France France CNIL GDPR enforcement Big Tech

France's Tax Authority Breach Tests Whether CNIL Enforces Security Failures as Strictly Against the State as It Does Against Free

DGFiP's 678,000-account breach puts CNIL's tough new security-failure doctrine, forged against Free, to its first real test against government.

DGFiP Breach vs. CNIL's Free Precedent People of Internet Research · France 678,000 Accounts affected Individuals and businesses whose t… €42M Free's GDPR security fine CNIL's January 2026 sanction for c… Dark-web listing How the theft was confirmed DGFiP's own checks missed the exfi… €20M Public-body fine ceiling CNIL's flat cap for non-turnover e… peopleofinternet.com
DGFiP Breach vs. CNIL's Free Precedent People of Internet Research · France 678,000 Accounts affected €42M Free's GDPR security fine Dark-web listing How the theft was confirmed €20M Public-body fine ceiling peopleofinternet.com

Key Takeaways

What Happened

France's Direction générale des Finances publiques (DGFiP) confirmed on August 14, 2026 that an attacker had infiltrated its information system in June and July 2026, extracting tax and cadastral data on 678,000 individuals and businesses. The intrusion relied on stolen credentials belonging to a DGFiP agent and an authorized third party. Exposed data included reference taxable income, family quotient, source withholding rates, and — for businesses — SIREN numbers and company names, plus cadastral addresses and property sizes. Login credentials for taxpayers' own online accounts were not compromised, DGFiP said (CNIL).

The detection failure is as notable as the breach itself. DGFiP's own security checks, run after it blocked the compromised accounts, did not initially catch that data had been stolen — investigators only established the extraction after a hacker using the handle "ZeroBytes" advertised the database for sale on a criminal forum around August 12–13 (SecurityAffairs; BleepingComputer). DGFiP notified CNIL immediately, filed a criminal complaint that went to the Paris prosecutor's cybercrime unit, and Public Accounts Minister David Amiel asked for proposals to tighten security procedures. CNIL published its own statement on August 18 confirming it is conducting file and on-site verifications of DGFiP's compliance with security obligations, and warned that sanctions are possible if failures under GDPR or French data protection law are found (CNIL).

CNIL's New Security Doctrine

This breach lands seven months after CNIL set a domestic benchmark for exactly this kind of failure. On January 13, 2026, CNIL fined Free and Free Mobile a combined €42 million — €27 million and €15 million respectively — over an October 2024 breach that exposed 24 million subscriber contracts. The sanction rested on three specific findings: authentication and anomaly-detection systems that were not robust enough to prevent or catch unauthorized access (Article 32 GDPR), a breach notification to affected users that omitted information they needed to protect themselves (Article 34), and retention of former-subscriber data with no deletion process in place (Article 5(1)(e)) (CNIL).

Measured against that standard, DGFiP's failure looks comparable or worse: credentials were misused for weeks before anyone noticed, and the theft itself was confirmed only because the data turned up for sale, not through DGFiP's own monitoring. If CNIL's Free decision established that "we got hacked" is not a defense — that inadequate detection and slow, incomplete disclosure are separately punishable — that logic does not stop being true because the defendant is a ministry rather than a telecom.

The Case for Treating Government More Gently

There is a real argument for caution here. DGFiP is not a company competing for customers; it is a monopoly administration that every French household and business must deal with, funded from the same public purse that would absorb any fine CNIL imposes — a sanction doesn't create new security budget, it just moves money between government accounts. And unlike a private firm's shareholders, DGFiP has already demonstrated the transparency GDPR is meant to induce: it notified CNIL immediately, went public within days, and is proactively contacting every affected person. Punishing rapid disclosure as harshly as concealment risks teaching agencies the opposite lesson.

Why the Same Standard Should Still Apply

But that argument for leniency is actually an argument for scrutiny, not against it. Because taxpayers cannot opt out of DGFiP the way a Free customer could switch carriers, CNIL's independent oversight is the only accountability lever citizens have — the same logic that justifies utility regulation applies with more force to a data monopoly than to a market competitor.

Notably, French law already builds in the asymmetry critics might worry about: CNIL's own guidance puts the ordinary-procedure ceiling at €20 million, "or in the case of a company, 4% of annual worldwide turnover" (CNIL). Free's fine reached €42 million because 4% of a multibillion-euro telecom's global revenue exceeds the flat cap; DGFiP, lacking commercial turnover, is realistically capped near that flat €20 million regardless of severity. The state was never going to face Big Tech-scale numbers — GDPR's own arithmetic sees to that.

What CNIL controls is not the ceiling but the rigor of its findings. A published decision that applies the same forensic standard it used against Free — naming the specific authentication and monitoring gaps, not just gesturing at "the breach" — would do more for regulatory credibility than the fine amount itself. Businesses watching CNIL's 2026 enforcement wave, which the regulator says will devote half its inspections and sanctions to cybersecurity failures this year, are entitled to see that the standard is about security practice, not about who can pay the biggest check. Anything less invites the fair complaint that GDPR enforcement in France polices private innovation more zealously than it polices the state.

Sources & Citations

  1. CNIL — DGFiP breach verifications statement
  2. CNIL — Free/Free Mobile sanction decision
  3. CNIL — sanction definition and fine ceilings
  4. BleepingComputer — DGFiP breach report
  5. SecurityAffairs — DGFiP breach report