Major French Tax Agency Breach: Hackers Arrested Amid Phishing Wave

French authorities have made a breakthrough in a significant cyberattack targeting the Directorate General of Public Finance (DGFiP). According to reports from Le Parisien, police arrested two individuals on September 5th suspected of involvement with the hacker group "ZeroBytes." One suspect, an 18-year-old, has been formally charged and remanded in custody as investigations continue.

Over 678,000 Records Stolen, Some Sold Onward

The arrests are directly linked to a major data breach at the DGFiP earlier this year. Officials have confirmed that sensitive information belonging to at least 678,000 individuals and businesses was compromised. The exposed data is extensive, encompassing names, core tax information, and contact details.

Adding to the severity, the ZeroBytes group previously claimed to have sold portions of the stolen tax data to buyers. This suggests the financial privacy of a vast number of French citizens and companies may now be circulating on dark web markets, creating ripe conditions for targeted fraud and identity theft.

Breach Fallout: Paper Phishing Letters Target Crypto Holders

In the wake of the DGFiP incident, a new wave of scams has emerged across France. Security researchers have identified a flood of fraudulent paper letters, impersonating the DGFiP, being sent to cryptocurrency holders.

These sophisticated forgeries use the upcoming EU DAC8 regulation for digital asset reporting as a pretext. Recipients are urged to scan a QR code within the letter, which redirects them to a phishing website designed to steal critical wallet information like private keys or seed phrases.

Suspicious Timing Raises Alarms, Direct Link Unproven

A notable point of concern is the timing. The emergence of these fraudulent letters closely coincides with the DGFiP data breach, leading to speculation that the scammers might be using address data from the leak for targeted delivery.

Security experts, however, remain cautious. They emphasize that while the synchronicity is suspicious, there is currently no concrete evidence proving the address data used in the phishing campaign originated directly from the DGFiP breach. Investigators are exploring potential links between the two criminal activities from multiple angles.

These events serve as a dual warning. They highlight the vulnerabilities in large institutional data security while also showcasing an evolution in cybercrime—a hybrid model blending digital data theft with offline, socially-engineered fraud. Vigilance against such combined threats is now more critical than ever.