Tech
French Tax Authority Breach Exposes Sensitive Taxpayer Data
France’s Finance Ministry has confirmed that a cyberattack on the country’s tax authority resulted in the theft of personal and professional taxpayer data, potentially putting the information of hundreds of thousands of people at risk.
The ministry said Thursday that a “malicious actor” claimed to have broken into the Directorate General of Public Finances (DGFiP) in late June. An investigation confirmed that attackers had gained access to the agency’s systems and were able to consult and extract taxpayer information.
French officials are still trying to determine what exact information was taken and how many people were affected, with the precise scope of the breach still under investigation. The ministry said people whose information was compromised will be notified directly and informed about which data may have been exposed and what precautions they should take.
The number of potential victims could be substantial. The specialised cyberattack monitoring platform, FrenchBreaches, said that about 678,000 records were stolen, including roughly 393,000 individuals and 286,000 professionals.
Reuters noted that the French Finance Ministry has not confirmed those figures.
What taxpayer information was exposed?
The reported stolen information could give criminals plenty of material for targeted scams and identity theft.
According to reporting by Brussels Signal, the potentially exposed information includes names, addresses, dates of birth, reference tax income, withholding tax rates, family circumstances and some property-related information. The dataset also allegedly contained internal tax identifiers, information about dependents and records of previous interactions with the tax administration.
That combination is particularly concerning because tax records can provide attackers with a detailed profile of an individual or business. Such information could potentially be used to facilitate identity theft, targeted phishing campaigns or other forms of fraud.
FrenchBreaches also reported that the stolen information was being offered for sale for several thousand euros. Those details came from the alleged attackers and have not been independently confirmed by French authorities.
Attack reportedly went undetected
There are also unanswered questions about how the attackers managed to extract data without the data theft being detected.
Le Monde reported that the unauthorized access was identified and cut off at the end of June during a routine security check. However, the agency apparently did not detect that data had already been extracted at the time. The incident only became public after the alleged attacker claimed responsibility on a cybercrime forum and offered stolen data for sale.
The alleged attacker, operating under the name ZeroBytes, claimed to have accessed an internal DGFiP tool through a virtual private network using stolen professional credentials. The DGFiP has not confirmed the account of the attack.
The DGFiP has since strengthened its access controls, while the French Ministry said it will report the incident to France’s data protection regulator, the CNIL, and file a formal complaint. The investigation is being carried out with help from France’s national cybersecurity agency, ANSSI.
Must-read security coverage
Another cybersecurity challenge for France
The incident is the latest in a growing list of cyberattacks targeting French government institutions in recent months.
In February, the French Finance Ministry disclosed that an attacker had gained unauthorized access to information associated with approximately 1.2 million bank accounts in the country’s FICOBA registry by using stolen official credentials. Authorities said there was no known connection between that incident and the latest DGFiP breach.
Later in April, France’s National Agency for Secure Titles (ANTS), which handles documents such as identity cards, passports and driving licenses, disclosed a breach affecting potentially 11.7 million accounts. That incident prompted Prime Minister Sébastien Lecornu to announce a €200 million ($232 million) cybersecurity initiative funded through the France 2030 investment program.
Lecornu said France had been seeing roughly three data theft incidents per day since the beginning of 2026.
French authorities have not yet established the full scope of the DGFiP breach, meaning the reported figure of nearly 700,000 affected records remains unconfirmed.
Until investigators determine exactly what was stolen, taxpayers notified by the agency may need to treat convincing tax-related emails, calls and other requests with additional caution — particularly when they contain personal information that would normally make a message appear legitimate.
Other Security News: Microsoft is pushing Entra ID users toward passkeys as it moves away from SMS and voice-based authentication methods that are more vulnerable to phishing and interception.
>
Tech
‘Unprecedented’ number of Apple users received recent spyware alert, say investigators
An unprecedented number of Apple customers have reported receiving a recent threat notification alerting them to suspected spyware attacks targeting their devices, according to experts who investigate these types of incidents.
Several people publicly and privately reported receiving Apple’s spyware alerts over the weekend, after Apple sent out a new wave of notifications on Friday alerting customers in 110 countries that they had been targeted with powerful spyware.
From time to time, the technology giant sends these types of alerts in batches to customers that it believes have been either targeted or compromised with malware normally used by governments, which the company refers to as “mercenary spyware.” In the last few years, Apple says it has alerted people in more than 150 countries.
The latest batch appears to have been the largest yet, per one of the digital rights groups that Apple suggests victims of spyware reach out for help.
Mohammed Al-Maskati, the director of the Access Now team of investigators who review and investigate reports to the helpline, told TechCrunch that since Friday, they have received a record high number of people reaching out for help. This includes people who had already received threat notifications in the past.
Al-Maskati said the number is around 30% to 40% more than the nonprofit’s investigators usually receive after Apple sends out new notifications.
An unusually large number of people have also publicly reported receiving these notifications over the weekend as well, according to several social media posts.
Contact Us
Have you received a notification from Apple about being targeted with mercenary spyware? Or do you have information about spyware makers? We would love to hear from you. From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email.
One of them is a Ukraine Armed Forces soldier who said he is fighting the war against Russia. The soldier, who asked to remain anonymous to protect himself, said that he initially thought it was a scam, until he verified it with Apple.
“I was a bit surprised to be honest, I wouldn’t have thought I was important enough for them to target me like this. I am flattered though,” the soldier told TechCrunch.
The soldier also said that he is aware of other people in Ukraine’s military who have received the same notification. “They were a bit worried,” he said.
The Computer Emergency Response Team of Ukraine (CERT-UA) did not respond to TechCrunch’s request for comment, asking whether it was aware of other Ukrainians, particularly soldiers, receiving these notifications.
John Scott-Railton, a senior researcher at The Citizen Lab, a digital rights group that has investigated government spyware attacks for more than 15 years, told TechCrunch that the reports show that spyware attacks may be more prevalent than people realize.
“The scale and geographic diversity of public posts about receiving notifications are pretty unprecedented,” said Scott-Railton. “For every public notification like this, you can imagine there’s a huge notification iceberg that the public will never learn about. This is a clear indication that something bigger is going on.”
Both Al-Maskati and Scott-Railton said that the volume of people receiving the alerts could also be attributed to Apple’s new methods of alerting users.
Starting this year, Apple now notifies users on their iPhone lock screen, in their Settings app, via the email associated with their Apple account, and when users log in to their Apple Account on the web.
“Apple’s new notification method has helped raise awareness of the issue’s importance, making it harder for users to ignore,” Al-Maskati said.
Apple did not respond to TechCrunch’s request for comment.
If you’ve received one of these notifications, take it seriously. If you are not a journalist, dissident, or human rights defender, there are other organizations that can help you investigate.
If you haven’t already, as Apple and experts suggest, turn on Lockdown Mode, a special security feature designed to make it harder to hack iPhones, iPads, and Mac computers. Apple has said that it is not aware of anyone who had Lockdown Mode enabled getting hacked.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
>
Tech
Samsung Galaxy H1 Leak Points to New Over-Ear Headphones: What We Know
Samsung appears to be exploring a new full-size wireless headphone product, potentially expanding its Galaxy audio lineup beyond earbuds. Code and connection icons found in the Galaxy Wearable app reference a device reportedly known internally as Galaxy H1.
SamMobile first reported the discovery on Aug. 14. Samsung has not announced Galaxy H1, but a full-size headset could fill a longstanding gap in its Galaxy device ecosystem; its final name, design, specifications, price, and release date remain unknown.
The app leak suggests a headphone project
The evidence comes from Galaxy Wearable app code and icons that reference “Galaxy H1” and depict headphones with a headband and ear cups. The assets suggest a wireless, full-size design rather than another pair of Galaxy Buds.
Software references can appear before Samsung formally announces hardware. In July, the unannounced Galaxy S26 FE and Galaxy Tab S12 appeared in a Google app, providing another recent example of software surfacing possible products ahead of launch.
The H1 icons are not necessarily renders of finished hardware. The Verge reported that they indicate the general wireless headphone form factor but may not show the final design. “Galaxy H1” also appears to be an internal name rather than a confirmed retail brand.
If H1 reaches the market as a premium product, it could add a Galaxy-branded option alongside high-end headphones from Apple, Sony, and other established audio brands. Samsung has not disclosed its intended price segment or competitors.
Samsung has sold full-size wireless headphones before. Its Level range included the Level On Wireless Pro, announced in August 2015 with Bluetooth connectivity and active noise cancellation.
Samsung later completed its Harman International acquisition in March 2017, adding brands including AKG, JBL, and Harman Kardon to its audio portfolio. More recently, Samsung has continued expanding its wearable ecosystem with devices including the Galaxy Watch9 and Watch Ultra2.
A 2027 launch is possible, but specs remain unknown
SamMobile says the headphones could arrive sometime in 2027, but Samsung has announced no release date. Any narrower launch window or connection to a specific Galaxy event remains speculative.
Core features are also unknown. Active noise cancellation, device switching, Samsung audio codecs, and AI-assistant support would be plausible based on existing Galaxy products, but none has been confirmed for H1. Battery life, charging, Bluetooth version, microphones, and wired-audio support have not been disclosed.
Samsung’s current Galaxy Buds4 series supports Bluetooth 6.1, Auto Switch, and Samsung Seamless Codec UHQ. A future Samsung headset could inherit some of those ecosystem features, but the current leak provides no evidence that H1 will.
If the product reaches commercial release, compatibility, software support, and Samsung-specific features could determine how well it fits managed Galaxy deployments. Samsung’s reported Galaxy Watch9 support expansion shows how update commitments can affect device-lifecycle planning. Until Samsung confirms H1 and provides product and support details, IT teams have too little information to factor it into refresh or purchasing plans.
Read more: Samsung’s premium hardware lineup is expanding elsewhere as well, with the Galaxy Z Fold8 and Fold8 Ultra adding new choices for organizations and buyers evaluating the latest Galaxy devices.
>
Tech
Mac Malware Can Control Active Browser Sessions
A routine-looking download can turn into a much bigger problem for Mac users.
Jamf Threat Labs found an AmnesiaStealer campaign reaching macOS through a fake software download and capable of keeping attackers connected to browser sessions after infection. Researchers say the added access can extend the intrusion beyond the malware’s initial data theft.
An attack begins with a user-run Terminal command, but its more unusual stage comes later, after AmnesiaStealer is already inside the system.
A fake download opens the door on macOS
Jamf Threat Labs traced the campaign to a counterfeit GitHub-style page offering a macOS download. Visitors are instructed to copy an encoded command into Terminal, using a ClickFix attack chain that relies on the target to execute the malicious instructions.
Running the command triggers a shell script that downloads and launches AmnesiaStealer. The malware also attempts to obtain the user’s login password as it prepares to collect information from the system.
Turning stolen data into browser access
AmnesiaStealer first collects information stored on the infected device. Jamf found it targeting browser data and the macOS Keychain, with Apple Notes and Telegram also in its sights.
Mac infostealers have pursued similar information before. FrigidStealer, for example, has targeted browser credentials and Apple Notes.
The malware can then download an optional component called stream_module. This can copy a Chromium browser profile and launch another browser instance outside the user’s view. Operators can see what appears in the browser and send keyboard or mouse input back to it.
Copied browser data can preserve an authenticated session. Services that still recognize an existing session may not immediately ask for another login. Stolen session cookies can create a similar problem, while remote browser control also allows an operator to interact with the session from the compromised system.
Must-read Apple coverage
Work accounts raise the cost of a compromised device
If you use a Mac for work, treat a suspected AmnesiaStealer infection as more than a malware-removal job. Accounts already open in the browser may include company email or cloud services, depending on your role and access.
Take the affected device offline and contact your IT or security team if it is company-managed. Use a clean device to revoke active sessions and reset passwords for sensitive accounts. Review recent activity for anything you do not recognize.
If your role includes privileged or financial access, tell responders which services were open or recently used. A session tied to an administrative console or finance platform can carry permissions well beyond an ordinary user account.
Credential recovery should run alongside endpoint investigation. Unexpected Chromium processes or copied browser profiles can help establish whether the browser-control component was used. Recent threats such as ClickLock malware have already made credential theft a concern for Apple users, and AmnesiaStealer adds another form of access for defenders to account for after an infection.
Other News: WhatsApp is testing on-device AI scam alerts that flag suspicious messages from unknown senders without sending message content to the cloud.
>
-
movies3 months agoSearch For Canadian TV Actor Stewart McLean Now Homicide Investigation
-
Fashion9 years agoThese ’90s fashion trends are making a comeback in 2017
-
Fashion9 years agoAccording to Dior Couture, this taboo fashion accessory is back
-
Fashion9 years agoModel Jocelyn Chew’s Instagram is the best vacation you’ve ever had
-
Fashion9 years agoEmily Ratajkowski channels back-to-school style
-
Fashion9 years ago9 Celebrities who have spoken out about being photoshopped
-
Fashion9 years agoYour comprehensive guide to this fall’s biggest trends
-
Fashion9 years agoA photo diary of the nightlife scene from LA To Ibiza
