ZeroBytes breach exposes 1.22M French students and 4.35M staff

Share

On August 17, 2026, hacker ZeroBytes claimed responsibility for breaching France’s Ministry of Education, potentially exposing data on 1.22 million students and 4.35 million staff credentials. The intrusion reignites concerns about the security of French public-sector information systems.

🔑 Key takeaways

  • France’s Ministry of Education confirmed an intrusion detected on the night of July 25, 2026.
  • ZeroBytes claims to have exfiltrated roughly 43 GB of data, totaling 346 million raw records.
  • The breach allegedly affects 1.22 million students, 4.35 million staff identifiers, and 602,000 academic accounts.
  • The ministry filed a complaint and notified ANSSI (France’s national cybersecurity agency) and CNIL (the data protection authority).
  • ZeroBytes previously claimed attacks on France’s tax authority DGFiP, retailer Intermarché, and the French Handball Federation.

An unprecedented intrusion in French education

According to information published by FrenchBreaches, the attack on the Ministry of Education ranks among the largest data breaches ever suffered by a French administration. The hacker, operating under the alias ZeroBytes, posted a message claiming to have maintained access to the compromised systems for several days despite being detected by internal security teams.

In the claim, ZeroBytes wrote: « You detected me, but you didn’t cut me off. So I stayed infiltrated under your eyes. » The hacker also stated that a VPN (Virtual Private Network) access was used to reach the targeted internal environments and exfiltrate data over several days.

Attack timeline and ministry response

The intrusion was detected on the night of July 25, 2026. The following day, July 26, the ministry severed external access to the compromised system and activated a crisis cell. It was not until July 31 that the administration publicly confirmed the attack, describing « a fraudulent intrusion into one of its information systems » caused by the impersonation of a professional account.

At that stage, the ministry specified that the affected system was used solely for staff training and contained neither passwords nor student data. This statement stands in stark contrast to ZeroBytes’ claims, which assert access to several distinct internal environments and access maintained for several days after detection.

« You detected me, but you didn’t cut me off. So I stayed infiltrated under your eyes. »

ZeroBytes, hacker

Breakdown of the stolen data

Analysis of the published files reveals three main clusters. The first, roughly 24 GB across 1,581 files, primarily concerns systems of the Créteil academy and data of national scope. The second, around 17.8 GB across 1,048 files, aggregates exports from I-Prof — the staff career management system — covering all 33 French academies. The third, about 1.6 GB, consists of LDAP (Lightweight Directory Access Protocol, a centralized authentication service) and OpenAM directory extractions for the Créteil and Versailles academies, totaling nearly 602,000 entries.

Types of compromised information

For students, files include names, dates and places of birth, postal and email addresses, phone numbers, school identifiers, academic records, assignments, disciplinary data, absences, dropout-tracking records, and sometimes cryptographic hashes (irreversible digital fingerprints) of passwords. For staff, the data includes identity, date of birth, contact details, academic email addresses, administrative identifiers, corps and grade, assignments, employment status, contracts, qualifications, training history, and availability. Information about parents and legal guardians — notably their relationship to the students — is also present.

BE1D databases (Base Élèves 1er Degré, primary school student database) account for roughly 5.5 GB across more than 200 files, while SCONET exports (Système d’information des élèves du second degré, secondary student information system) total around 8.5 GB for the 2024-2025 school year and 5.7 GB for 2025-2026. Some records reportedly date back to the early 2000s, spanning more than twenty years of history — which explains why the total line count (346 million) far exceeds the number of unique individuals.

A pattern of attacks attributed to ZeroBytes

This intrusion adds to a series of attacks already claimed by ZeroBytes in recent months. The same group breached the Direction générale des finances publiques (DGFiP, France’s tax authority), affecting roughly 678,000 taxpayers, as well as Intermarché and the French Handball Federation. Earlier in the year, the Compas HR portal was hit in March 2026 and the EduConnect platform in April 2026, affecting approximately 3.5 million students.

DateTargetEstimated volume
June 2026DGFiP (tax authority)678,000 taxpayers
March 2026Compas HR portalHR data (volume unspecified)
April 2026EduConnect platform3.5 million students
July 2026Ministry of Education1.22M students / 4.35M staff IDs

Risks and recommendations

The combination of identity information, contact details, and academic or professional records exposes affected individuals to heightened risks of targeted phishing (fraudulent messages designed to steal data), identity theft, fraudulent SMS or calls, and social engineering attacks (psychological manipulation to extract sensitive information). The presence of password hashes — even if not in clear text — increases the danger when weak or reused passwords are involved. Data concerning minors and their legal guardians makes these attacks particularly sensitive.

The ministry urges potentially affected individuals to remain vigilant against any suspicious message and to report any attempted fraud. ANSSI and CNIL are continuing their investigations to determine the exact scope of the breach. At this stage, the administration has not confirmed the figures advanced by ZeroBytes and stresses that independent verification of the files is required.


Conclusion

This attack illustrates the persistent vulnerability of French public-sector information systems to organized threat actors. Beyond the Education Ministry case, the multiplication of intrusions claimed by ZeroBytes in 2026 suggests an intensification of operations targeting administrations and major economic players. The coming days will be decisive in measuring the true scope of the leak, confirming the authenticity of published data, and identifying the exploited vulnerabilities.

For the millions of potentially affected individuals, caution remains essential: increased account monitoring, systematic password renewal, and vigilance against any unusual contact using detailed personal information.

Sources

This article is published for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles