France's General Direction of Public Finance has confirmed it fell victim to two separate cyberattacks spanning June and July, marking the latest in a troubling string of breaches targeting the country's most sensitive government databases. The scale of the intrusions highlights how vulnerable even heavily protected institutional systems remain against determined threat actors, raising fresh concerns about data security across the European Union's second-largest economy.

The first breach occurred in June and exposed financial records belonging to at least 678,000 individual and business accounts. According to the tax authority's assessment, attackers obtained a range of sensitive information including taxpayer names, income reference data tied to their fiscal profiles, and details of tax obligations they had fulfilled. This category of data is particularly valuable to cybercriminals because it can be leveraged for identity theft, financial fraud, or sold on underground markets to other malicious actors seeking to target French residents.

A second, separate intrusion took place the following month targeting an entirely different system—the national land registry database. The tax authority stated that details connected to approximately 200,000 property accounts were compromised during this July operation. Property records typically contain ownership information, transaction histories, and valuation data that criminals can exploit to facilitate real estate fraud or conduct sophisticated social engineering campaigns against property owners.

The hacking collective known as Zerobytes has claimed responsibility for orchestrating both attacks. Operating through announcements posted on dark-web forums typically used for illicit trading and criminal coordination, the group asserted that their haul included data on 250,000 land registry accounts—a figure somewhat higher than official authorities acknowledged—representing approximately two million individual property owners and stakeholders. The discrepancy between claimed and confirmed figures is not uncommon in such incidents, where hackers may inflate their accomplishments for reputational purposes within criminal communities.

According to Zerobytes's own disclosure, the attackers gained initial access through a virtual private network system that tax officials rely upon to conduct their work. VPN credentials represent a particularly prized target because they offer gateway access to internal networks, potentially enabling further lateral movement and deeper system compromise. The revelation that such administrative access tools were compromised suggests that either credential security protocols were inadequate or that the attackers possessed advanced capabilities enabling them to bypass standard authentication safeguards. This particular attack vector has become increasingly common among sophisticated state-sponsored and criminal hacking operations targeting government institutions worldwide.

The Zerobytes collective has previously been associated with other high-profile cyberattacks against French government computer infrastructure, indicating this represents a repeat threat actor rather than a one-time opportunistic breach. The group's demonstrated persistence and access to sophisticated techniques suggests they may maintain ongoing interest in French state systems, potentially positioning them for future intrusions if vulnerabilities remain unpatched or if security practices do not substantially improve.

France has emerged as one of the world's most frequently targeted nations by cybercriminals, according to cybersecurity researchers and threat intelligence firms. This elevated risk profile reflects multiple factors: the country's advanced economy and digital infrastructure, the high-value datasets held by government agencies, and the substantial financial resources available to pay ransoms or purchase stolen information on criminal markets. France's position as a leading European power also makes it an attractive target for state-sponsored hacking operations seeking competitive intelligence or disruptive capabilities.

The frequency and severity of breaches affecting French government agencies has escalated markedly in recent years. In April, the ANTS agency responsible for processing identity document applications experienced a massive cyberattack that compromised the personal information of nearly 12 million individuals and professionals nationwide. That incident exposed citizens to substantial risks of identity fraud and unwanted contact from criminals seeking to exploit their compromised credentials.

The tax authority breaches follow an even more alarming discovery made public just four months earlier. In February, the finance ministry disclosed that a large-scale computer system compromise had resulted in the theft of banking details belonging to 1.2 million account holders. That particular breach demonstrated how attackers could penetrate financial systems and extract records that could facilitate direct theft, fraud against banks, or coordinated money laundering schemes involving compromised account information.

The cumulative impact of these successive breaches—affecting identity documents, tax records, land registries, and banking information—suggests that French government institutions face a systemic vulnerability crisis. Rather than isolated incidents, these attacks paint a picture of cyber adversaries operating with relative freedom to access multiple unconnected systems, often exploiting similar weaknesses in credential management, network segmentation, and incident detection capabilities. For French residents and businesses, the pattern represents a significant ongoing risk that their most sensitive personal information remains vulnerable to theft despite government assurances of adequate protection.

For Malaysia and other Southeast Asian nations, the French experience serves as a cautionary lesson about the evolving sophistication of ransomware and data theft operations targeting government institutions. As regional governments expand their digital infrastructure and citizen data collection efforts, they must invest substantially in cybersecurity capabilities, threat monitoring, and incident response protocols. The repeated breaches affecting France—a wealthy developed nation with substantial security budgets—underscore that no country can afford complacency regarding cyber threats to government systems housing sensitive citizen information.