DGFiP COMPROMISED: THE EXTRAORDINARY CONFLICT OVER “BACKDOORS”
The DGFiP was hacked. Your data, our data, were taken, and the risks of fraudulent use of those data are enormous, creating the possibility of serious consequences for many of you. But behind that striking formulation, do you know what was happening behind the scenes?
In everyday language, the word “hack” sums up what happened. Technically, Bercy refers to unauthorized access obtained following identity theft, which made it possible to view and extract data. The real issue therefore goes far beyond a simple computer incident. To understand what is at stake, we need to look at how France organizes the protection of its administrations, why a major European cybersecurity reform is still not fully transposed, and why a conflict over encryption has for months pitted different conceptions of security against one another.
BEFORE GOING ANY FURTHER: WHAT IS NIS2, AND WHAT DOES “TRANSPOSE” MEAN?
NIS2 means “Network and Information Systems 2”. Behind this highly technical name lies the second major European directive devoted to the cybersecurity of organizations essential to the functioning of a country.Its objective is easy to understand: to require European States to better protect essential administrations, infrastructure and companies against cyberattacks.
Why does this concern everyone?Because NIS2 notably covers actors in energy, transport, health, telecommunications, digital services, industry and certain public administrations. A successful attack on a hospital, electricity operator, tax administration or digital infrastructure can have consequences far beyond the computer attacked: interruption of a service, shutdown of activity, data theft, fraud, damage to important infrastructure or propagation of the attack to other organizations.
But a European directive does not automatically become, in every detail, French law applicable overnight. The European Union sets common objectives and obligations, then each State must adapt its own law to make them fully applicable on its territory.This operation is what is called “transposition.”
It can be pictured very simply. In substance, the European Union tells the 27 Member States: “Here is now the minimum level of cybersecurity that certain essential administrations, infrastructure and companies must meet. It is up to you to incorporate these rules into your national legislation, precisely identify the organizations concerned, organize oversight, cyberattack-reporting obligations and sanctions.”
For NIS2,France had until October 17, 2024to complete this work. Yet it is August 2026 andthis transposition is still not fully complete. On July 8, 2026, the European Commission decided to refer France to the Court of Justice of the European Union for failure to complete the transposition. At the same time, the DGFiP has just acknowledged that identity theft enabled unauthorized access to its information system, with data concerning individuals and professionals being viewed and extracted.
A QUESTION THEN ARISES: WHAT HAPPENED, FOR ALMOST TWO YEARS, BEHIND THE INSTITUTIONAL CURTAIN OF FRENCH CYBERSECURITY?
Before going any further, a limit must be stated so that no one can caricature this article.I am not claiming that the failure to transpose NIS2 caused the DGFiP compromise. Nor am I claiming that NIS2 would miraculously have prevented this intrusion. And I am not claiming that the DGSI deliberately prevented France from protecting itself.What the official documents do show is sufficiently concerning to justify a much deeper political inquiry.
NIS2 WAS SUPPOSED TO BE TRANSPOSED BY OCTOBER 17, 2024
The European NIS2 Directive was adopted on December 14, 2022 to raise and harmonize the level of cybersecurity across the European Union. Article 41 is very clear: Member States had to adopt and publish the measures necessary for its transpositionno later than October 17, 2024, and apply them from October 18, 2024.
Source:EUR-Lex, Directive (EU) 2022/2555, Article 41:
https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng
Legally, the directive covers eighteen sectors considered critical and includes certain public administrations. In particular, it classifies central-government public administrations among the “essential entities”, according to the definitions adopted nationally, while providing specific exceptions for certain activities relating to national security, defence or law enforcement.
An “essential entity”is, in simple terms, an organization whose failure could have major consequences for the population, the economy or the functioning of the country.The word “critical”is therefore not dramatic wording. It means that we are talking about organizations whose normal operation is considered especially important.
Source:EUR-Lex, NIS2 Directive, scope and annexes:
https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng
NIS2 imposes a genuine cyber-risk management doctrine. In practical terms, it is no longer enough to say that one is doing one’s best. Security must be organized, documented, supervised and tested.
analyse the risks affecting systems
provide for incident management
organize business continuity and backups
secure the supply chain, meaning the contractors, suppliers and software on which the organization depends
manage vulnerabilities, in other words technical weaknesses that could be exploited
train staff and senior management
use cryptography and encryption where necessary
control access rights
use multi-factor authentication where appropriate
directly involve governing bodies in cybersecurity governance
“Multi-factor authentication”means not relying on a simple password alone. A second proof of identity is added, for example a physical security key, an application or another independent mechanism.“Cryptography”covers techniques used to protect information, notably by making it unreadable without the intended key.
Source:EUR-Lex, NIS2 Directive, notably Articles 20 and 21:
https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02022L2555-20221227
THIS IS THEREFORE NOT DECORATIVE LEGISLATION. IT IS A MAJOR CHANGE IN CYBERSECURITY GOVERNANCE.
FRANCE MISSED THE DEADLINE. THEN EUROPEAN WARNINGS ACCUMULATED
On November 28, 2024, the European Commission opened infringement proceedings against France and twenty-two other States that had not fully transposed NIS2. On May 7, 2025, it moved to the next stage by sending a reasoned opinion to France and eighteen other Member States. Then, on July 8, 2026, the European Commission decided to refer France, Ireland, Spain and the Netherlands to the Court of Justice of the European Union for failure to fully transpose NIS2. It also requested financial penalties.
Source:European Commission, November 28, 2024:
Source:European Commission, May 7, 2025:
Source:European Commission, status of NIS2 transposition and 2026 referral:
https://digital-strategy.ec.europa.eu/en/policies/nis-transposition
To understand the seriousness of this timeline, the mechanism needs to be explained.An “infringement procedure”is the procedure through which the European Commission formally alleges that a State is failing to comply with EU law. It begins by asking the State to bring itself into compliance. If the problem persists, the Commission may issue a “reasoned opinion”, meaning a more formal legal challenge. If that is still not enough, it can refer the matter tothe CJEU, the Court of Justice of the European Union.
The CJEU is the court responsible for ensuring compliance with European Union law. In other words, when the Commission decides to refer a case to it,the matter is no longer at the stage of a simple political or administrative reminder. The disagreement enters a European judicial procedure that can, under certain conditions, lead to financial penalties.
WE ARE THEREFORE FAR BEYOND A SIMPLE ADMINISTRATIVE DELAY OF A FEW WEEKS.
AND NIS2 IS NOT EVEN THE ONLY EUROPEAN DISPUTE LINKED TO THIS DELAY
On May 12, 2026, the European Commission had already brought an action against France before the Court of Justice,Case C-481/26, for failure to transpose theCER Directive 2022/2557on the resilience of critical entities. That directive is also part of the same major French bill on the resilience of critical infrastructure and the strengthening of cybersecurity.
The word “resilience”here means the ability of an essential organization to continue operating, or restart quickly, when it faces a crisis.NIS2 focuses on cybersecurityof networks and information systems.CER takes a broader viewof the continuity of critical entities in the face of different disruptions. The delay to the French legislation therefore no longer creates a single European legal dispute, but several.
Source:CURIA, European Commission v French Republic, Case C-481/26, action brought May 12, 2026:
https://juris.curia.europa.eu/juris/document/document.jsf?docid=313368&doclang=en
YET THE FRENCH BILL HAS EXISTED SINCE OCTOBER 2024
The French Government tabled the bill on the resilience of critical infrastructure and the strengthening of cybersecurity on October 15, 2024. It had invoked the “accelerated procedure”. This does not mean that Parliament no longer debates. It means that the Government chooses a shortened legislative route, with fewer successive readings between the National Assembly and the Senate before seeking a common text. In other words, the Government had officially chosena procedure intended to move faster.
The Senate adopted the bill at first reading on March 12, 2025, after which the text was sent to the National Assembly.
Source:National Assembly, legislative dossier:
https://www.assemblee-nationale.fr/dyn/17/dossiers/DLR5L17N50731
The National Assembly’s special committee examined it on September 9 and 10, 2025.A “special committee”is a group of MPs formed to examine a particular bill before it is considered in thechamber, meaning the room where all MPs can then debate and vote on it in public session. The committee studies the articles, debates amendments and prepares the version that will be put before all MPs.
It worked on472 amendments, adopted244and, particularly notably for such a broad subject, adopted the billunanimously.An “amendment”is simply a proposal to modify, add or delete part of a bill.
Source:National Assembly, Report No. 1779:
https://www.assemblee-nationale.fr/dyn/docs/RAPPANR5L17B1779-tI.raw
And yet, as of August 14, 2026, the National Assembly’s official legislative dossier still shows no consideration of the text in public session after the special committee’s work in September 2025. A committee’s adoption of a bill is therefore not enough to make it law. The text must still be placed on the agenda, debated and voted on according to the required procedure.
Source:National Assembly, updated legislative dossier:
https://www.assemblee-nationale.fr/dyn/17/dossiers/DLR5L17N50731
THE DELAY FIRST HAD CONVENTIONAL POLITICAL EXPLANATIONS
To be completely fair, the institutional explanations that do exist must be recalled. The National Assembly’s official report explains that transposition was first delayed by the dissolution of the National Assembly, then by the fall of Michel Barnier’s government following a no-confidence vote, and finally by congestion in the legislative timetable.
Source:National Assembly, Report No. 1779:
https://www.assemblee-nationale.fr/dyn/docs/RAPPANR5L17B1779-tI.raw
On March 25, 2026, questioned in the National Assembly by Philippe Latombe, Minister Delegate Anne Le Hénanff again cited congestion in the parliamentary agenda and stated, after discussions with the political groups, that the bill would be examined in July. She nevertheless acknowledged that transposition had still not been completed and that certain obligations would become truly mandatory only after the legislation was adopted.
The minister notably cited the example of a company that, before transposition, did not yet have an obligation to notify ANSSI of a cyberattack even though it would once NIS2 had been transposed. The same minister nevertheless recalled that companies had no reason to wait for the law before voluntarily strengthening their security. Exactly the same distinction must be applied to the State.
Source:National Assembly, oral question without debate No. 623:
https://www.assemblee-nationale.fr/dyn/17/questions/QANR5L17QOSD623
WHAT NIS2 CHANGES IN CONCRETE TERMS WHEN AN INCIDENT OCCURS
The word “notification”here means that an organization suffering a serious incident cannot simply manage the crisis privately and inform the authorities several weeks later. The new regime provides for rapid escalation of information so that the cyber authority can understand the threat, support the response and, where necessary, warn other organizations exposed to the same risk.
For a significant incident falling within NIS2, the directive provides for an early warning within24 hoursafter becoming aware of the incident, a fuller notification within72 hours, followed by a final report no later thanone monthafter the notification. If the incident is still ongoing, an interim report is provided and the final report follows within one month after it has been handled.
Source:EUR-Lex, NIS2 Directive, Article 23:
https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022L2555
ANSSI HAD EVEN ALREADY PUBLISHED THE INSTRUCTIONS
ANSSI is the French National Cybersecurity Agency.It is the French State’s technical reference authority for cybersecurity. It helps administrations and sensitive organizations protect themselves, publishes security frameworks and plays a central role in preventing and responding to cyber threats.
Since March 17, 2026, ANSSI has made the Référentiel Cyber France, ReCyF, available. A “framework” is, in simple terms, a structured set of rules and measures used to determine what level of security should be achieved and how to assess it. ReCyF lists the recommended measures for meeting NIS2 security objectives.
But ANSSI itself specifies that, until the legal framework has fully entered into force, this framework remains non-binding by default. The Agency nevertheless urges future essential and important entities to begin their security work immediately rather than wait for transposition to be completed.
Source:ANSSI, NIS2 Directive and ReCyF:
NIS2 IS NOT THE BEGINNING OF MANDATORY STATE CYBERSECURITY
This is an essential point.The delay in NIS2 does not meanthat the DGFiP or any other French administration was previously free to do whatever it wanted in computer security.
France has long had aPSSIE, the “State Information Systems Security Policy”. It can be viewed as the baseline set of cybersecurity rules that the State already imposes on itself. Published by Prime Ministerial circular in 2014, it lays down a set of protection rules applying to State information systems. The French framework also provides forsecurity accreditationprocedures for certain systems contributing to State missions.
A “security accreditation” is a formal decision through which an authority accepts that a system may operate after its risks and the protective measures in place have been examined. It is therefore not merely an informal recommendation.
Source:Légifrance, July 17, 2014 circular on the PSSIE:
https://www.legifrance.gouv.fr/circulaire/id/38641
Source:Légifrance, security-accreditation framework for information systems supporting State missions:
https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000050080243
Where personal data are processed, the GDPR also applies.The GDPR is the General Data Protection Regulation.Many citizens mainly know it through consent banners on websites, butit also requires appropriate technical and organizational measuresto ensure a level of security appropriate to the risk.
In the event of a personal-data breach, notification to the supervisory authority must occur without undue delay and, where feasible, within72 hoursafter becoming aware of it, unless the breach is unlikely to result in a risk to people’s rights and freedoms. In France, the competent supervisory authority isCNIL, the French Data Protection Authority.
Source:EUR-Lex, GDPR, Articles 32 and 33:
https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
In other words, the delay in NIS2 is open to criticism and institutionally significant, butit absolutely cannot serve as a smokescreenfor obligations that already existed. The right question is not whether the DGFiP was allowed to protect itself before NIS2. It was. The question is whether already mandatory measures and well-known good practiceswere actually being applied at the required level.
WHAT PROTECTIONS WERE ACTUALLY IN PLACE?
BECAUSE THE COUR DES COMPTES HAD ALREADY WARNED ABOUT STATE CYBERSECURITY
On June 16, 2025, the Cour des comptes published a report on the State’s response to cyber threats affecting civilian information systems. The Cour des comptes is the institution responsible, among other things, for overseeing the use of public money and evaluating certain public policies. In that report, it noted a sharp increase in cyber threats, which were becoming increasingly sophisticated and diverse.
It notably called for stronger interministerial governance and for cybersecurity resources to be adapted.In everyday language, that means it considered that the different ministries and State services needed to be better coordinated, have clear rules and use resources suited to the threat.
Source:Cour des comptes, June 16, 2025:
The Cour also noted that in-depth assessment of central administrations’ cyber maturity was still relatively recent and that the tools, arrangements and actors involved in public-sector cybersecurity still needed to be rationalized and coordinated.“Cyber maturity”simply means an organization’s real level of preparedness for digital risks: procedures, skills, resources, controls, incident response and ability to correct weaknesses.
Source:Cour des comptes, full report:
A CRUCIAL POINT: ARTICLE 16 BIS IS NOT A NIS2 REQUIREMENT
Why is there an “Article 16 bis”?The word “bis”simply means that a new article was inserted between two existing articles during the parliamentary process. Article 16 bis was therefore not an obligation imposed by the European NIS2 text.It was added by the Senateto the French bill.
The French bill does not transpose NIS2 alone. It brings together several European frameworks relating to resilience and cybersecurity, including the CER Directive, the NIS2 Directive and adaptations linked to the DORA Regulation for the financial sector.
DORAis a European regulation on digital operational resilience in the financial sector.Unlike a directive, a European regulation is in principle directly applicablein the Member States. The French bill nevertheless contains national adaptations needed to align this framework with French law.
Source:National Assembly, Report No. 1779 on the bill:
https://www.assemblee-nationale.fr/dyn/docs/RAPPANR5L17B1779-tI.raw
This makes the political question even more precise: did an additional national provision, separate from the minimum obligations required to transpose NIS2,contribute to blockingthe legislation containing precisely the transposition that France should have completed by October 2024? At this stage,that causal link must be established. But it deserves a public answer.
People sometimes refer to the bill as a“legislative vehicle”. The expression is parliamentary jargon. It simply means that the same piece of legislation serves as the legal vehicle for bringing several reforms into French law. If that vehicle remains stalled, several sets of rules remain suspended with it.
THEN ARTICLE 16 BIS APPEARS: THE HEART OF THE CONFLICT OVER ENCRYPTION
Article 16 bis seeks to prevent encryption-service providers from being required to integrate mechanisms designed deliberately to weaken the security of their systems. The National Assembly report explains that the article notably targets the well-known “backdoors” as well as master keys that make it possible to bypass encryption.
A backdooris a mechanism that bypasses a system’s normal protections in order to access information that would otherwise be protected.A “master key”is, by analogy, a key capable of opening several protected accesses. The idea may sound attractive if that access is reserved for the authorities. The problem is thata deliberately created weakness remains a weakness. If a cybercriminal or a foreign service discovers it, steals it or hijacks it, it can become an entry point for the very actor it was supposed to keep out.
Source:National Assembly, Report No. 1779, Article 16 bis:
https://www.assemblee-nationale.fr/dyn/docs/RAPPANR5L17B1779-tI.raw
The argument made by supporters of Article 16 bis is therefore simple: deliberately creating a bypass for the authorities can also create a vulnerability that a malicious actor can exploit. The National Assembly did not remove the provision in committee. It broadened it to cover certain “processes” that could produce the same effect as a technical backdoor.
WHERE DID THIS CONFLICT COME FROM? THE PRECEDENT OF THE ANTI-DRUG-TRAFFICKING LAW
The conflict did not emerge in a vacuum. In early 2025, during consideration of the bill intended to “free France from the drug-trafficking trap,” the Senate introduced an Article 8 ter imposing obligations on encrypted-messaging operators intended to enable access to the intelligible content of certain communications.
In plain terms, the debate concerned the authorities’ ability to obtain readable content from communications that were nevertheless protected by encryption. The provision generated serious concerns about the overall security of encryption. It was removed during the parliamentary process and ultimately did not survive the joint committee.
A “joint committee”, often abbreviatedCMP, brings together MPs and senators when the two chambers have not adopted exactly the same text. Its role is to try to reach a common wording.
Source:National Assembly, amendment CL392 removing Article 8 ter:
https://www.assemblee-nationale.fr/dyn/17/amendements/0907/CION\_LOIS/CL392
Source:Senate, April 2025 debates confirming the removal of Article 8 ter by the joint committee:
https://www.senat.fr/seances/s202504/s20250428/s20250428\_mono.html
The timeline then becomes much easier to understand: a highly intrusive decryption proposal, opposition, withdrawal, a parliamentary response through Article 16 bis, concern within the intelligence services, then institutional conflict over the wording to retain.This history does not by itself establish why NIS2 was not adopted.It does, however, explain why encryption became one of the most sensitive points in the dossier.
Source:National Assembly, Report No. 1779:
https://www.assemblee-nationale.fr/dyn/docs/RAPPANR5L17B1779-tI.raw
BUT FOR THE INTELLIGENCE SERVICES, THIS ARTICLE CREATES A MAJOR PROBLEM
The DPR, or Parliamentary Intelligence Delegation, is not a secret service.It is a parliamentary body responsible for monitoring and overseeing the work of the French intelligence services. When it writes that a provision representsa “major risk for public intelligence policy”, this is therefore not an anonymous comment on the Internet, but an institutional position from parliamentarians specifically tasked with this oversight.
In an official communication from May 2026, the DPR indeed considers that the wording of Article 16 bis could weaken the legal framework allowing certain intelligence and investigative techniques and make them harder to implement. It also considers it necessary to continue dialogue with platforms and envisages that legislative intervention may be required if cooperation remains insufficient.
Source:Parliamentary Intelligence Delegation, May 2026 communication:
The DGSI, cited in this dossier, is theGeneral Directorate for Internal Security. It is the French service responsible notably for counter-espionage, counter-terrorism and protection against certain threats affecting national security. For these services, the problem posed by end-to-end encryption is concrete.
In a genuinely end-to-end encrypted system, a message is made unreadable at the sender’s end and becomes readable again only at the recipient’s end. The intermediary carrying the message normally does not possess the key needed to read its content. This is excellent for protecting citizens, businesses, journalists or industrial secrets. But it can also make lawful access to the communications of a person under surveillance much more difficult.
We therefore have two genuine security concerns colliding:
cybersecurity specialists and defenders of encryption fear that a door created for the authorities could also become a vulnerability exploitable by cybercriminals or hostile States
intelligence services explain that very robust end-to-end encryption can prevent access to certain communications that are nevertheless lawfully sought in investigations into serious threats
Both sides are therefore talking about security, but they are not protecting against exactly the same risk.That is precisely what makes the trade-off so difficult.
ON JULY 1, 2026, OLIVIER CADIC PUBLICLY ACCUSES THE GOVERNMENT
On July 1, 2026, at an official meeting of the Senate Committee on Foreign Affairs, Defence and the Armed Forces, Olivier Cadic spoke. He is the author of Article 16 bis. He explained that he had met with the DGSI, the Minister of the Interior and several figures at the highest level of the State on this matter.
Source:Senate, committee record of July 1, 2026:
https://www.senat.fr/compte-rendu-commissions/20260629/etran.html
He then made a very specific public accusation. According to him, after his amendment was adopted by the Senate and strengthened in committee at the National Assembly, the Government was now preventing the bill from being placed on the National Assembly’s agenda, thereby blocking its final adoption. He also stated that no alternative wording of the article had been proposed to him.
The “agenda”simply means the list of texts that the National Assembly will actually consider in public session. A bill may therefore have been studied and adopted in committee without ever becoming law if it is not subsequently scheduled for debate and a vote in the chamber. That is why the accusation concerning placement on the agenda is politically important.
Source:Senate, official record:
https://www.senat.fr/compte-rendu-commissions/20260629/etran.html
This statement is neither an anonymous tweet nor a rumour. It appears in the Senate’s official record. But rigour is still required.It is Olivier Cadic’s accusation. It is not an admission by the Government.We do not currently have a Government document stating: “We blocked NIS2 because of Article 16 bis.” We must therefore avoid presenting that causal link as an established fact.
WHAT HAS NOW BECOME IMPOSSIBLE TO DENY
Several documented facts can be placed side by side:
the conflict over Article 16 bis exists
the Parliamentary Intelligence Delegation considers it a major issue for the services
the author of the article says that he met directly with the DGSI and the Minister of the Interior
that author publicly accuses the Government of blocking the entire bill
the Government had previously cited political instability and congestion in the parliamentary agenda
the National Assembly’s special committee had nevertheless adopted the bill unanimously as early as September 2025
the Government was still announcing in March 2026 that it would be examined in July
that examination did not take place and, in August 2026, the bill still has not been adopted
Source:National Assembly, DPR, May 2026:
WHAT EXACT PART DID THE ENCRYPTION CONFLICT PLAY IN THE NIS2 DELAY?
AND MEANWHILE, THE LEAKS CONTINUE
DGFiP is the Directorate-General of Public Finances, in other words the French tax administration. It manages taxation, part of public revenue collection and numerous extremely sensitive tax or financial databases.“Bercy”is the name commonly used to refer to the Ministry of the Economy and Finance, located in the Bercy district of Paris.
On February 18, 2026, Bercy had already announced unauthorized access to the national bank-account register, FICOBA.FICOBA is the national register of bank and similar accounts.It records the existence of accounts opened in France and the identity of their holders. It is not a detailed statement of every purchase made by a citizen, but the information it contains remains highly sensitive.
According to Bercy, a malicious actor had stolen the credentials of a civil servant who had access as part of exchanges between ministries. The searches and data extractions concerned around 1.2 million accounts. Accessible information notably included the holder’s identity, address and bank details, including RIB or IBAN.
A RIBis a French bank-account identity statement.The IBANis the international identifier for a bank account. These elements are not, by themselves, enough to empty a bank account. But when combined with other personal information, they can make certain fraud attempts and impersonation scams much more credible.
Source:Ministry of the Economy, FICOBA statement of February 18, 2026:
https://presse.economie.gouv.fr/?p=171314
Then, on August 13, 2026, Bercy issued another official communication. This time, a malicious actor had obtained unauthorized access to the DGFiP information system following identity theft. Initial investigations confirmed that the access had enabled data concerning individuals and professionals to be viewed and extracted.
An “information system”does not mean just a computer or a server. It is the whole made up of software, databases, user accounts, networks, procedures and people that enable an organization to process its information. Anda cyberattack does not always mean that a hacker has technically “broken” a server. An attacker may steal credentials, deceive a person, hijack a session or impersonate an authorized user. This is among the situations covered by digital identity theft.
Source:Ministry of the Economy, DGFiP statement of August 13, 2026:
https://presse.economie.gouv.fr/?p=182374
At the time this article is being written, the DGFiP says it is still seeking to determine precisely what data were compromised and how many users are affected. Identified individuals must be informed separately. The DGFiP announced notification to CNIL and the filing of a complaint.
It would therefore be false to write today that all tax data concerning every French citizen are out in the wild.We do not know that. But it would be equally false to minimize what is officially acknowledged:data were extracted, and this is not the first time in 2026.
Source:Ministry of the Economy, DGFiP statement of August 13, 2026:
https://presse.economie.gouv.fr/?p=182374
WOULD NIS2 HAVE PREVENTED THE DGFiP COMPROMISE?
No one can seriously claim that.Even a very well-protected system can be attacked.NIS2 is not a magic shield.A law can impose rules, controls and obligations, but it cannot guarantee that no attack will ever succeed.
But NIS2 imposes precisely a cybersecurity logic in which the server is no longer the only thing protected. Identities, access rights, the supply chain, crisis procedures, business continuity, training, detection mechanisms, authentication and the real effectiveness of security measures must also be protected. Senior management must oversee these arrangements.
Source:EUR-Lex, NIS2 Directive, notably Articles 20 and 21:
https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02022L2555-20221227
WHAT COMPARABLE MEASURES WERE ALREADY ACTUALLY APPLIED AT THE DGFIP? AND, ABOVE ALL, WHICH MEASURES WERE NOT?
THE ABSENCE OF NIS2 IS NOT AN EXCUSE. BUT ITS DELAY REMAINS A PROBLEM.
The DGFiP did not need a new European law to understand that an IT account with elevated privileges had to be strongly protected. The State did not need to wait until 2026 to restrict access rights, monitor abnormal behaviour or strengthen authentication procedures. ANSSI itself was encouraging future regulated entities to anticipate NIS2 before it entered into force nationally.
A “privileged account”is an IT account with greater rights than an ordinary account. It may be able to consult more files, modify settings or administer certain parts of a system.The more power an account has, the more serious its compromise can be.That is why such accounts should normally be especially protected, monitored and limited to what is strictly necessary.
Source:ANSSI, NIS2 and ReCyF:
But transposition adds something else. It turns principles and good practices into structured legal obligations and changes the scope of the system:
it expands supervisory mechanisms
it strengthens inspection powers
it organizes incident notifications
it creates a harmonized national framework
it strengthens the responsibility of senior management
it considerably expands the number of actors subject to regulation
The National Assembly report estimates that entry into force of the NIS2 title would multiply the number of regulated entities in France by around thirty, fromaround 500 to 15,000.Nearly twenty-two months of delayon a change of this scale are therefore not neutral.
Source:National Assembly, Report No. 1779:
https://www.assemblee-nationale.fr/dyn/docs/RAPPANR5L17B1779-tI.raw
At this stage, the entire dossier can be summarized in plain language. Europe asked States to strengthen their cybersecurity through law. France began the work but did not complete transposition on time. An article added to the French legislation to protect encryption triggered a documented conflict with intelligence concerns.We still do not know exactly how much this conflict contributed to the overall delay.But while that question remains unresolved, cyberattacks and compromises continue.
A CASE STUDY FOR OTHER COUNTRIES: WHAT NOT TO LET HAPPEN
This case should also be studied beyond our borders as an example of what must not be allowed to happen. When a country knows the threat, has a European framework, has a national cybersecurity agency, has already prepared its frameworks, and nevertheless sees a major institutional dispute emerge which a directly involved parliamentarian says is contributing to blockage of the whole package, political accountability requires establishing exactly what happened.
The problem must never remain confined to the offices where services are in dispute. When several services pursue legitimate but incompatible objectives and no political authority manages to arbitrate quickly enough, the consequences can flow down to companies, administrations and ultimately citizens.
If hearings confirmedthat the conflict over encryption contributed to immobilizing the entire reform for months,that would be precisely the kind of institutional failure from which other European States should learn.A conflict between encryption security, intelligence needs, the parliamentary timetable and Government responsibility must never obscure the main objective: effectively protecting systems and the population.
AND THE PARADOX BECOMES STARK
When the whole timeline is brought together, it becomes difficult to look at the picture without asking questions:
a European directive adopted as early as 2022
a deadline set for October 2024
a French bill tabled in October 2024
a text adopted by the Senate
a text adopted unanimously by the National Assembly’s special committee
ANSSI having already produced its framework
the European Commission deciding to take France to the EU Court over NIS2
another European action already brought concerning the CER Directive
the Cour des comptes stating that State cyber governance still needs to be strengthened
a documented conflict over encryption
the Parliamentary Intelligence Delegation considering Article 16 bis a major risk for intelligence policy
the author of that article claiming that the Government is blocking the bill
FICOBA compromised earlier in the year
the DGFiP now acknowledging a new extraction of data
Source:European Commission, July 2026:
https://ec.europa.eu/commission/presscorner/detail/en/ip\_26\_1499
From that point on,asking for explanations is not conspiracy thinking. It is precisely what democratic oversight should produce.
AN OFFICIAL TIMELINE AND HEARINGS ARE NOW REQUIRED
A parliamentary “hearing”means summoning officials, experts or institutional representatives before a committee so that they answer parliamentarians’ questions publicly. In this dossier, documented answers are now required on very specific points:
why the examination announced for July 2026 ultimately did not take place
what exact role Article 16 bis played in this delay
what compromise proposals, if any, circulated between the Government, the DGSI, ANSSI, the Ministry of the Interior and parliamentarians
whether the entire bill was genuinely delayed because of a single provision or whether other blockages existed
which measures from the future NIS2 framework were already applied at the DGFiP at the time of the two 2026 incidents
which measures were not
Because these are now questions of political and administrative accountability.
AND NO, TAX DATA “OUT IN THE WILD” ARE NOT TRIVIAL
Many citizens may still think: “All right, my data may have leaked. So what? I have nothing to hide.” That is a fundamental mistake. A data leak does not merely create an abstract file stored somewhere. It can give a fraudster the elements needed to make an attack far more convincing.
“Phishing”, means impersonating an administration, a bank, a company or a trusted person in order to push a victim into clicking a link, revealing a password, sending information or approving a transaction. The more accurate information the fraudster already has about the victim, the more authentic the scenario can appear.
Concrete risks notably include:
far more convincing phishing messages because they contain real information about the victim
scams impersonating the DGFiP or
in order to obtain bank details, passwords or other sensitive information
attempts at identity theft and the fraudulent opening of accounts or services in a victim’s name
fake bank-adviser scams in which the fraudster already knows enough information to inspire trust
cross-referencing with other leaks to build an increasingly detailed profile of the same person
far more personalized tax or banking fraud attempts
Source:CNIL, advice after a data leak:
https://www.cnil.fr/fr/conseils-fuite-vol-donnees
Source:
, phishing and DGFiP impersonation:
https://www.cybermalveillance.gouv.fr/tous-nos-contenus/actualites/smishing-hameconnage-sms
Source:CNIL, data leaks and IBANs:
Source:
, fake bank-adviser fraud:
Source:Ministry of the Economy, FICOBA statement:
https://presse.economie.gouv.fr/?p=171314
So no,an extraction of tax data is not merely a computer filefloating around the Internet. It can become raw material for building a personalized tax scam, stealing an identity, making a fake bank adviser more credible, targeting a taxpayer while already knowing their address or some financial information, trying to obtain even more sensitive information, and cross-referencing those data with information from other leaks.
THE POLITICAL CONCLUSION IS BECOMING DIFFICULT TO AVOID
We knew the cyber threat existed, and there were many warnings:
we knew cyberattacks existed
we knew digital identity was a target
we knew administrations held some of the country’s most sensitive data
Europe had set a deadline
ANSSI had prepared the measures
the Cour des comptes had warned
parliamentarians had worked on the legislation
in August 2026, NIS2 is still not fully transposed while the DGFiP acknowledges a new extraction of data
Whether or not they played a direct role in the August 2026 incident, these failures, delays and unresolved trade-offs have one certain consequence:they delay the full implementation of a cybersecurity frameworkthat Europe considered necessary as early as 2022 and legally required from October 2024. Meanwhile, incidents continue.
And when public-sector cybersecurity fails, it is not only abstract institutions that are exposed.It is citizens’ data, accounts, identities and concrete security.When services undermine one another at the top, political responsibility consists precisely in preventing the public from paying the price for a trade-off that never arrives.
In plain terms,the serious allegation is not that “NIS2 would have prevented the hack”. We do not know that. It is that a European framework considered necessary was supposed to have been fully transposed since October 2024, that a significant institutional conflict exists around a provision added to the French legislation, that the legislative process is still unfinished and that, meanwhile, public-sector systems continue in fact to be compromised.
For citizens, this institutional debate is therefore not abstract.When protection fails, their data, identity, accounts and sometimes their money can end up exposed.
Something more is now required than: “We will learn lessons from the incident.”
Four questionsmust now be answered clearly:
WHO BLOCKED WHAT?
WHY?
SINCE WHEN?
AND WITH WHAT CONSEQUENCES FOR FRENCH CITIZENS’ DATA?

