No passwords were stolen in this breach - and that's not the reassurance it sounds like
The French finance ministry has confirmed that someone got into the systems of the DGFiP, its tax administration, and extracted data belonging to 678,000 individuals and businesses. There was no clever exploit involved. The intruder used the credentials of a tax office employee and an outside contractor, connected to the agency's VPN, and ran queries through an internal search tool. That was in late June, on the 26th. It was detected and cut off at the time, and stayed out of public view until a seller using the handle "ZeroBytes" listed the database on a hacking forum on August 12.
The ministry is clear that user IDs, passwords and online accounts weren't compromised. Now look at what was: names, dates of birth, addresses, phone numbers, family circumstances, reference taxable income and withholding tax rate, along with company names and property records including addresses and plot sizes. The seller additionally claims another 252,149 land-registry records covering more than two million people, which the ministry hasn't confirmed.
To a scammer that list is worth considerably more than a password. Someone who already knows your address, your household situation and your actual taxable income doesn't have to work at sounding legitimate. And the calendar makes it sharper still: the ministry says it will begin contacting affected people next week, by email or letter. Anyone following the news now has both a ready-made script and a plausible reason to send you a link.
Which gives you a simple rule for the next few weeks. If a message about your tax file turns up, ignore its link and ignore its phone number, no matter how official the letterhead. Open your browser, type the tax authority's address yourself, and log in the way you always do. Genuine refunds never carry a fee, and genuine tax offices don't collect card numbers over the phone.
Tendvane's Privacy & accounts check shows which of your email addresses have already turned up in known breaches, which is a useful sense of how much of you is circulating before the convincing email arrives.