France’s finance ministry has confirmed an illegitimate access to the tax administration’s information system, carried out in late June after an official’s identity was stolen. The French tax data extracted covers 678,437 people, split between 392,867 individuals and 285,570 businesses. The file is circulating on dark web marketplaces for a few thousand euros. For French crypto holders, the exposure runs well past ordinary phishing risk.
Key Takeaways
- 678,437 taxpayers are affected, including 27,000 declaring at least €100,000 in income.
- The access came from an official’s stolen credentials, not from a flaw in the public tax portal.
- France recorded 30 violent attacks on crypto holders in the first half of the year.
Identity Theft, Not a Flaw in the Tax Portal
The entry point was not technical in the usual sense. The attacker compromised an official’s professional credentials and internal network access, which opened the information system without exploiting any software vulnerability and without encrypting anything.
The administration detected and cut that access in late June during its own checks. The statement released by the finance ministry concedes that consultation and extraction of data covering both individuals and businesses did take place before the shutdown. The privacy regulator was notified, a criminal complaint was filed, and affected users are to be informed individually.
The contents explain the alarm. This French tax data holds names, dates of birth, home addresses, phone numbers, email addresses and tax identifiers. It also carries declared income and tax rates, which amounts to a wealth map bundled with a home address. France carries real weight in this sector, as Capital B’s purchase of 192 BTC underlined earlier this year.
Income stratification makes some records far more sought after than others. The file counts 27,000 people declaring at least €100,000, 386 above one million and eight beyond ten million. The data is offered for a few thousand euros, a trivial price against what it enables.
That pricing tells its own story about the resale market. A buyer paying a few thousand euros for a list of several hundred high-income households is not planning a mass campaign. They are selecting a handful of targets and building a case file on each one.
Why This File Points Straight at Crypto Holders
France has required declaration of accounts held on foreign exchange platforms for several years, alongside capital gains tax on disposals. French tax data can therefore identify a digital asset holder, which no ordinary commercial database does.
The file does not explicitly flag crypto owners, but it hands over an updated target list cross-referenced with income and home address. The sector had absorbed a comparable warning a week earlier, when 13,689 Trezor customer addresses leaked through a shipping provider.
The physical threat is anything but theoretical in this country. Chainalysis data on violent attacks targeting crypto holders counts 30 publicly known cases in France in the first half of 2026, with more than $30M taken. The pace runs ahead of 2025, itself a record year at $58M.
An internal precedent weighs on the file as well. A French tax employee was arrested in June 2025, suspected of selling confidential information on crypto investors to criminal networks. Researcher Jameson Lopp summed the situation up by noting that the leak hits the country worst affected by these attacks.
Also on Cryptonomic:
- MSCI Moves to Drop Strategy From Stock Indexes
- Trezor Breach Exposes 13,689 Buyers Through Its Shipper
- SEC Pulls Its Reg Crypto Meeting With No New Date
What an Affected Taxpayer Can Actually Do
One technical detail caps a risk without removing the others. The stolen data does not open the secure account on the public tax portal. It does make identity theft easier with third parties who settle for a bundle of personal details before opening a file.
The immediate operational rule fits in one sentence: the tax administration never asks for bank details or credentials by message. An email quoting the correct income and the correct address is still a fraudulent email, and its accuracy is exactly what makes it dangerous. That caution extends to financial services themselves, in a shifting regulatory landscape where Binance France missed its MiCA licensing deadline.
For exposed holdings, the answer is as much physical hygiene as digital. That means not publishing positions, keeping the delivery address separate from the actual home, and spreading assets across several signing devices rather than one.
None of that undoes an address already in circulation. What it does is break the chain between a name found in a file and a quantity of assets an attacker can estimate, which is the link that turns a database entry into a target worth the trip.
Further out, the question turns political. A state that mandates tax transparency on digital assets takes on a matching duty of protection, and France is already tightening its grip on the sector elsewhere, as shown by the Polymarket block on illegal gambling grounds.
Investigators still have to establish the exact scope of what left the system. Until that final count lands, a stolen file can never be revoked, and its value to an attacker is measured in years.
Follow the story on Cryptonomic.


