← Back to list

When a French Tax Official Sold Citizens’ Data to Criminals

David SEHYEON Baek · 2026-07-07 12:59 · 0 claps · 13.7 min read paywalled
#france #cryptocurrency #data-breach #cybercrime #true-crime
Open on Medium ↗
Wiki topics: CRY · Crypto & Web3 PFI · Personal Finance 🧘 · Spirituality

When a French Tax Official Sold Citizens’ Data to Criminals

The Knock in Montreuil

On the evening of September 26, 2024, three armed men walked up to a house in Montreuil, on the eastern edge of Paris, and forced their way inside. The man who lived there was a warden at La Santé, the old prison in the capital’s 14th district. The dispute that put him on someone’s list was almost trivial by the standards of organized crime, a quarrel over mobile phones that had been smuggled into a cell. The men who came to his door were paid roughly 800 euros to hurt him. What made the attack remarkable was not the violence. It was the accuracy. The men knew exactly where he lived, at an address he had only recently moved to.

That precision is what investigators from the Seine-Saint-Denis judicial police could not explain by ordinary means. The warden had not been followed. His new address was not public. When they traced the leak backward, it did not lead to a hacker in a distant country or a stolen phone. It led to a desk inside a French government tax office in Bobigny, and to a 32-year-old clerk named Ghalia C. who, according to Le Parisien, had looked him up in the tax administration’s software and passed the result along for money.

The story that unspooled from that single query is, on its surface, a French crime story about cryptocurrency and kidnapping. Underneath, it is something harder and more general. It is about what happens when the state collects the most intimate financial facts about its citizens, promises to guard them, fails, and then discovers that no one can meaningfully be held to account, because the institution that lost the data is funded by the same people it exposed.

The Clerk with the Keys to Everything

Ghalia C. worked in the corporate taxation department of the Bobigny tax office, in the Seine-Saint-Denis department north of Paris. She had access to an internal tax tool that French officials call Mira, a search engine that lets an authorized agent cross-reference a person’s identity, declared assets, and filing history in seconds. It is the kind of system that exists inside every modern tax authority, and it is enormously powerful precisely because it collapses a person’s financial life into a single lookup.

She should probably never have been near it. According to reporting from Le Parisien and the case coverage that followed, Ghalia C. carried a prior conviction for supplying narcotics to prison inmates and retained contacts inside the prison system. She was, in other words, exactly the profile a serious vetting process is meant to keep away from a national financial database, and she sat in front of one every working day.

What she did with it was methodical. Investigators who examined her workstation after her arrest found searches on prison guards, health inspectors, a judge, and the billionaire industrialist Vincent Bolloré. They also found something that turned a grubby insider-leak case into a national security question. She had been running queries on cryptocurrency investors, resolving the one piece of information that digital-asset holders most need to keep hidden, the link between a pseudonymous crypto fortune and a physical home address.

Eight Hundred Euros an Address

The economics were almost insultingly small. Police found cash deposits and Western Union transfers moving through her accounts, tied to an anonymous client who, by the case’s own arithmetic, paid roughly 800 euros per address. That is the same figure the Montreuil attackers were paid to carry out the assault, a neat and grim symmetry between the price of the data and the price of the beating it enabled.

Ghalia C. was taken into custody on June 30, 2025, and charged with criminal conspiracy and complicity in violence against a public official, with further charges opening in Nancy over the intimidation of civil servants. In her hearings she admitted passing information along but said she had not known what her coordinators intended to do with it. Her lawyer argued, plausibly enough, that she could not name the man at the top of the chain because she had never known his identity. When she refused to hand over her phone passcode or identify her intermediaries, the Paris Court of Appeal denied her release in early January 2026. The public prosecutor’s summary was blunt, saying she had abused her position in a completely abnormal manner to serve a hardened criminal.

The detail that lingers is the anonymity of the buyer. A single clerk with a grudge and a login turned a state registry into a directory of targets, and the state still does not know who was buying.

A Severed Finger and a Business Model

To understand why a residential address is worth killing for, you have to understand what a wrench attack is. Cryptocurrency is secured by private keys. There is no branch to call, no fraud department to reverse a transfer, no vault a bank can freeze once the coins have moved. If you can force the holder, in person, to type a seed phrase or hand over a hardware wallet, you have defeated every layer of cryptographic security at once. The industry named the technique after the joke that no amount of encryption stops someone hitting you with a five-dollar wrench until you talk.

France became the world capital of that crime. In January 2025, David Balland, a co-founder of the French hardware-wallet company Ledger, was abducted with his wife from their home near Vierzon in central France and held at separate locations. The kidnappers contacted another Ledger co-founder and demanded a ransom of roughly 100 bitcoin. To prove they were serious, they severed one of Balland’s fingers and sent it as proof, according to Le Parisien. France’s elite GIGN unit rescued him and later found his wife bound in a vehicle. Part of the ransom was paid during negotiations, and, working with Tether and exchanges, investigators traced and froze almost all of it.

Balland was not an isolated case but a template. In May 2025, according to reporting on the wave, the father of a crypto entrepreneur was seized in broad daylight in Paris, a finger amputated, a ransom of five to seven million euros demanded before police freed him. The same month, three masked men tried and failed to abduct the daughter of Pierre Noizat, chief executive of the exchange Paymium, thwarted in the street partly by a bystander with a fire extinguisher. In February 2026, near Grenoble, kidnappers took a magistrate and her mother and held them for roughly thirty hours, a plot aimed at the woman’s partner, a crypto startup executive, with six people including a minor later arrested. In one case reported out of Dompierre-sur-Mer, a couple was tortured in their own home until they transferred around eight million euros in crypto.

On April 24, 2026, Vanessa Perrée, the head of France’s National Anti-Organized Crime Office, put numbers to the pattern. Prosecutors had charged 88 people, more than ten of them minors, across twelve kidnapping cases, with 75 held in pretrial detention. Her office had recorded around 135 crypto-related incidents since 2023, rising from 18 in 2024 to 67 in 2025, with 47 already logged in the opening months of 2026. Perrée described structured networks that reused the same operatives across cases. The people doing the physical work, as the case files show, are frequently very young, clustered between 16 and 23, recruited through channels like Telegram as expendable hands while the organizers stay out of sight. France, by several counts, now accounts for something close to 40 percent of Europe’s crypto ransom attacks.

Telegram’s founder Pavel Durov drew the line between the two halves of the story out loud. Writing on April 24, 2026, he tied the abductions directly to the leaks, citing Ghalia C. by name and what he called massive tax database breaches, and warning that the state’s appetite for more identity data would only widen the target list. His formula was four words. More data, he wrote, equals more victims.

The Breaches That Needed No Insider

Ghalia C. required a corrupt human being. The more unsettling truth is that the French state has been losing its citizens’ financial data without needing one.

In late January 2026, an intruder accessed FICOBA, the national registry of French bank accounts maintained by the tax authority, the DGFiP. FICOBA is not a small system. It indexes close to 300 million accounts tied to roughly 80 million people, and it exists to let tax, customs, and law enforcement agencies see where a citizen banks. The attacker did not break the encryption or exploit a software flaw. They logged in, using credentials stolen from a civil servant authorized to query the file through an interministerial information-sharing platform. By the time the DGFiP detected the activity and cut the access, data on about 1.2 million accounts had been exposed, including IBANs, account holders’ names, physical addresses, and in some cases their tax identifiers.

The French Banking Federation was quick to reassure the public that the file does not show balances and cannot be used to move money directly. That reassurance misses the real danger. A name matched to an address, an IBAN, and a tax number is close to a perfect toolkit for targeted fraud and for the kind of impersonation that talks a frightened account holder out of their remaining defenses. It is also, read a different way, the same commodity Ghalia C. was selling by hand, now available at scale to whoever holds one stolen password.

The pattern repeated in June 2026, this time against the state’s own supposedly secure ground. DINUM, the government’s digital directorate, disclosed that Tchap, the sovereign messaging platform built so that civil servants would not have to trust WhatsApp or Signal, had been compromised through a hijacked account. A threat actor calling itself Misere claimed responsibility. The government confirmed that 73,467 accounts were affected, fewer than nine percent of registered users, and maintained that end-to-end encrypted private conversations stayed protected, with only unencrypted public rooms exposed. Misere told a larger story, claiming to have taken 13.5 gigabytes of data across more than 643,000 messages, along with references to restricted-distribution documents. Those larger figures have not been verified by DINUM or by France’s cybersecurity agency ANSSI, and several French analysts have deliberately kept them out of their trackers for lack of confirmation. Even the confirmed slice is bad enough. Names, government email addresses, and department affiliations are precisely what a spear-phishing campaign needs to map a ministry and walk deeper into it.

These were not the first, and the timing rhymes. In March 2024, France Travail, the national employment agency, was breached in an incident that touched the records of jobseekers registered over roughly two decades. In December 2025, according to American Banker, hackers reached internal email servers and criminal-record files at the Interior Ministry after employees shared passwords in plaintext. The European Union’s cybersecurity agency ENISA warned in late 2025 that government bodies now absorb the largest share of cyberattacks in the bloc, around 38 percent of the incidents it tracked. The common thread across FICOBA, Tchap, France Travail, and the Interior Ministry is not exotic. It is a stolen or shared credential and a system that granted one account the power to reach across a national dataset without a second lock.

The Honeypot the Law Built

Here the story turns from failure to design, because the concentration of this data is not an accident. It is policy.

French tax law treats digital assets with unusual thoroughness. Gains on the disposal of crypto by an individual are taxed under the flat Prélèvement Forfaitaire Unique at 30 percent, made up of 12.8 percent income tax and 17.2 percent social contributions, with a small exemption when total annual disposals stay under 305 euros. Trade often enough to look professional and the gains shift to the progressive income scale, which climbs toward 45 percent. France is comparatively liberal in one respect, taxing only conversions to conventional currency rather than crypto-to-crypto swaps, so liability is deferred until an asset becomes euros or goods. But it demands a great deal of visibility in exchange. Taxpayers must compute gains against their whole portfolio at the moment of each disposal, file the relevant disposal forms, and declare every foreign account each year on Form 3916.

Layered on top, the European Union’s DAC8 directive and its MiCA framework have handed the DGFiP expanded authority to audit exchange accounts and cross-reference user registries. The result is a lawful, deliberate concentration of names, home addresses, bank details, and precise measures of crypto wealth inside government systems. Every argument for it is reasonable on its own terms, fairness, enforcement, the fight against money laundering. And every one of those arguments builds the exact dataset that turns a single leaked login into a shopping list for kidnappers. This is the paradox Durov was pointing at, and it is not really about crypto. It is about the general truth that a registry assembled for oversight is, from the criminal’s side of the glass, a target folder waiting to be opened.

The Fine That Cannot Be Levied

Now weigh the consequences, and the asymmetry that sits at the center of all this comes into view.

When a private company loses this kind of data, the European machinery of punishment is real and expensive. Under Article 83 of the GDPR, a firm can be fined up to 20 million euros or 4 percent of its worldwide annual turnover, whichever is larger. Those are not theoretical ceilings. Meta was hit with a 1.2 billion euro penalty in 2023, Amazon with 746 million in 2021, and France’s own regulator, the CNIL, issued a 325 million euro fine against Google in a recent enforcement round. A breached company faces regulators, shareholders, class actions, and a market that prices the damage into its value the next morning.

Now look at what happens when the breached party is the French state itself. According to the CMS GDPR enforcement tracker for France, the CNIL can take enforcement action against public authorities, but no administrative fine may be imposed for personal-data processing carried out by the State. The mechanism traces back to Article 83(7) of the GDPR, which lets each member state decide whether and how far its own public bodies can be fined, and France has drawn that line so that the State’s own processing sits outside the reach of a monetary penalty. The DGFiP lost 1.2 million people’s banking identities and faces no prospect of the kind of fine that a bank leaking the same records would have paid without argument.

The circularity gets worse where public bodies can be fined at all. CNIL fines do not stay with the regulator. They are paid into the state treasury. So in the scenario where a public agency is penalized, the money travels from one government account to another, drawn from and returned to the same pool of tax revenue. The citizen whose data was exposed funds both sides of the transaction and receives none of it. A fine on a company is a transfer from a negligent private actor to the public purse. A fine on a state agency, if it happens at all, is the public purse moving money from its left pocket to its right, while the people whose addresses are now in a criminal’s spreadsheet get a letter advising them to watch for suspicious emails.

Who Pays When the State Loses Your Data

Follow the incidence of the harm all the way down and the injustice is complete. The clerk in Bobigny goes to prison, which is right, but she was a symptom. The organizers who bought her queries remain unidentified. The DGFiP, the institution that granted a convicted narcotics smuggler standing access to a national financial engine and then lost a separate registry to a single stolen password, absorbs no fine, loses no revenue, and answers to no shareholder. Its budget next year will be set by the same ministry it reports to, and paid, as always, by the taxpayers whose data it failed to protect.

The victims, meanwhile, carry costs that no administrative process will ever reimburse. A severed finger does not grow back. A magistrate held for thirty hours does not un-live it. The 1.2 million account holders exposed through FICOBA cannot change their home address as easily as a company can rotate a breached API key, and they will spend years as slightly better targets for fraud than they were before the state lost their file. When a bank leaks your data, you can leave the bank. When the tax authority leaks it, there is no exit. Filing is not optional, and the same monopoly that compels the disclosure is the one that failed to guard it and cannot be made to pay for the failure.

This is the deeper significance of the French case, and the reason it travels far beyond crypto or France. Every modern state is running the same play, gathering more identity data each year, from digital IDs to messaging metadata to real-time financial reporting, on the promise that centralization serves the public. The promise is made by institutions that, almost uniquely, cannot be fined into caring when they break it. The market disciplines a careless company. Very little disciplines a careless ministry.

Breaking the Loop

None of this argues that the data should not exist, only that the accountability is missing, and the fixes fall into two honest categories.

The first is technical and organizational, and it is unglamorous precisely because it works. The recurring failure across FICOBA, Tchap, France Travail, and the Interior Ministry was a single credential unlocking far too much. Phishing-resistant hardware authentication, the FIDO2 and passkey family rather than passwords and SMS codes, closes the exact door the attackers walked through. Access to engines like Mira should be attribute-based and context-bound, tied to an open case file, a jurisdiction, and a supervisor’s approval, so that a lower-level clerk simply cannot run an arbitrary lookup on a billionaire or a prison guard. Every query against a high-value or public-figure record should trip an automated alert and demand a second authorization in real time. And the vetting that let a person with a narcotics conviction sit in front of a national database has to be treated as a security control, not a formality. These measures are well understood. What has been missing is the pressure to fund and enforce them.

The second is the accountability gap itself, and it is harder because it is political rather than technical. A regulator that cannot fine the State has no lever that bites. Serious options exist, from statutory duties that expose responsible officials personally, to independent audit with published findings and real consequences, to direct compensation paid to breached citizens rather than fines cycled back into the treasury. Data minimization belongs here too, since the cheapest record to protect is the one never collected, and DAC8-era reporting should be pressure-tested against whether each field is worth the risk of holding it. Until some mechanism makes the collecting institution feel the cost of losing what it takes, the incentive runs one way, toward gathering more and guarding it exactly as well as an un-finable body ever bothers to.

Individuals are left to defend themselves in the gap. The practical advice from investigators and from figures like the security researcher Jameson Lopp is consistent and slightly bleak, treat your home address as a secret, keep visible crypto wealth off social media and conference stages, avoid tying corporate filings and foreign-account declarations to where you actually sleep, and hold assets in ways that make an instant coerced transfer impossible, through geographically split multi-signature setups or time-locked vaults, with a small decoy wallet to satisfy an attacker in the room. It is sound guidance. It is also an admission that the citizen is now expected to compensate, at their own expense and their own risk, for the state’s failure to secure what it insisted on collecting.

The Cost of Being Findable

Strip the case back to its smallest unit and this is what remains. A woman at a desk in Bobigny typed a name into a government system built to make citizens legible to their state, and turned that legibility into a map to a stranger’s front door. The men who used the map were paid 800 euros. The man who bought it was never found. The system that made it all possible is still running, still collecting, still promising to protect what it holds, and still facing no bill it will actually pay when it fails.

Legibility was supposed to be the price citizens paid for a functioning state. The French crypto kidnappings show the bargain running the other way, with the citizen bearing the full cost of exposure and the state bearing almost none of the cost of the breach. Until that imbalance is corrected, the safest assumption for anyone whose data sits in a national registry is the one the victims learned the hard way. The database that knows where you live is only ever one stolen password, or one 800-euro clerk, away from telling someone who means you harm.


메타데이터
post_id
7b253310ed35
slug
when-a-french-tax-official-sold-citizens-data-to-criminals-7b253310ed35
url
https://medium.com/@davidsehyeonbaek/when-a-french-tax-official-sold-citizens-data-to-criminals-7b253310ed35
canonical_url
https://medium.com/@davidsehyeonbaek/when-a-french-tax-official-sold-citizens-data-to-criminals-7b253310ed35
author_url
https://medium.com/@davidsehyeonbaek
status
ok
fetched_at
2026-07-08 05:49:34