Breaking
14 Sep 2026, Mon

AM 1575 News — Pirated taxes: phishing with tax number at risk | August 14, 2026

You are listening to a new special of France Today in podcast and on Central Milan 1575 kHz.

Confirmed cyber attack

The Ministry of Economy has confirmed the compromise of the French taxpayers’ platform, which occurred at the end of June. A malicious actor gained unauthorized access to the information system of the Directorate General of Public Finances (DGFiP) and, according to early investigations, was able to view and download data from both individuals and businesses. Authorities have not yet specified how many taxpayers were affected nor the full extent of the information taken.

Stolen data

According to the specialized site French Breaches, the theft would include names, dates of birth, residential addresses, cadastral identifiers and parcel numbers, as well as phone numbers and email addresses. The presence of the tax number among the stolen information makes the data particularly sensitive, because it allows impersonating the victim in official communications.

Fraud risks

With this information at hand, cybercriminals can launch targeted phishing campaigns, posing as the DGFiP. The scams could come as emails or SMS that cite the victim’s tax number, asking for password confirmation or bank details to access their personal space on the tax website. The messages typically include links to fake portals that faithfully reproduce the look of government sites.

Advice for taxpayers

Tax authorities have already issued an alert to the public: the DGFiP never asks, either by email or by phone, for bank information, personal data or login credentials. Users must carefully verify the sender’s address: only communications ending with “@dgfip.finances.gouv.fr” are legitimate. It is recommended not to click any link contained in suspicious messages and, if in doubt, to access your account only by typing the address directly into the browser, ensuring the domain ends with “.gouv.fr”. Moreover, the DGFiP does not make calls from mobile numbers (06 or 07) and does not use spoofing techniques to mask legitimate numbers; any call requesting sensitive data should be considered fraudulent. In case of phishing attempts, it is advisable to report the incident immediately to DGFiP support and the competent authorities.


rachel-generic

Rachel’s editorial – When data become the new daily bread

I will now read you my today’s editorial.

It is not the first time that our beloved public administration becomes the data sweeper: two months ago the health sector handed out its personal stuff to anyone who wanted it, now the finance ministry opens the chests of our tax numbers. And while our data slip away like breadcrumbs, the media present us with the sacred recipe “to protect children”: forcing the little ones to hand over identity and history to use Instagram, TikTok and the like, guaranteeing that “they will be safe”. But really, who watches the guard?

The press release from the Ministry of Economy is curiously more vague than a Kafka novel: “a malicious actor gained access”, but no indication of how many data were taken or how many poor taxpayers will still have to fear phishing. The role of journalism? To skim the news with advice like “don’t click” and “check the email address”, as if a digital applause were enough to quell our fear. And we, gullible, keep reading the warnings without asking: who really controls this advice?

And while cybercriminals enjoy impersonating the Directorate General of Finance, our phones ring with numbers that seem taken from a fake call‑center catalog. Spoofing, phishing, emails that promise refunds of our accounts: it is almost poetic. Yet the bitterest poetry is that after this scandal, no one worries about data compatibility with children’s social media. Tax data to access Instagram filters? A convenience marriage between the State and platforms that promise “protection of the little ones” but sell our secrets to those who need them.

In short, the official narrative is a piece of theatre: “protect the children” is the script, but the real aim is to record, classify and monitor those who dare to dissent. We place too much trust in security messages that once had to protect us from the virus, now sell our privacy at clearance prices. It truly is time to ask ourselves: how many more “data forests” must be felled before we realise the fire is lit by ourselves?

Koan of the day

Monk: Master, if a hacker can steal my tax number, why should I still give my data to social media to “protect” my children?

Master: Because the child watching a cat video is more valuable to the market than what the tax authority deems “important”, so the government hands over the ticket to the circus.

Monk: And if the phishing risk is real, isn’t it wiser to close the door rather than open it to everyone?

Master: Whoever closes the door stays in the dark room, but whoever opens it to everyone discovers that the curtain has already been raised on a play that never had an audience.

This is all for now. From the Paris newsroom, I’m Rachel Costa: this is FranceToday with Central Milan 1575 kHz.