Print this article

French Ministry Data Breach Prompts Fresh EU Privacy Concerns

Tom Burroughes

18 August 2026

Government databases holding details of individuals’ tax and other financial affairs continue to be vulnerable to cyber attacks, as demonstrated by high-profile cases. 

Last week, the Finance Ministry in France confirmed that the data of 678,000 users had been stolen by a “malicious actor.”

Privacy campaigner Filippo Noseda, partner at international law firm , who has for years flagged concerns that government-to-government data transfers compromise citizens’ privacy, said in a letter to the European Union that the “French Ministry of Finance only came clean after reports in the press, confirming a culture of contempt and cover-up when it comes to citizens’ personal data.” 

Noseda’s letter, which he republished on his LinkedIn page, was addressed to Michael McGrath, EU Commissioner for Democracy, Justice and Rule of Law and Consumer Protection; Antonio Costa, President of the European Council, Wojciech Wiewioroski, European Data Protection Supervisor, and Anu Talus, Chair, European Data Protection Board. Noseda has asked the EU for a temporary halt, and data security audit, of all EU and EU member states' systems that hold "sensitive personal and financial data of individuals and businesses pursuant to measures requiring bulk collection of information enacted by the EU."

Noseda also wrote to the Organisation for Economic Co-operation and Development, including Manal Corwin, director, Centre for Tax Policy and Administration, referring to "renewed concerns relating to OECD bulk collection of data."

The incident raises further concerns about whether government data gathering on individuals’ business and financial affairs, and associated demands for transparency, conflict with legitimate financial privacy.

There is a particular concern when such data is transferred in bulk to other governments under various international treaties, such as the Common Reporting Standard (CRS) 

Two weeks ago, the government of Liechtenstein said a register of beneficial ownership had been attacked and that, as a result, systems have been temporarily taken offline. (See analysis from this news service here.)

In its 13 August statement, the French ministry said: “In-depth investigations conducted since 12 August 2026 have established that, before access was cut off, these accounts had been used to view and extract certain data concerning a total of 678,000 individuals and businesses, including tax data such as reference taxable income, family quotient, and the withholding tax rate, and, for businesses, data such as their company name or SIREN number. Land registry data relating to property addresses and surface areas was also accessed. As soon as this data theft was identified, the DGFiP notified the CNIL (France's data protection authority). The `Finances publiques’ online accounts of individual and business users were not compromised. Also, the login credentials and passwords of individuals and businesses were not compromised.

"Following new findings from the ongoing investigations, additional security measures were immediately implemented, including preventive shutdowns of access to sensitive information systems. Investigations are continuing in order to determine precisely the nature and volume of the data extracted, as well as the number of users affected,” the statement, originally published in French, said. The DGFiP will contact affected individuals and companies, it said. (DGFiP is Direction générale des Finances publiques, the tax authority.)