A sophisticated phishing campaign is currently targeting digital asset holders in France. Using physical mail that mimics the visual identity of the Direction générale des finances publiques (DGFiP), scammers are attempting to coerce taxpayers into declaring all their exchange platforms, wallets, and DeFi protocols. The document, written in formal administrative language, claims to be an urgent formal notice, threatening heavy financial penalties of up to 80% in surcharges. To "regularize" their situation, victims are urged to scan a QR code that leads to a fraudulent portal designed to harvest sensitive data.
The relative success of this scam relies on leveraging databases from massive data breaches. Cybersecurity experts have linked the targets to previous data compromises, notably those involving logistics providers or historical security incidents within the crypto ecosystem. This targeting, while sometimes random, is amplified by the current climate of distrust following recent security breaches that exposed the information of hundreds of thousands of individuals. By using a physical medium, the scammers effectively bypass traditional IT protections, pushing users to take action from their personal smartphones.
Beyond simple theft of platform access, this maneuver poses a real threat to the financial security of investors. By precisely mapping a victim's assets, attackers secure a valuable database to design personalized extortion campaigns or even physical threats. Authorities reiterate that the DGFiP never uses QR codes for such reporting procedures and does not send formal notices via standard mail without going through official, established channels.
Vigilance remains the best defense against these manipulation attempts. Several clues can help identify the hoax: tax inconsistencies, spelling errors, and the absence of mandatory information on the envelope. It is imperative to never scan suspicious codes received by mail. In case of doubt regarding the authenticity of a tax document, the only prudent course of action is to log in directly to the official impots.gouv.fr website or to contact your local tax office directly through their usual communication channels, completely ignoring the instructions found on the suspicious letter.