France's Direction Generale des Finances Publiques (DGFiP), the agency that runs the country's online tax portal impots.gouv.fr, confirmed this week that attackers accessed and extracted taxpayer data affecting both individual and business accounts. The confirmation came only after a criminal actor operating under the handle ZeroBytes began touting the stolen records on a criminal forum, claiming roughly 678,000 people were affected, split between about 393,000 individual accounts and 286,000 professional accounts; French officials have not independently verified the exact count but acknowledged unauthorized access occurred. The timeline is the part most relevant to engineering and security teams: DGFiP says the intrusion was actually detected and cut off during routine security checks back in late June, but the agency made no public disclosure at the time, and the breach only became known once the attacker put the data up for sale roughly six weeks later. That gap between detection and disclosure is a recurring pattern worth internalizing, not a one-off failure: internal detection without a corresponding public or regulatory disclosure process leaves affected users unprotected for the entire gap period, during which stolen identity data can already be resold, cross-referenced with other breach datasets, or used for targeted phishing. Government tax systems are a particularly high-value target class for exactly this kind of long-tail exploitation, since the data involved (legal names, addresses, income and property details, business registration information) does not expire or get revoked the way a password or credit card number can, so its value to attackers persists for years. For teams building or securing systems that handle comparably sensitive, non-rotatable personal data, the case is a concrete argument for tightening detection-to-disclosure SLAs, ensuring breach response runbooks do not stall between confirmed internally and reported externally, and assuming that intrusion-detection success at the network layer does not by itself mean the incident is resolved from a user-harm standpoint. DGFiP says it will report the incident to French data-protection regulator CNIL and is still working to determine and notify the full set of affected taxpayers.