctly. Private-key leaks empty wallets. Abused admin access drains treasuries.

A tax agent's login, it turns out, can put human beings at risk rather than merely exposing balances.

Ghalia C. remains in pretrial detention. Prosecutors allege she used authorized access to transmit confidential information to an anonymous client; she acknowledged passing on information, denied knowing the client's violent intentions, and refused to provide her phone passcode or identify contacts.

She did not need to defeat a security system. She had authorized access, an alleged criminal purpose, and a database that trusted her queries.

Now imagine that access model scaled up: ZeroBytes publicly listed a purported DGFiP dataset for sale on a cybercrime forum, reportedly seeking several thousand euros.

Whether the dataset was sold, and to whom, has not been independently confirmed.

The next person to exploit the data would not need a job at Bobigny. They would not need Mira.

They would need only a copy of the data, and time to identify a target.

France already knows what one insider with a keyboard can allegedly do to a single family's front door.

It does not yet know what a stranger with a spreadsheet could do with a database reported to contain personal and tax-related information on hundreds of thousands of people.

The precise contents and full scope of the leaked dataset remain under investigation.

So who finds out first: The government auditing itself, or the family that answers the knock?


share this article

REKT serves as a public platform for anonymous authors, we take no responsibility for the views or content hosted on REKT.

donate (ETH / ERC20): 0x3C5c2F4bCeC51a36494682f91Dbc6cA7c63B514C

disclaimer:

REKT is not responsible or liable in any manner for any Content posted on our Website or in connection with our Services, whether posted or caused by ANON Author of our Website, or by REKT. Although we provide rules for Anon Author conduct and postings, we do not control and are not responsible for what Anon Author post, transmit or share on our Website or Services, and are not responsible for any offensive, inappropriate, obscene, unlawful or otherwise objectionable content you may encounter on our Website or Services. REKT is not responsible for the conduct, whether online or offline, of any user of our Website or Services.