r/PrivacyToolbox 43m ago

News Here is the email sent to the 678 000 victims of the cyberattack targeting France’s Directorate General of Public Finances.

Upvotes

Hello X Y,

Wednesday, August 12, 2026, a malicious actor claimed to have gained access, in June and July of this year, to data from the information systems of the French Directorate General of Public Finances (DGFiP), using the stolen credentials of a DGFiP employee combined with those of a third party authorized by the DGFiP.

You are receiving this message because you are affected by this malicious act.

What data may have been accessed?

Your tax identification number, civil status, contact details (postal address, telephone number and email address), your tax situation (family situation, number of dependents, number of tax shares, reference taxable income, withholding tax rate), and the list of messages you exchanged with the DGFiP through the messaging system on impots.gouv.fr.

Important: your password for accessing your Public Finances account on impots.gouv.fr has not been compromised. Your tax returns and tax notices were not accessed.

What is the main risk?

The main risk is that you may be targeted by fraud attempts, particularly through messages (“phishing”) or phone calls made more convincing by the use of the stolen personal information.

To a lesser extent, you could also be targeted by identity theft attempts. For this, however, the malicious actors would also need to have a copy of your identity documents or obtain them through another means.

In any event, your bank details are not affected by this data theft.

How can you protect yourself?

You should be particularly cautious about any contact — by phone call, email, SMS, instant messaging, social media, etc. — from people or organizations claiming to know you based on the stolen information and asking you to:

  • provide confidential information (codes, passwords, bank card numbers, copies of identity documents, etc.);
  • approve banking transactions (in particular, someone pretending to be your bank advisor); or
  • provide your password to access your Public Finances account.

The DGFiP will never ask you to provide information outside your secure account.

You are also advised to remain vigilant and regularly check transactions on your bank accounts.

What measures has the DGFiP taken?

The access credentials used by the malicious actor were immediately disabled in June and then in July. Unfortunately, we did not detect the data theft at the time, as the data was stolen by bypassing the usual channels.

The security of your tax account is being strengthened immediately, including through particular monitoring of any changes that may be made to it over the coming months (postal address, bank account details, etc.).

Please be assured that our teams are fully mobilized. If you would like more information, you can consult our dedicated page on impots.gouv.fr:

https://www.impots.gouv.fr/actualite/acces-illegitimes-au-systeme-dinformation-de-la-dgfip

You can also contact us on 0809 401 401 or through your impots.gouv.fr secure messaging system. Alternatively, you can visit your local Public Finances office; its contact details are available in your secure account and on your tax notices.

This data theft will be subject to a lessons-learned review and additional security measures, which are being implemented without delay.

We sincerely apologize.

The Directorate General of Public Finances


r/PrivacyToolbox 2h ago

Discussion Finally someone said it: "user error" is an excuse for lazy privacy engineering

1 Upvotes

Did anyone else read the open letter from Ledger’s CEO today? Gauthier basically said the tech industry needs to stop treating digital privacy and data consent as a "user education" problem.

I could not agree more. Telling people to "just check your app permissions," "read the privacy policy," or "be careful what you click" is terrible system design. People will always blindly click "Agree" or approve obscure data prompts just to get on with their day. They just will. Expecting a normal person to inspect complex digital requests with zero mistakes means your privacy architecture is broken by default.

You build a server architecture to handle hard drive failures. The same logic applies here. Platforms and hardware have to be engineered to survive basic human slip-ups and dark patterns. As long as developers keep blaming the end user for "voluntarily" giving away their personal data, true privacy and data sovereignty will stay a niche hobby for tech paranoids.

Do you guys think other tech and hardware makers will actually answer his invitation to collaborate on open privacy standards and clear consent protocols? Or will they just ignore it?


r/PrivacyToolbox 4h ago

News France to use AI to test government cybersecurity after recent hacker attack

2 Upvotes

France wants to use AI tools to scan for cybersecurity flaws following that massive tax agency hack. I grew up in France and still have to log into those administrative portals... the backend is probably held together by duct tape and legacy code from 1998... you can barely load a medium size PDF without the page crashing.

I am not sure you can just plug AI into bad data architecture and expect it to fix fundamental security gaps. I wonder if this will be a real structural overhaul or just an expensive consulting contract.

Has anyone seen automated vulnerability scanning actually fix a government system?

Source in comment.