PoliticalRepoPoliticalRepo

France · Question · Question écrite

17881

Question 17881 — taxes and duties

openFrance· National Assembly· FR

Introduced

1 September 2026

Last action

Status

posée

Sponsors

Subjects

Discovery layer

Source updated

1 September 2026

Summary

Mr. Matthieu Bloch alerts the Minister of Action and Public Accounts to the serious security breaches that have recently affected the information systems of the General Directorate of Public Finances (DGFiP). The DGFiP recognized that fraudulent access to its information systems had enabled the consultation and exfiltration of data concerning several hundred thousand individuals and professionals. These data are particularly sensitive since they may notably concern the identity and contact details of taxpayers as well as various elements relating to their tax situation. This new breach of data security comes just a few months after the fraudulent access to the national file of bank accounts (FICOBA), made public in February 2026. In this previous case, the usurpation of the identifiers of a official had allowed a malicious actor to access information relating to approximately 1.2 million bank accounts, including bank details, the identity and addresses of their holders. The repetition, in a few months, of incidents based in particular on the compromise or the usurpation of identifiers of authorized persons raises serious questions about the level of security of access to DGFiP information systems. It also questions the measures actually implemented following the FICOBA incident and their ability to prevent the recurrence of such intrusions. The tax administration collects and stores, by legal obligation, some of the most sensitive personal and asset information concerning French people. The latter are therefore entitled to expect from the State a level particularly high level of protection of this data. Consequently, he asks it to specify what measures to secure access to the DGFiP's information systems have been decided and actually deployed since the FICOBA incident of January 2026; what was, at the time of the latest intrusions, the level of deployment of strong authentication for agents and authorized third parties with access to sensitive tax data; why did the control and surveillance mechanisms not make it possible to immediately identify all fraudulent consultations or extractions of data; what new measures are now planned to strengthen authentication, traceability and detection of abnormal access; if the Government intends to make public the main conclusions of the security audits carried out following these incidents, in particular with the assistance of the National Information Systems Security Agency and, finally, what measures will be taken to guarantee rapid and complete information to all taxpayers whose personal data has been compromised.

Machine translation from French. The official text remains authoritative.

Timeline

No timeline events have been ingested for this record yet.

Votes

No vote records are attached yet.

Versions

No version snapshots stored. Document URLs remain at the source.

Documents

No documents linked.

Sponsors

No sponsors or actors listed by the source.

Related records

No cross-record relationships stored yet.

Sources

PoliticalRepo is an index and interpretation layer, not the authoritative legal source.