Public services and institutions

France data breaches in 2026: tax office, schools and AFPA explained

A sourced timeline of DGFiP, education and AFPA incidents, separating the actual scope and practical checks for each case.

Conceptual illustration: France data breaches in 2026: tax office, schools and AFPA explained
Conceptual illustration · SecurCheck

What is confirmed

DGFiP reported 678,000 individual and business records consulted or extracted; individual account portals were not compromised.

France's education ministry issued separate notices in March (COMPAS), April (students and EduConnect) and July-August (staff training). AFPA separately investigated an incident involving a third-party tool.

What it means

These incidents have different scopes: mechanically adding their figures yields a misleading total and may count people more than once.

On 7 September, ANSSI announced its REACTIV initiative to help government services respond to account compromise and data breaches.

What to do

Read the relevant organisation's notice to determine which incident and fields concern you; avoid generic urgent messages.

For a purported public notice, open the official portal via a bookmark or manually typed address and report impersonation attempts.

Check a suspicious sign

Suspicious ANTAI text or tax-office email? Check it. For a job offer referring to AFPA or France Travail, review the recruitment separately.

Sources

  1. Ministère de l’Économie — DGFiP
  2. Ministère de l’Éducation — COMPAS
  3. Ministère de l’Éducation — ÉduConnect
  4. ANSSI — dispositif REACTIV