On 14 August 2026, France’s Direction générale des Finances publiques (DGFiP), the French tax administration, announced that a malicious actor claimed a theft of data after illicit access to its information system during June, July and August. The public notice is precise on one point that matters to every foreign-owned French company: the impots.gouv.fr website and the professional and individual taxpayer spaces were not compromised. The incident is therefore not, on the information currently published by the administration, a mass compromise of company tax logins.
That distinction does not make the event harmless. A foreign founder may receive a convincing message referring to the company’s SIREN, address, tax office, previous correspondence or a French filing. SIREN means the national company identification number. Those details can make a fraudulent email or telephone call look authentic even when the company’s password was not stolen. The immediate risk is social engineering: the attacker uses legitimate-looking information to obtain a new secret, redirect a payment or persuade an employee, accountant or director to act outside the normal process.
This article separates the official DGFiP incident from a compromise of the company’s own account, then sets out a response that can be followed by a director living outside France. It covers the first verification, the evidence to preserve, the contact with the Service des impôts des entreprises (SIE), the business tax office, the bank and the French authorities, and the steps needed to keep VAT, corporate income tax and other deadlines under control. The broader company-law context is available on our French company legal guidance page.
I. What did the DGFiP data breach expose, and what must a foreign-owned French company verify first?
A. Why are the professional tax space and tax payments not reported as compromised?
The starting point is the wording of the administration’s own notice, not an alarming message received by email. The DGFiP incident notice records that, on 12 and 13 August 2026, a malicious actor claimed a theft of data after unauthorised access to the administration’s information system in the preceding months. It also states that the impots.gouv.fr website and the individual and professional taxpayer spaces were not compromised. The Bercy information page and professional FAQ describe an access route involving stolen public-agent credentials and warn that exposed information may be used for phishing, fraudulent calls and identity theft.
The published information concerns data held in an administration system, not a direct reading of every company’s secure tax account. The professional FAQ identifies categories that may have been consulted, including a company’s SIREN, name, address and certain message metadata. SIREN identifies the legal entity; SIRET identifies a particular establishment. The data may be enough to identify a real French company and its relationship with a foreign parent, but it does not by itself give an attacker the password for the company’s professional space, the ability to sign in as an authorised user or the authority to change a bank mandate.
The same FAQ says that the professional taxpayer spaces were not compromised, that professional-space passwords were not stolen according to the information then available, and that the incident was not an attack on the infrastructure used for electronic invoicing or on approved electronic-invoicing platforms. A company should therefore avoid two opposite errors. It should not reset every tax process blindly and create contradictory filings. It should also not assume that a message mentioning a genuine SIREN or tax document is authentic.
For a foreign-owned company, the first independent check should be made by typing the official address into a browser or using a previously verified bookmark. Do not use the button, telephone number or QR code in the message that triggered the concern. Sign in through the company’s known route and check four items: the legal entity displayed, the last successful access, the list of users or delegated advisers, and the recent declarations, payments, refunds or secure messages. A director abroad can ask the French accountant or registered-office provider to report what was received, but the report should be compared with the account itself and not treated as proof of a compromise.
Next, compare the message with the official incident. A genuine DGFiP communication can explain a data-security event without asking a company to disclose its password, full bank credentials, a one-time authentication code or a payment to a new account. The administration’s current guidance recommends accessing the professional space directly and treating unexpected requests for confidential information as suspicious. Preserve the message before deleting it. Its sender address, full headers, links, attachments, time and language may identify whether it is a real notification, a spoofed message or a later phishing attempt using information associated with the breach.
Check the company’s own systems separately. The DGFiP announcement does not establish that the company email account, accounting platform, bank portal, payroll system or electronic data interchange connection was attacked. EDI means electronic data interchange, the route by which an accountant or software provider can transmit tax data. Review sign-in alerts, forwarding rules, newly created users, adviser permissions, payment templates and changes to the bank details used for tax payments. If a company shares one mailbox between a foreign parent, a French director and an accountant, identify which person received the suspicious message and whether any link was opened.
Tax compliance continues during this review. Corporate income tax, commonly called IS for impôt sur les sociétés, VAT, payroll-related obligations and CFE, the cotisation foncière des entreprises or local business-property tax, do not stop because an administration has announced an information-system incident. If a return or payment is due, use the established channel, verify the amount against the accounting file, and keep the electronic receipt. If the company cannot access the space, record the failure and contact the SIE through an independently verified channel. A security incident is not, on its own, a statutory extension of a filing deadline.
The data-protection analysis also starts with a distinction. The DGFiP, as the controller of its relevant public-administration processing, assesses its own notification duties. Article 58 of Law No. 78-17 of 6 January 1978, the French data-protection statute, states that the controller “notifie à la Commission nationale de l’informatique et des libertés” and communicates a personal-data breach to the affected person under Articles 33 and 34 of the General Data Protection Regulation. The official wording is available on Légifrance, Article 58 of Law No. 78-17. That rule concerns the controller responsible for the relevant breach; it does not mean that every company mentioned in the affected data has automatically suffered a separate breach.
A company must still act if the information is later used against it. If an employee or director entered credentials into a false page, the company may have suffered its own security incident even though the DGFiP professional space was not attacked. If a malicious person entered the company’s account, read a tax message, altered a declaration or extracted a file, the legal qualification changes again. The evidence should show which system was affected, which data was accessed, whether an action was taken and when the company recovered control.
The criminal framework illustrates why the first technical classification matters. Article 323-1 of the French Penal Code covers fraudulent access to or remaining in an automated data-processing system, called a STAD from the French phrase système de traitement automatisé de données. Its opening words are “Le fait d’accéder ou de se maintenir, frauduleusement, dans tout ou partie d’un système de traitement automatisé de données”. Article 323-3, in the official Légifrance text, addresses fraudulent introduction, extraction, holding, reproduction, transmission, deletion or modification of data. It includes the phrase “supprimer ou de modifier frauduleusement les données qu’il contient”. These provisions are not labels to apply without evidence; they explain why access logs and preserved messages can become important legal evidence.
B. How should the foreign director classify phishing, account misuse and payment fraud?
A practical response uses three scenarios. The first is an official notice only: the company receives information about the DGFiP incident, but no one has clicked a suspicious link, no credential has been disclosed and the account shows no irregularity. The company should verify the notice through direct access, inform the people who handle its French tax obligations, review permissions and continue its calendar. A forced password reset or a new bank mandate is not a substitute for verification. The professional FAQ indicates that a password change was not required solely because of the DGFiP incident, although the company can change it through the normal direct-login route as a preventive measure.
The second scenario is a phishing or impersonation attempt. A phishing message may ask the recipient to “confirm” the SIREN, revalidate the account, upload a Kbis or pay a tax amount to a new IBAN. Kbis means the official extract issued by the commercial court registry; the greffe is that registry. IBAN means the international bank-account number. None of these familiar data points proves that the sender is genuine. The company should not reply, click, open an unexpected attachment or call the number in the message. It should preserve the original evidence, warn the accountant and bank through known contact details, and check whether a password, code or document was disclosed.
The third scenario is actual misuse: an unauthorised login, a changed user, a fraudulent tax payment, a false refund request, a modified bank detail or a company email account that has been taken over. The director should treat this as an incident affecting the company, even if the public DGFiP breach itself did not compromise professional spaces. Revoke suspicious sessions and delegations, change credentials from a clean device, secure the email account, ask the bank to place appropriate controls on the affected account, and contact the SIE through the secure professional messaging route or another independently verified channel. Do not erase the attacker’s messages or rebuild the system before collecting evidence.
Authority is a recurring issue for a foreign-owned company. The French company may be controlled by a foreign parent, managed by a non-resident president or represented daily by a French accountant. The director should identify who is authorised to contact the tax administration, who can instruct the bank, who can preserve the company’s systems and who can file a complaint. A power of attorney or accountant’s mandate does not automatically authorise every action. It should be checked for scope, duration and revocation. Keep the current Kbis, the articles of association, the parent’s resolution and the mandate together so that a French administration or investigator can understand the chain of authority.
French criminal law distinguishes access from the identity or correspondence fraud that may accompany it. Article 226-4-1 of the Penal Code provides that identity impersonation or the use of identifying data to disturb another person or damage their reputation is punishable, including when committed online. The text begins: “Le fait d’usurper l’identité d’un tiers”. A fraudulent caller who presents himself as the SIE, an accountant or a director may therefore create evidence relevant to more than one offence. The precise qualification belongs to investigators and the prosecutor; the company’s role is to preserve the facts without embellishment.
The company’s email investigation must remain within its authority. An administrator may review security logs and business messages when the company’s policies and the applicable law permit it, but a director should not instruct an employee to search a private mailbox casually or copy unrelated personal correspondence. Article 226-15 of the Penal Code covers bad-faith interception, diversion, use or disclosure of electronic correspondence. It is also relevant to the limits of an administrator’s role. In the Cour de cassation’s criminal judgment of 10 May 2017, no. 16-81.822, the court upheld liability where a person used a keylogger to obtain and read another person’s messages; the judgment states that the exercise of a defence in the underlying civil case was not a justification for the offence. The business lesson is narrow but important: a technical ability to access a mailbox is not the same as authority to use all of its content.
French case law also shows why a former adviser, employee or service provider should be removed promptly. In the Cour de cassation’s criminal judgment of 12 July 2016, no. 16-82.455, concerning a protected website, the court accepted that known or weak credentials do not create permission where there is “aucune autorisation de pénétrer sur le système de traitement automatisé de données”. A company should therefore revoke an old accountant’s access even if the password was once supplied legitimately and even if the user still knows it.
The same principle is visible in the Cour de cassation’s criminal judgment of 5 April 2022, no. 21-83.590. A dismissed service provider created an account under another name, reactivated a disabled account and extracted data. The court criticised the failure to draw the legal consequences of conduct that was “dissimulant ainsi sciemment son action aux autres utilisateurs du STAD”. A foreign parent should not interpret a former director’s or adviser’s continued technical access as continuing corporate permission. Revoke accounts, document the revocation and keep the access logs.
Modification and deletion need their own review. The Cour de cassation’s criminal judgment of 8 June 2021, no. 20-85.853, published in the Bulletin, explains that Article 323-3 can apply to a person who had access and modification rights when the action was knowingly hidden from another user. The court states that “des modifications ou suppressions de données sont nécessairement frauduleuses dès lors qu’elles ont été sciemment dissimulées à au moins un autre utilisateur”. If a tax return, bank template, accounting file or secure message was changed, preserve the before-and-after state and identify who could see the change.
Those cases do not prove that a phishing email has caused a criminal offence. They establish why a company should avoid destroying evidence, why a shared administrator account is risky and why permission should be described rather than assumed. The foreign director should prepare a neutral chronology: message received, person contacted, link opened or not, credential entered or not, account reviewed, access revoked, bank informed and official response obtained. That chronology helps counsel, the bank, the tax administration and the investigator work from the same facts.
II. What evidence and legal response should a foreign director organise after the incident?
A. What should be secured in the first 24 hours?
The first 24 hours should produce a controlled evidence pack, not a collection of forwarded messages. Create an incident folder with a clear date and keep an untouched copy of each original file. Record the time zone used by the company, because a foreign parent, a French accountant and a cloud service may display different times. Save the full email, including headers; the sender and reply-to addresses; the complete link destination; attachments; screenshots; call records; bank alerts; browser history relevant to the event; and the exact wording of any person who asked for a payment, code or document.
Do not open the suspicious link again merely to test it. If technical staff must inspect it, use a controlled process and preserve the original message first. Do not forward a malicious attachment to the whole team. Place a short internal hold on the relevant mailbox and account records so that automatic deletion does not remove evidence. Ask the IT provider to preserve authentication logs, mailbox rules, endpoint alerts, VPN records and administrator activity for the relevant period. The request should state that the records may be needed for a legal investigation and should identify the French company, its SIREN and the systems in scope.
At the tax-administration level, use the company’s known professional space to check recent activity and send a message through the secure route where possible. If access is blocked, contact the SIE, the Service des impôts des entreprises, using contact details independently retrieved from impots.gouv.fr or an existing tax notice. State the company’s legal name, SIREN, SIRET, registered office, the suspected date, the action that may have occurred and the evidence already preserved. Ask for a written confirmation of the status of the relevant declaration, payment, refund request or message. Do not ask the tax office to accept an unverified bank change by email.
The bank response should be parallel, not delayed until the tax administration replies. Use the bank’s known fraud channel. Explain whether the concern is a proposed payment, an executed payment, a changed beneficiary, a direct-debit mandate or an account takeover. If money has left the account, identify the value date, amount, beneficiary, reference and authorisation method. Ask the bank what must be blocked, what evidence it requires and how it will protect pending payments. Preserve the bank’s case number and the name of the person or department contacted.
French payment law makes speed important. Article L. 133-18 of the Monetary and Financial Code states that, for an unauthorised payment reported under the applicable conditions, the payment service provider refunds the payer immediately and no later than the end of the first business day, subject to the statutory fraud exception. The provision uses the phrase “immédiatement après avoir pris connaissance de l’opération”. Article L. 133-24 requires the user to report an unauthorised or incorrectly executed payment without delay and, in principle, no later than 13 months after the debit, while allowing a different period by agreement for a professional user. A company should not wait for its internal investigation to become perfect before giving the bank a formal alert.
Evidence of the company’s loss also matters. Article 1240 of the Civil Code states: “Tout fait quelconque de l’homme, qui cause à autrui un dommage, oblige celui par la faute duquel il est arrivé à le réparer.” That general civil-liability rule does not guarantee recovery against an unknown attacker or a bank, and it does not remove contractual limits. It explains why the company should quantify its direct loss, emergency costs, delayed filing, payment dispute, investigation fees and any contractual impact rather than recording only a vague “cyber incident”.
Make a complaint when there is an actual attempted or completed offence, not only because the word “breach” appeared in a news article. The official Service-Public guidance on phishing and vishing confirms that a victim can report a suspicious act, preserve evidence and lodge a complaint even when the attacker’s identity is unknown. The company can report the digital incident through the recommended French channels, and it can use THÉSÉE, the online route for certain digital-fraud complaints, where the facts fit that service. It can also attend a police station or gendarmerie and report to the competent prosecutor.
Article 15-3 of the Code of Criminal Procedure requires police officers and judicial police agents to receive complaints from victims of criminal offences, including when the complaint is made at a service that is not territorially competent. The provision says that officers “sont tenus de recevoir les plaintes déposées par les victimes”. The foreign director does not need to wait until the attacker is identified or travel to the company’s registered office before organising the file. A representative can prepare the documents, but the company should confirm who has authority to act for the legal person and keep the complaint receipt and case reference.
The first-day evidence pack should contain at least:
- the DGFiP notice and the official page used to verify it;
- the suspicious email, full headers, attachments, links and call details;
- the company’s Kbis, articles, SIREN, SIRET and current registered-office evidence;
- the tax-account users, adviser mandates, recent secure messages, declarations and payment receipts;
- bank statements, payment references, beneficiary details, direct-debit mandates and the bank’s fraud case number;
- access logs, mailbox rules, password-reset events and system-provider preservation confirmations;
- a chronology with the foreign parent, French director, accountant and any employee who handled the message; and
- translations or a short English explanation of each French document, while keeping the original French version unchanged.
Do not place passwords, authentication codes or live bank credentials in the evidence folder. Store sensitive material in a restricted location and give counsel or the investigator controlled copies. The evidence file should show what happened without creating a second security incident.
B. How should the company protect tax deadlines, personal data and the foreign management chain?
After the initial containment, the company should return to its ordinary French tax calendar and test each obligation against the records. The professional account is used for activities such as VAT declarations and payments, corporate-income-tax payments, certain local taxes, requests for VAT-credit refunds and tax certificates. The official Service-Public description of the professional EFI account explains these functions. EFI means échange de formulaires informatisé, the electronic-forms route used by the business or an authorised user. EDI is a different transmission route, usually operated by an accountant or software provider. A company must identify which route was used for the disputed action before it can say that a return was or was not filed.
Reconcile the tax space with the accounting ledger, not with a screenshot alone. For each relevant return, keep the submitted form, acknowledgement, payment instruction, bank debit and underlying calculation. For VAT, check the taxable transactions, reverse-charge treatment and VAT number used. For IS, check the instalment or balance, the accounting period and the tax computation. For CFE, check the establishment and the local-tax notice. If the company uses a French accountant, request a written list of transmissions and ask the accountant to identify any message that did not originate from the normal workflow.
Do not assume that an incident creates a tax amnesty or an automatic pause. If a return cannot be filed because a legitimate technical problem prevents access, preserve the error, contact the SIE and ask what alternative filing or payment route applies. If a payment is disputed, notify the bank without delay and separately warn the tax administration so that an unpaid liability is not mistaken for a deliberate refusal. A company that waits silently may later have to explain a late return, while a company that files a false duplicate return may create a different problem.
Keep notices and response dates in the evidence file. If a tax audit, request for information or proposed adjustment arrives during the incident, record the date and the channel. Article L. 57 of the Book of Tax Procedures provides that an adjustment notification must be reasoned so that the taxpayer can make observations or accept it. The current procedural position must be checked for the specific notice and tax, but the practical point is stable: preserve the notice, the date of receipt, the supporting documents and the response deadline. A cyber incident does not justify ignoring a tax letter.
The company should then determine whether it has suffered a personal-data breach of its own. The DGFiP incident may involve company identifiers and contact information, but that is different from an unauthorised disclosure by the company of employee, customer, supplier or director data. If a phishing event exposed a mailbox containing personal data, or if an attacker accessed the company’s accounting platform, the company should assess confidentiality, integrity and availability, identify the categories of people affected, estimate the risk and document the decision. Article 58 of Law No. 78-17 and the GDPR rules on breach notification should be considered with the company’s data-protection adviser. The CNIL, the Commission nationale de l’informatique et des libertés, is France’s data-protection authority; its incident page on the tax-system breach confirms that it was notified of the public incident and gives general vigilance recommendations.
The company should not file a second notification merely to repeat the DGFiP’s facts. It should make a separate assessment if its own systems or data were affected. Write down why the event was classified as no breach, a low-risk incident, a notifiable breach or an event still under investigation. Identify the decision-maker, the evidence reviewed and the next review date. If the company has customers or employees in several countries, coordinate the French analysis with the foreign parent’s data-protection process without replacing the French assessment with a foreign template.
Governance should be repaired at the same time. The foreign parent should receive a concise incident report in English, but the company’s French legal file should retain the original documents and French messages. The report should name the legal entity, its SIREN, the people who had authority, the systems reviewed, the actions taken and the unresolved questions. If the company has a president, a general manager, a finance director and an accountant, record which person can approve a tax payment, change a bank mandate, submit a return and communicate with the SIE. A person who only prepares a return should not automatically be able to approve its payment.
Review every delegated account. Remove former employees, former accountants, consultants and parent-company users who no longer need access. Replace shared passwords with named accounts where the service permits it. Activate multi-factor authentication where available. Store recovery details in a corporate-controlled location rather than in the personal mailbox of a founder. Review the company’s email forwarding rules, domain-security settings, device updates and backup process. If the company uses EDI, ask the software provider for its transmission logs and its process for revoking the accountant’s certificate or authorisation. If it uses an electronic-invoicing platform, confirm independently that the platform and its bank details have not been changed.
Contractual and civil claims require a separate mapping. If a service provider failed to revoke access, mishandled a document or followed a fraudulent payment instruction, collect the contract, security clauses, authority matrix, logs and loss calculation. Article 1240 is a starting point for non-contractual liability, but the parties’ contract, the provider’s professional duties, causation and any contributory conduct must be analysed. Do not accuse an accountant or bank in a public email before the evidence is complete. Send a preservation request and a factual notice that protects the company’s position while allowing the provider to investigate.
Where several people appear to have coordinated an attack, preserve evidence of the separate acts and communications. Article 323-4 of the Penal Code addresses participation in a group formed to prepare certain offences involving automated data-processing systems. It is not a conclusion that a coordinated phishing campaign satisfies that provision. It is a reason to retain sender domains, telephone numbers, payment beneficiaries, reused wording and links instead of treating each message as an isolated nuisance.
A foreign director should also plan the next contact with French counsel or the authorities. Prepare a two-page chronology and a document index before the call. State whether the company’s professional tax space was independently checked, whether any credential was entered, whether any payment was made, whether any personal data was exposed and whether a complaint or bank report has been filed. Ask targeted questions: should the company notify the CNIL about its own system, should a tax declaration be refiled, should a bank mandate be cancelled, should a provider be put on notice, and who should represent the company in France? This format makes the legal consultation faster and reduces the risk that an overseas management team acts on a partial translation.
Finally, keep a post-incident review date. Thirty days later, verify that all delegated users remain correct, that no suspicious forwarding rule has returned, that tax receipts reconcile to the ledger, that the bank has closed or updated its fraud case and that the complaint reference is recorded. Revisit the company’s internal policy for tax communications: no change of bank details by email alone, no payment after a telephone request without independent callback, no disclosure of one-time codes, and no upload of a Kbis or identity document to a link that has not been verified. These controls are particularly important when the director, the foreign parent and the French accountant work in different countries and languages.
Conclusion
The current DGFiP information does not report a compromise of the impots.gouv.fr website or professional taxpayer spaces. A foreign-owned French company should therefore distinguish the public incident from a separate phishing, account-takeover or payment event. The correct response is to verify through direct access, inspect users and recent activity, preserve the original evidence, notify the SIE and bank through known channels, protect every tax deadline and document whether the company’s own personal-data systems were affected.
If there was an unauthorised payment, speed matters under the payment rules. If there was an unauthorised access or concealed modification, the Penal Code and the cited Cour de cassation decisions make permission, logs and chronology central. The foreign director does not need to manage this alone from abroad: a properly documented mandate, an English incident summary, the original French records and a focused legal review can keep the company operational while its French and foreign stakeholders coordinate.
Need a quick opinion on your case
Telephone consultation within 48 hours with a lawyer from the firm.
We can help a foreign founder or company secure the evidence, coordinate with the French tax administration and assess the next legal step.
+33 6 46 60 58 22
Maître Reda Kohen — contact the firm