Breaking: Russian Cyber Campaign Hits French Tax Authority — France Summons Ambassador
Russian Cyber Campaign Hits French Tax Authority — France Summons Ambassador
France's Ministry of Economy has confirmed a major cyberattack against the French tax platform (impots.gouv.fr), with attackers accessing highly sensitive personal and financial data belonging to French citizens. Digital Affairs Minister Jean-Noël Barrot announced that France will summon the Russian ambassador to Paris, citing a "large-scale cyber campaign" attributed to Russian state actors targeting multiple European countries including France.
The breach was first claimed in cybercrime forums before the Ministry confirmed it less than 24 hours later. The attack targeted critical government financial infrastructure — the tax authority's systems — exposing personal and financial data at a scale still under investigation. The severity rating assigned to the incident is the highest possible: an attack threatening the organisation's existence, according to external TPRM assessments.
The diplomatic escalation follows Finland's July 13 summoning of Russia's ambassador over a separate cyber campaign, and Germany's similar diplomatic action. Three European nations have now formally accused Russia of state-sponsored cyber operations against their government systems. France's response is notable for the speed and directness of the attribution, and for the target: a core revenue-collection platform handling the financial data of 67 million citizens.
The incident adds a new dimension to the Russian cyber threat picture. Previous European campaigns focused on espionage and disruption. This attack on a financial infrastructure platform — with confirmed data exfiltration of personal and financial records — represents a shift toward operations that directly compromise citizen trust in government digital services.
So What / Action
For CISOs with European operations or EU data processing: this is a concrete escalation from espionage to infrastructure compromise with data exfiltration. If your organisation interfaces with French government systems (tax filing, GFI integration, DSN reporting), verify those connection points for compromise indicators. For any organisation in an EU member state: treat this as confirmation that Russian state actors are actively targeting government financial infrastructure, not just conducting reconnaissance. Review threat models for any system that handles citizen financial data, and ensure your incident response plan accounts for the diplomatic dimension — breaches involving state actors now carry mandatory reporting implications under NIS2. If your government interfaces were built on trust (API keys, shared certificates, SAML federations with .gouv.fr domains), validate that trust now.

