Skip to content
>_ITDITDWeb Security Platform

Security Guides

When the data leaks from someone you can't stop using: four 2026 government data breaches (DoD's DMDC, Illinois DHS, Latvia's CSDD, France's tax authority) and what citizens can do

Four 2026 cases where government agencies lost citizens' data (the DoD's DMDC, Illinois DHS, Latvia's road traffic directorate CSDD, France's DGFiP), compared from the agencies' own statements. How each got in, and how to protect tax and benefit accounts, request your records and spot agency-impersonation scams.

Published 2026-09-30 Updated 2026-09-30 Last verified 2026-09-30 22 min read

For: anyone who has received, or may receive, a data breach notice from a national or local government agency, and their families. Also for people who run government systems or work for companies that do work for government. This article compares four cases using the agencies' own notices, FAQs and government press releases, plus news reports quoting officials. It does not cover attack techniques.

First: if a government agency sends you a breach notice

If you searched for one of these incidents, you probably want to know whether you're affected and what to do. These steps are based on what the agencies themselves are telling people.

1

Don't use the numbers or links in the notice; check the agency's official site

France's DGFiP says in its FAQ that its notice "contains no direct link to your tax space and asks for no confidential information". Latvia's CSDD asked people to check information on its official portal, e.csdd.lv, and set up a dedicated incident section on its website. In other words, genuine agencies are moving away from having you act through links in a notice. Check through an official site you type in yourself, or a main phone number you look up yourself.

2

Find out which items leaked, and lock each number where it can be abused

What leaked determines what to do. If your Social Security number was involved, place a credit freeze at Equifax, Experian and TransUnion (free, and it lasts until you lift it, per the Federal Trade Commission) and get an IRS IP PIN, a six-digit number that stops someone filing a tax return with your SSN and changes every year. In the French case, where tax identifiers and income details were involved, DGFiP recommends checking the register of bank accounts in your name (FICOBA) in your impots.gouv.fr space for any account you didn't open.

3

Harden the login to your tax and benefit accounts

DGFiP says impots.gouv.fr passwords were not stolen in this incident. Its personal space already uses two-step verification that emails a six-digit code after your password, and its FAQ says that if a code arrives that you didn't request, change your password quickly. The practical point: the email account that receives the code is itself a key to your tax account. Give that mailbox a strong password and two-factor authentication (see What is two-factor authentication?).

4

Hang up on anyone claiming to be the agency, and call back yourself

The FTC says "government agencies will never call, email, text, or message you on social media to ask for money or personal information", and warns that caller ID can be faked. DGFiP repeats that the tax authority never asks for confidential information by email, text or phone, and CSDD asked people to be especially careful with emails and texts that appear to come from CSDD. A caller who knows your address, income, number plate or military job has not proven anything (see What is phishing?).

5

Use your right of access to learn what leaked

If no notice arrives, or it's vague, you have a right to ask for your own data. In the EU there's GDPR Article 15 (which France's CNIL says applies to public administrations, is free, and requires an answer within one month); in the US, the Privacy Act of 1974; in Japan, Article 76 of the Act on the Protection of Personal Information. CSDD said its incident section explains the procedure for customers to obtain information about their affected data.

Signs of a genuine agency contact (from the agencies' own statements)

  • No direct link to your account in the notice (DGFiP)
  • Tells you to check on the official site or app (CSDD, DGFiP)
  • Never asks for passwords, verification codes or card numbers
  • The same information appears in a notice or FAQ on the official site

Signs of a scam

  • A call or text asking you to "confirm" a number, code or password
  • Quotes your address or income to sound credible
  • Asks for payment, gift cards or cryptocurrency
  • Urgency or threats: "today", "or you'll be arrested"

Where to check, by country (open them yourself)

US: credit freezes and IP PINs through the FTC (consumer.ftc.gov) and IRS (irs.gov). Report scams at ReportFraud.ftc.gov.
France: the notice and FAQ on impots.gouv.fr; DGFiP's FAQ lists 0809 401 401 for questions. For help with fraud, 17Cyber.gouv.fr; to report it, cybermalveillance.gouv.fr.
Latvia: e.csdd.lv and the incident section on CSDD's website.
Illinois: IDHS says the individual notices include toll-free numbers for questions.

The four 2026 cases at a glance

Based on the agencies' notices, FAQs and government press releases, and news reports quoting officials. Numbers are only those given by the agencies or officials.

Agency (country)Announced / notifiedWhat got out (agency's account)People (agency / officials)Way in (agency's account)
Defense Manpower Data Center (DMDC) (US DoD)Notice dated Sept 18, 2026 (per reports)Unencrypted personal data including SSNs2.76 million living and 294,000 deceased (a Pentagon official)A vulnerability in a file-sharing system
Illinois Department of Human Services (IDHS) (US)Jan 2, 2026Customer data in internal planning mapsApprox. 32,401 and approx. 672,616, in two groupsIncorrect privacy settings on a mapping website
Road Traffic Safety Directorate (CSDD) (Latvia)Aug 13, 2026 (numbers on Aug 18)Historical payment-receipt data back to 2008About 1.2 million (CSDD)A vulnerability in a web application CSDD maintained (Ministry of Transport commission)
Directorate General of Public Finances (DGFiP) (France)Aug 14, 2026Tax identifiers, income-related details and moreA total of 678,000 individuals and businesses (government press release)Impersonated credentials of an agent and an authorized third party
3 ways
How the four cases got in: a wrong setting, a vulnerable system, impersonated credentials
2008 on
How far back CSDD's affected payment-receipt data goes (per the directorate)
Not included
Users' login passwords (DGFiP and CSDD both say they were not in the stolen data)
Unknown
Who viewed IDHS's maps (the agency says the mapping website could not identify viewers)

1. A wrong setting

IDHS: internal maps left public on an outside mapping site. Viewers can't be identified

2. A vulnerable system

DMDC: a file-sharing system / CSDD: a web application it maintained

3. Impersonated credentials

DGFiP: IDs of an agent and an authorized third party. Access was cut; the theft was established later

↓ Whichever way in, what reaches citizens is

"Agency" contacts that know your address, numbers, income, car or military job

And because it's the state, you can't just stop using the service

Four tools citizens do have

Check official sites / lock tax and benefit accounts (IP PIN, credit freeze, the email that gets your code) / call back yourself / right of access

Three ways in, each noticed differently and each leaving different questions. What reaches citizens is the same: convincing contacts from someone claiming to be the agency.
  1. Jan 2, 2026

    Illinois DHS issues a media notice about internal maps that were publicly viewable (it says it discovered this on September 22, 2025).
  2. Jul 16

    DMDC discovers a vulnerability in a file-sharing system (according to the notice as reported).
  3. Aug 12–13

    A malicious actor claims illegitimate access to DGFiP's systems; DGFiP says this is when the data theft was established.
  4. Aug 13

    CSDD announces it has been hit by a cyberattack.
  5. Aug 14

    France's economy and finance ministry issues a press release on DGFiP (678,000).
  6. Aug 18

    CSDD says the personal data of 1.2 million people was obtained.
  7. Sept 18

    DMDC sends notices to affected people (per reports). The same day, Latvia's Ministry of Transport publishes its evaluation of the CSDD incident.
  8. Late Sept

    A Pentagon official gives news outlets the number of people affected by the DMDC breach.

What each agency said

Based on the agencies' notices, FAQs, government press releases, and news reports quoting officials. Contractors and vendors the agencies used, and individuals involved, are not named.

US Department of Defense: Defense Manpower Data Center (DMDC)
What (the notice, as reported)
On July 16, 2026, DMDC discovered a security vulnerability in a file-sharing system. It says a small number of unauthorized users accessed files on a server containing unencrypted personal information between October 2025 and July 16, 2026
Data
Social Security numbers plus at least one other item (name, date of birth, contact information, sex, race, or military personnel information such as job specialty). Varies by person
People
A Pentagon official told news outlets 2.76 million living and 294,000 deceased people were affected
Response
Patched the vulnerability and restored the system. According to the notice, there is no indication the information has been misused. Offers 12 months of free credit monitoring
Illinois Department of Human Services (IDHS)
What
On September 22, 2025, IDHS discovered that internal planning maps its staff had created on a mapping website were publicly viewable due to incorrect privacy settings. The maps were meant for internal use, for decisions such as where to open new local offices
Who and when
Approximately 32,401 Division of Rehabilitation Services customers (publicly accessible April 2021 to September 2025), and approximately 672,616 Medicaid and Medicare Savings Program recipients (January 2022 to September 2025)
Data
For the first group: names, addresses, case numbers, case status, referral source and more. For the second: addresses, case numbers, demographic information and the name of the medical assistance plan, without recipients' names
Response
Changed the settings on all maps between September 22 and 26, 2025, and adopted a policy prohibiting customer-level data on public mapping websites. It says the mapping website was unable to identify who viewed the maps, and it is unaware of any misuse
Latvia: Road Traffic Safety Directorate (CSDD)
What (Aug 13)
Said it was hit by a sophisticated cyberattack over a weekend; the attackers partially accessed IT systems and obtained historical payment-receipt data for CSDD services. It stopped the attack with CERT.LV and informed authorities including the Data State Inspectorate. Customers' usernames and passwords were not affected, it said
Scope (Aug 18)
Personal data of 1.2 million people, from receipts dating back to 2008: personal ID or company registration number, name or company name, payment amounts and dates, vehicle registration numbers and addresses (not complete in all cases). Phone numbers and email addresses were not compromised, as reported
Evaluation (Sept 18)
A Ministry of Transport commission found that a vulnerability in a web application CSDD maintained enabled the initial access. It put the scope at about 1.15 million individuals and up to 200,000 legal entities, and recommended, among other things, reviewing data retention periods and improving contracts with, and oversight of, outsourced services
Afterwards
In-person and e-CSDD services continued
France: Directorate General of Public Finances (DGFiP, the tax authority)
What
A malicious actor claimed the theft on August 12 and 13, 2026. According to the government press release, the illegitimate access in June and July relied on impersonated credentials of a DGFiP agent and an authorized third party. DGFiP cut the access when it was detected, but checks at that point did not reveal that data had been taken, it says
People
A total of 678,000 individuals and businesses (press release). The later FAQs give just over 350,000 individuals and just over 250,000 businesses
Data (individuals)
Tax identifier, civil status, postal, phone and email contact details, tax situation (family situation, dependants, number of shares, reference taxable income, withholding rate), and the list of messages exchanged through impots.gouv.fr. For fewer than 250 people, message content too (attachments were not viewed). Land-registry data on property addresses and surface areas was also viewed
Response
Cut access for the agent accounts used and preventively cut access to sensitive systems. Referred the matter to the CNIL and filed a complaint. Strengthened protection of affected people's tax accounts, watching closely for changes of address or bank details in the coming months. impots.gouv.fr personal and business spaces and passwords were not compromised, it says

How to read the numbers

The DMDC figure is what a Pentagon official gave news outlets; this site could not find a public DoD notice page when checking. CSDD announced 1.2 million people on August 18, while the Ministry of Transport's September 18 evaluation gives about 1.15 million individuals and up to 200,000 legal entities. DGFiP broke its press-release figure of 678,000 into individuals and businesses in its FAQs. This article does not rank the four cases by how "bad" they were. Separately, DGFiP also reported that on August 17 a technical vulnerability was found on a vacant-estates portal containing only public data.

This site's view: against a data holder you can't leave, your tools are rights and locks, not choice

When a private service leaks your data, most people think about closing the account. With a tax office, a benefits agency, driving and vehicle registration, or military personnel records, you can't. And these four cases reached years of records (CSDD's receipts back to 2008, IDHS's maps from 2021) and even records of people who have since died (294,000 deceased in the DMDC case).

So what works on the citizen's side is not the power to choose, but two tools. One is rights: use the right of access to find out what's held and what leaked. The other is locks: put a lock on the places a leaked number can be abused (new credit, tax filings, your tax account), with an IP PIN, a credit freeze, and a protected mailbox for your verification codes. As the IDHS case shows, some leaks come with no way to know who saw the data. Waiting until you find evidence of misuse is too late, in this site's view.

Other government and public-body cases are covered in detail in their own articles, so they aren't repeated here.

For people who run government systems or work for government contractors: a first step for each way in

1

1. Wrong settings: list the sharing scope of every outside service

The IDHS case happened on a mapping website, the kind of outside service that rarely gets managed as an information system. The agency's fix was a policy that no customer-level data goes onto public mapping sites. The first step is to list the outside SaaS tools staff use (maps, forms, shared spreadsheets, file sharing) and find anything set to "anyone with the link" or "public". With services like these you may never be able to tell who viewed the data, so prevention is the only option.

2

2. Vulnerable systems: how many years of unencrypted data sit in your file shares?

The DMDC case involved a file-sharing system; the CSDD case, a web application the directorate maintained. In general, patching speed alone isn't enough. Take stock of whether numbers people can't change, like SSNs, sit unencrypted in file-sharing locations, and how many years of records are kept there. That is the point behind the Ministry of Transport commission's recommendation to review data retention periods at CSDD. How to defend edge devices and software is covered in how to defend your VPN.

3

3. Impersonated credentials: hold staff and authorized third parties to the same bar

In the DGFiP case, the government says credentials of an authorized third party as well as an agent were impersonated. Government systems have accounts for people who aren't staff: contractors, and professionals who act for citizens. The first step is to require the same phishing-resistant MFA (passkeys or FIDO2 security keys) for non-staff accounts as for staff, and to limit what each can see to what the job needs (see What is a passkey?).

4

Check 'access was cut' and 'nothing was taken' separately

DGFiP says that when it detected and cut the illegitimate access, it couldn't yet see that data had been taken. In general, disabling an account and establishing how many records that account read and sent out are different jobs. For the second, log how many records each account looks up per day, and alert when it exceeds a multiple of normal, starting with your most sensitive data.

If you're affected: the nearest danger is the 'agency' contact that follows the notice

In all four cases, details only you should know got out: addresses, ID numbers, income, number plates, military jobs. That's enough to build convincing calls, texts and emails. If someone asks for a code, password or bank details in the name of "compensation", "a tax refund" or "updating your registration", hang up and call a number you looked up yourself on the agency's official site. DGFiP's FAQ advises keeping evidence (messages, site addresses, screenshots) if you suspect fraud.

Sources (public records)

The facts in this article are based on the official notices and public records below, and on news reports quoting officials. Numbers are only those given by the agencies, governments or officials; no press estimates or speculation about undisclosed causes are used. Contractors and vendors are described by role only.

  • Illinois Department of Human Services, "Notice to the Media from Illinois Department of Human Services – Incident Involving Protected Health Information" (January 2, 2026) — idhs.prezly.com
  • CSDD, "CSDD saskārusies ar kiberdrošības incidentu" (August 13, 2026, official announcement published by Latvijas Vēstnesis) — lvportals.lv
  • CSDD, "CSDD mājaslapā izveidota vienota sadaļa par kiberdrošības incidentu" (August 21, 2026) — lvportals.lv
  • Latvian Ministry of Transport, "Pabeigts CSDD kiberincidenta izvērtējums" (September 18, 2026) — lvportals.lv
  • Latvian public broadcaster LSM (English): CSDD's August 18 announcement (1.2 million, receipts back to 2008) — eng.lsm.lv / interim board elected (August 20) — eng.lsm.lv
  • DGFiP, "Vol de données suite à des accès illégitimes au système d'information de la DGFiP" (August 14, 2026, updated September 14) — impots.gouv.fr / FAQ for individuals (August 24, 2026) — impots.gouv.fr (PDF) / FAQ for businesses — impots.gouv.fr (PDF) / "Fuites de données : comment réagir ?" — impots.gouv.fr (PDF)
  • French Ministry of the Economy and Finance, press release No. 953, "Accès illégitimes au système d'information de la Direction générale des Finances publiques" (August 14, 2026) — presse.economie.gouv.fr
  • DGFiP, "FAQ : Réussir l'authentification en deux étapes" — impots.gouv.fr (PDF)
  • CNIL, "Le droit d'accès : connaître les données qu'un organisme détient sur vous" — cnil.fr
  • News reports (contents of DMDC's notice, and the figures given by a Pentagon official): Military Times (September 24, 2026) — militarytimes.com / Federal News Network — federalnewsnetwork.com / Stars and Stripes (September 29, 2026) — stripes.com
  • Federal Trade Commission, "What To Know About Credit Freezes and Fraud Alerts" — consumer.ftc.gov / "How To Avoid a Government Impersonation Scam" — consumer.ftc.gov
  • Internal Revenue Service, "Get an identity protection PIN" — irs.gov
  • US Department of Justice, Office of Privacy and Civil Liberties, "Privacy Act of 1974" — justice.gov
  • Japan, Act on the Protection of Personal Information (Article 76, right to request disclosure) — e-Gov (Japanese)

Update history

2026-09-30: First published. Based on the IDHS notice, CSDD and Latvian Ministry of Transport announcements, DGFiP's notice and FAQs and the French finance ministry's press release, news reports of DMDC's notice and a Pentagon official's figures, and public guidance from the FTC, IRS, CNIL and US Department of Justice. We'll update if the agencies publish more, such as an official DMDC notice page.

FAQ

QWhat were the major government data breaches of 2026?
A

According to the agencies' statements and officials' accounts, they include the US Department of Defense's Defense Manpower Data Center (DMDC), where unencrypted personnel records including Social Security numbers were accessed through a file-sharing system vulnerability, and a Pentagon official put the count at 2.76 million living and 294,000 deceased people; the Illinois Department of Human Services (IDHS), where internal maps containing customer data were publicly viewable because of incorrect privacy settings on a mapping website, affecting approximately 32,401 and approximately 672,616 people in two groups; Latvia's Road Traffic Safety Directorate (CSDD), where historical payment-receipt data back to 2008 was taken and the directorate said 1.2 million people were affected; and France's tax authority (DGFiP), where impersonated credentials of an agent and an authorized third party were used to extract data on a total of 678,000 individuals and businesses.

QWhat can citizens do when a government agency leaks their data?
A

You can't stop using a tax office or benefits agency, so focus on measures that work after a leak. (1) Verify any notice through the agency's official website or a number you look up yourself, not the number or link in the notice. (2) Lock your tax and benefit accounts: in the US, an IRS IP PIN and a credit freeze at all three bureaus; in France, protect the email address that receives impots.gouv.fr's two-step verification code. (3) Don't respond to calls, texts or emails claiming to be the agency; hang up and call a number you looked up. (4) Use your right of access to find out what the agency holds about you.

QAfter the DGFiP breach, do I need to change my impots.gouv.fr password?
A

According to DGFiP's FAQ, the personal and business spaces on impots.gouv.fr were not compromised and passwords were not among the stolen data, so a change is not necessary (though you can change it at any time). The tax authority says it never asks for confidential information by email, text or phone, and asks people to always log in by going to impots.gouv.fr themselves rather than clicking a link. If you receive a verification code you didn't request, the FAQ says to change your password quickly.

QI got a notice from the DoD's DMDC. What should I do?
A

According to news reports, DMDC's notice offers 12 months of free credit monitoring. If you use the enrollment site in the letter, check it against the letter itself before entering anything. Because Social Security numbers were involved, this site recommends a credit freeze at Equifax, Experian and TransUnion (free, per the Federal Trade Commission) and an IRS Identity Protection PIN, a six-digit number that stops someone else filing a tax return with your SSN. The IRS will never contact you asking for your IP PIN.

QCan I ask a government agency what data it holds about me?
A

In many countries, yes, as a right. In the EU (including France and Latvia), Article 15 of the GDPR gives a right of access; France's data protection authority, the CNIL, says it applies to public administrations, is free, and requires an answer within one month. In the US, the Privacy Act of 1974 lets you review and get a copy of your records held in a federal agency's system of records. In Japan, Article 76 of the Act on the Protection of Personal Information lets you request disclosure from the head of an administrative organ.