Overview of the Breach
France's General Directorate of Public Finances (DGFiP) confirmed a personal data breach affecting about 600,000 individuals and businesses. The exposed data included tax identification numbers, household financial details, withholding rates, and, for around 250 people, the actual contents of private messages exchanged with the tax authority. DGFiP is notifying affected parties and warning about potential phishing attacks.
This incident highlights how a single technical vulnerability in a public portal can escalate into a crisis requiring coordinated breach notification, fraud prevention messaging, and ongoing investigation across multiple systems.
Key Findings
Broader Breach Surface Than Initially Reported
DGFiP initially estimated 678,000 affected parties, later revising this to about 600,000 without explanation. This change underscores a common challenge: your initial breach assessment will evolve as forensic investigations progress. You need a communication strategy that accommodates these changes without losing credibility.
Varied Exposure Levels
More than 350,000 individuals had personal and tax information exposed, including marital status, household composition, number of dependents, and reference tax income. Approximately 250,000 businesses had only company names and SIREN numbers compromised. Around 250 people had message contents exposed. This tiered exposure creates distinct notification obligations under Article 34 and requires tailored fraud-prevention guidance for each group.
Vulnerability Extended to a Second System
DGFiP disclosed a separate vulnerability in the Vacant Successions Portal (PSV) and suspended the service. The investigation into whether applicants' details were exposed continues. Discovering additional vulnerabilities during breach response is typical when forensic teams expand their scope beyond the initial attack vector.
Immediate Secondary Fraud Risk
DGFiP warned affected parties about impersonation attempts, CEO fraud, and scams involving bogus bank advisers. The authority clarified it would never request PINs or identity documents by phone, text, or email. Your notification is often the first touchpoint criminals will exploit, so clear guidance is essential.
Implications for Your Team
Understand Your 72-Hour Notification Window
Article 33 requires notification to your supervisory authority within 72 hours of becoming aware of a personal data breach. "Becoming aware" means having enough information to determine a breach has occurred, not complete forensic certainty. If you're a public-sector controller, expect your timeline to be scrutinized more heavily than a private company's.
Prepare Tiered Notification Templates
The DGFiP breach shows why one-size-fits-all notifications fail. Someone whose message contents were exposed faces different fraud risks than someone whose SIREN number was compromised. Your Article 34 communication must describe the likely consequences of the breach and the measures you've taken or propose to mitigate adverse effects. If you're sending identical language to people facing different risk profiles, you're not meeting the standard.
Provide Specific Fraud-Prevention Guidance
Generic warnings about phishing don't help your data subjects distinguish legitimate follow-up from attack traffic. DGFiP's approach was specific: they will never ask for PINs or identity documents except through their secure portal. You need equivalent clarity. What channels will you actually use? What information will you never request? What should recipients do if they're uncertain about a communication's authenticity?
Anticipate Additional Affected Systems
The PSV vulnerability emerged during the broader DGFiP investigation. Your forensic scope should expand to examine systems with similar architecture, shared authentication mechanisms, or comparable access patterns to the initially compromised system. This expansion will delay your final breach count, which is why your initial supervisory authority notification should acknowledge that the assessment is ongoing.
Action Items by Priority
Immediate (within 72 hours of awareness)
Notify your supervisory authority under Article 33 with your current understanding of the breach, explicitly noting which elements remain under investigation. Document your decision-making around the 72-hour timeline, including when you had sufficient information to determine a breach occurred versus when you achieved complete forensic clarity.
Week One
Draft tiered notification templates for different exposure scenarios before you finalize your affected-party count. Each template should address the specific risks that population faces and provide concrete fraud-prevention steps. Identify which internal or external channels you'll actually use for follow-up communication and document those channels in your notifications.
Week Two
Expand your forensic scope to systems with similar technical architecture or access patterns. If you're a public-sector controller, prepare for media inquiries about discrepancies between initial and revised breach counts; have a clear explanation ready about how your assessment methodology evolved.
Ongoing
Monitor for secondary fraud attempts against affected parties and update your guidance if new attack patterns emerge. If you suspended services (like DGFiP did with PSV), document your decision-making around when to restore them and what remediation you completed first.



