A week after the initial breach, the Liechtenstein State Administration took four additional government financial systems offline—including the VAT portal (eMWST-Portal), the Lides judicial system, the central account register, and the Intax tax information portal. This cascading response suggests the breach may have been broader than initially reported or triggered a wider security freeze .
A malicious actor gained unauthorized access to the information system of France's Direction Générale des Finances Publiques (DGFiP) through identity impersonation—using a stolen identity to access an internal VPN and a taxpayer search tool . The intrusion occurred in late June 2026, but the breach was only confirmed and publicly disclosed by France's Economy Ministry on August 13, 2026
.
The attacker claims to have exfiltrated 678,438 tax data lines, affecting approximately 393,000 individuals and 286,000 professionals/businesses . Exposed fields include names, addresses, dates of birth, family situation, tax identification numbers, declared income, and tax rates
. The stolen file is reportedly being offered for sale online for several thousand euros
.
The French government confirmed the "illegitimate access" and that data was consulted and extracted. Preliminary investigations confirmed the access was cut off in late June when detected, but the data had already been copied . This is France's second tax-data breach of 2026
.
Both countries had consolidated sensitive financial data into centralized government registers—beneficial ownership in Liechtenstein, taxpayer records in France. This makes them extremely attractive targets: a single breach yields intelligence or ransom-grade data on thousands of entities.
The French attack succeeded not through complex malware but through identity theft used to gain VPN access—a social-engineering approach that traditional perimeter defenses often miss . This suggests attackers are moving toward exploiting legitimate access pathways rather than breaking through technical barriers.
The French intrusion happened in late June but was only disclosed in mid-August—a gap of over six weeks. The Liechtenstein attack was detected within days, but its cascading impact (four related systems taken down a week later) suggests that initial containment did not fully stop the compromise .
Liechtenstein's register is a legal transparency tool meant to combat money laundering. However, its very purpose—linking real people to corporate structures—means a data leak directly exposes individuals who may have legitimate privacy expectations . The same tension applies to France's tax database, which aggregates citizens' full financial profiles.
Liechtenstein is a wealthy, highly digitized financial center, yet its core transparency register was breached with apparent ease. The attack suggests that smaller jurisdictions may lack the continuous threat-monitoring and rapid-response capacity of larger nations—and that financial secrecy hubs are prime targets for state and criminal actors alike.