
A breach of France's tax database affecting 678,000 people coincides with a surge in physical crypto attacks. The combination exposes a weakness cold storage cannot fix.
France's latest tax-data breach creates a security problem for cryptocurrency holders that cold storage cannot solve. The French tax authority confirmed August 14 that attackers extracted data on 678,000 individuals and businesses, including income and property information. Separately, security firm CertiK recorded 33 verified physical crypto attacks in France during the first half of 2026, making the country the largest concentration in its global dataset.
The breach does not directly expose crypto wallets. The combination of identity, income and address data with a rising trend in wrench attacks expands the threat surface. French prosecutors said in March a family in Vaires-sur-Marne was targeted by mistake when attackers searched for cryptocurrency. A couple in Le Chesnay was forced to transfer about €900,000 in Bitcoin.
The DGFiP detected the intrusion in June and July after a malicious actor compromised credentials of a tax official and an authorized third party. The affected access was terminated. The attacker later publicly claimed data extraction, which subsequent investigations confirmed. The government said 678,000 individuals and professionals were affected. Online tax accounts were not compromised.
CertiK recorded 52 verified wrench attacks globally during the first half of 2026, up from 39 in the same period of 2025. France accounted for 33 cases. The financial exposure associated with the worldwide attacks reached approximately $124.1 million, compared with $10.5 million a year earlier. Home invasions rose from one verified incident in the first half of 2025 to 20 in H1 2026.
The risk is not to any specific token but to the holders themselves. Physical attacks target the person, not the private key. Hardware wallets and multisig arrangements do not prevent coercion. The security perimeter expands from the wallet to the holder's identity, residence and family.
Data minimization can reduce the risk. Separating public identity from wallet activity, reviewing what home information is publicly available, and using geographically separated signing authority all limit the data points criminals can correlate. Treating personalized tax or banking contact with suspicion is also important because stolen information can make phishing calls convincing.
The breach follows another major incident earlier in 2026. Attackers obtained unauthorized access to FICOBA, France's national database of bank accounts, affecting about 1.2 million accounts. That breach included account-holder identities and addresses but not balances. The DGFiP breach adds tax and property information, which criminals can combine across leaks.
French authorities referred the breach to the CNIL. The next key disclosure will be whether investigators can confirm how much of the dataset circulated and whether the high-income taxpayer claims are accurate. Unconfirmed reports say the leaked dataset includes 386 people with reference taxable income exceeding €1 million.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.