France · Question · Question écrite
17881
Question 17881 — taxes and duties
Introduced
1 September 2026
Last action
—
Status
posée
Sponsors
—
Subjects
Discovery layer
Source updated
1 September 2026
Summary
Mr. Matthieu Bloch alerts the Minister of Action and Public Accounts to the serious security breaches that have recently affected the information systems of the General Directorate of Public Finances (DGFiP). The DGFiP recognized that fraudulent access to its information systems had enabled the consultation and exfiltration of data concerning several hundred thousand individuals and professionals. These data are particularly sensitive since they may notably concern the identity and contact details of taxpayers as well as various elements relating to their tax situation. This new breach of data security comes just a few months after the fraudulent access to the national file of bank accounts (FICOBA), made public in February 2026. In this previous case, the usurpation of the identifiers of a official had allowed a malicious actor to access information relating to approximately 1.2 million bank accounts, including bank details, the identity and addresses of their holders. The repetition, in a few months, of incidents based in particular on the compromise or the usurpation of identifiers of authorized persons raises serious questions about the level of security of access to DGFiP information systems. It also questions the measures actually implemented following the FICOBA incident and their ability to prevent the recurrence of such intrusions. The tax administration collects and stores, by legal obligation, some of the most sensitive personal and asset information concerning French people. The latter are therefore entitled to expect from the State a level particularly high level of protection of this data. Consequently, he asks it to specify what measures to secure access to the DGFiP's information systems have been decided and actually deployed since the FICOBA incident of January 2026; what was, at the time of the latest intrusions, the level of deployment of strong authentication for agents and authorized third parties with access to sensitive tax data; why did the control and surveillance mechanisms not make it possible to immediately identify all fraudulent consultations or extractions of data; what new measures are now planned to strengthen authentication, traceability and detection of abnormal access; if the Government intends to make public the main conclusions of the security audits carried out following these incidents, in particular with the assistance of the National Information Systems Security Agency and, finally, what measures will be taken to guarantee rapid and complete information to all taxpayers whose personal data has been compromised.
Machine translation from French. The official text remains authoritative.
Timeline
No timeline events have been ingested for this record yet.
Votes
No vote records are attached yet.
Versions
No version snapshots stored. Document URLs remain at the source.
Documents
No documents linked.
Sponsors
No sponsors or actors listed by the source.
Related records
No cross-record relationships stored yet.
Sources
PoliticalRepo is an index and interpretation layer, not the authoritative legal source.
- Official source: https://www.assemblee-nationale.fr/dyn/17/questions/QANR5L17QE17881
- Open data entity: https://www.assemblee-nationale.fr/dyn/opendata/QANR5L17QE17881