Banque de France building in Nantes, photographed on September 19, 2022. Credits: Chabe01 / Wikimedia Commons — CC BY-SA 4.0.

Bank of France Building in Nantes, photographed on September 19, 2022. Credit: Chabe01 / Wikimedia Commons — CC BY-SA 4.0.

The Socialist group in the Senate is asking Gérard Larcher to open a parliamentary inquiry after the unauthorized access to DGFiP’s information system, in order to establish responsibility and any possible security gaps. The tax administration has identified 678,000 affected users, and the Paris prosecutor’s office has opened an investigation. As of August 17, 2026, however, the parliamentary committee has not been created, while the state is beginning to notify those affected.

A Political Request, Not Yet a Committee

The letter is dated August 15. Patrick Kanner, president of the Socialist, Ecologist and Republican group, asks the president of the Senate to give Parliament an overall view of the incidents that have affected the tax administration since the start of the year. In an interview with RFI, he sums up his goal: “I want to know why, how, where the failures are.”

The wording matters. The Socialist group is not presenting the existence of a structural failure as an established fact. It wants to determine whether the successive episodes are independent or reveal common vulnerabilities, then identify the legislative, regulatory, organizational, or budgetary responses needed.

This request alone is not enough to create a committee. Under the procedure set out by the Senate, a draft resolution must be adopted, or a group may exercise its annual right of referral after a review of admissibility. As of August 17, the Senate has not announced the creation of the committee requested by Patrick Kanner.

Patrick Kanner, photographed in September 2014. Credits: Claude Truong-Ngoc / Wikimedia Commons — CC BY-SA 3.0, CC BY-SA 3.0 Unported.
Patrick Kanner, photographed in September 2014. Credits: Claude Truong-Ngoc / Wikimedia Commons — CC BY-SA 3.0, CC BY-SA 3.0 Unported.

An Intrusion at the End of June, Revealed in August

The statement from the Ministry of Public Action and Accounts places the unauthorized access at the end of June 2026. It attributes it to identity theft, without specifying whether this involved an employee, a contractor, or another authorized account holder. The access was cut off during an operational check, but it had already made it possible to view and extract data concerning individuals and businesses.

DGFiP then estimated the number of affected users at 678,000. For individuals, the exposed information includes, in particular, last and first name, family quotient, reference tax income, and withholding tax rate. For businesses, the administration cites, in particular, the Siren number as well as the company’s address or that of its representative.

These elements are sensitive because they describe a person’s identity and tax situation with precision. DGFiP nevertheless says they do not make it possible to access the secure account on impots.gouv.fr directly. Identified individuals must receive, starting August 17, an email or letter indicating the data that may have been viewed or extracted and the recommended steps for heightened vigilance.

The Gap Between The Intrusion And Its Identification

The timeline leaves one central question unanswered. The administration says it interrupted the access at the end of June, but it did not acknowledge the extraction until after the public claim that appeared on August 12. Its director general, Amélie Verdier, explained that the attacker did not carry out large-scale requests, which are easier to spot. That discretion would have delayed understanding the true extent of the incident.

The technical entry point is not public. The nature of the stolen identity, the level of authorization misused, the exact duration of the access, the checks that triggered the alert, and the computer logs available are not documented. It would therefore be premature to talk about a flaw in the impots.gouv.fr website or to attribute the attack to a specific technical weakness.

The claim circulated under a pseudonym does not amount to judicial identification either. Assertions about the perpetrator, the sale of the files, financial motivations, or the targeting of specific taxpayers remain separate from the facts confirmed by the administration and the courts.

A Criminal Investigation With Different Objectives

The cyber unit of the Paris prosecutor’s office opened an investigation on August 15, entrusted to the Office for Combating Cybercrime. The investigations focus in particular on the fraudulent extraction of data contained in an automated processing system run by the state and on participation in a criminal conspiracy.

The criminal investigation must identify the perpetrators, reconstruct the method used, and establish the offenses. Parliamentary oversight would have a different role: examining the management of the public service, the chain of authorizations, alert procedures, the resources devoted to security, and coordination between agencies.

The two processes cannot, however, overlap without limit. Before creating an inquiry committee, the Senate’s law committee checks that its purpose respects the independence of the judiciary. The scope would therefore need to be framed so as to oversee the organization and actions of the public authorities without encroaching on the facts under prosecution.

The Ficoba Precedent At The Center Of The Questions

The case comes a few months after unauthorized access to the Ficoba file, which lists bank accounts opened in France. In February, DGFiP had indicated that a malicious actor had used the credentials of a civil servant authorized to consult this file as part of exchanges between ministries. Bank details, identities, and addresses had then been accessed.

At this stage, nothing shows that Ficoba and the June intrusion rely on the same technical chain or the same perpetrators. Their comparison nevertheless raises common questions: how are authorizations granted and reassessed? What signals trigger a block? At what point does an abnormal consultation become a confirmed data breach? And who decides to inform users?

The Solidaires Finances publiques union says it alerted management as early as June to the risks of hacking, identity theft, and targeted phishing, after a leak affecting France Services. That alert does not prove any link with the unauthorized access discovered at DGFiP. It does, however, provide an element that senators could compare with the administration’s responses: were the warnings characterized, passed on to the relevant managers, and followed by verifiable measures?

What The Senate Could Seek To Establish

An inquiry committee has powers that a simple political hearing does not. It can summon officials, take testimony under oath, request official documents, and carry out document reviews and on-site inspections, subject in particular to protected secrets and judicial authority. Its work ends with the filing of its report and, at the latest, after six months.

In this case, it could first reconstruct a timeline shared by DGFiP, the senior official for defense and security, the French National Cybersecurity Agency, and the National Commission on Informatics and Liberty. It would be necessary to distinguish the date of the intrusion, the date it was stopped, the date the extraction was understood, the notification to the CNIL, and the information provided to users.

It could then examine the corrective measures. DGFiP says it has tightened access restrictions and is working with specialized state services. But the nature of these changes, their timeline, independent oversight, and the human and budgetary resources mobilized are not yet public. The interministerial task force that Sébastien Lecornu is to chair on August 17 will also have to be assessed in light of concrete decisions, not merely its meeting.

For Users, Vigilance Without Any Prior Step

DGFiP plans to contact each affected individual or business directly. There is therefore no public form to fill out to find out whether you are within the stated scope. Caution remains necessary, because accurate tax data can make a fake refund, a supposed correction, or an urgent request much more convincing.

On its page devoted to security reflexes, the administration reminds users that it never asks for a bank card number by email. If in doubt, it is better to open impots.gouv.fr yourself or go to your secure account rather than follow a link received in a message.

The DGFiP cyberattack thus raises two parallel requirements: immediately protecting exposed individuals and explaining how access interrupted in June could only be fully understood in August. It is on this second question, that of responsibility and the state’s ability to correct its own vulnerabilities, that the Socialist request will have to be judged if it becomes an actual inquiry committee.

This article was written by Christian Pierre.