Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

France suffers from unprecedented cyber attack wave, with one hacker supposedly behind it all

France has confirmed an unprecedented wave of cyber attacks impacting a number of government agencies and private-sector businesses.

Tue, 18 Aug 2026
France suffers from unprecedented cyber attack wave with one hacker supposedly behind it all

Over several posts on an infamous dark web forum, a cyber criminal going by the name ZeroBytes disclosed breaches of French government agencies, starting with impots.gouv.fr, which is the official online portal for the French tax authority, the Direction générale des Finances publiques (DGFiP).

According to the post, which was made last month, the incident occurred on 26 June and saw 678,438 lines of data stolen. According to media reports, around 678,000 people have been impacted, a number confirmed by the French government.

Following this, ZeroBytes posted a second DGFiP listing, saying that they breached the agency on 29 July, and claimed 252,149 rows of data were stolen.

 
 

However, the threat actor alleges that there were multiple people per row of data, and estimated that the number of people impacted was 2,041,778. ZeroBytes went as far as to say that the database accessed contained the data of around 20 million citizens, but said the scrape was taking too long.

“We couldn’t finish the extraction because honestly, it’s just horrible to scrape and would have taken months. I’m still logged into the panel, so if you want, you can buy it along with the database. I’m not going to sell this one for very much anyway. And as always, no mention from France about this incident,” the threat actor said.

In both listings, the threat actor posted links to samples of the data.

The French Ministry of Action and Public Accounts (Ministère de l’Action et des Comptes publics) confirmed the breach in a statement.

“On Wednesday, 12, and Thursday, 13 August 2026, a malicious actor claimed illegitimate access to the information system of the Directorate General of Public Finances (DGFiP), which occurred in June and July 2026, based on the usurpation of identifiers of a DGFIP agent and an authorised third party,” the agency said in a statement translated from French.

“Upon detecting these intrusions, the French Public Finances Directorate (DGFiP) immediately suspended access to all accounts used in the identified incidents. However, the access controls carried out at that time did not reveal that these intrusions had led to data theft, due to the sophistication of the attack.

“The in-depth investigations conducted since August 12, 2026, have established that, prior to their interruption, these access points had been used to consult and extract data concerning a total of 678,000 individuals and professionals, including tax data such as reference tax income, family quotient, and withholding tax rate, and, for businesses, data such as their company name and SIREN number.

“Cadastral data relating to addresses and property sizes were also accessed. As soon as these data breaches were identified, the French Public Finances Directorate (DGFIP) notified the French Data Protection Authority (CNIL). The online accounts of individual and professional users were not compromised. User IDs and passwords were not compromised.”

The government added that additional security measures, such as shutting down access to sensitive data systems, were implemented following revelations from ongoing investigations. It also said the full scope and nature of the data extracted and users impacted was being determined.

“The French Public Finances Directorate (DGFiP) will contact each of the individuals and professionals concerned directly starting next week. They will receive individual information by email or letter specifying the data that may have been accessed or extracted and, where applicable, the precautionary measures to take.”

ZeroBytes also hits the education sector

The threat actor continued to go after France, also claiming a breach of the Ministry of National Education (Ministère de l’Éducation nationale), saying they had stolen a partial database containing 346,178,591 lines of total raw data.

The data largely pertains to the Créteil Academy, and totals at around 43 gigabytes and 2,500 files.

“By obtaining VPN access, we were able to extract the database from the Créteil Academy, including an LDAP extraction (with hashed passwords) for Créteil and Versailles, as well as I-Prof,” the threat actor said in a blog post.

The data was based on five different sectors, including the Base Élèves 1er Degré (BE1D), a management system for primary-school students, which saw the data of around 815,000 students allegedly breached, with data including names, titles, dates of birth, school meal details, transport details, childcare data, parents and guardian details and addresses, school history, email addresses and more.

According to a summary, the breach impacted around 800,000 to 2 million primary school students in the Créteil region, over 625,000 middle and high school students nationally, teaching staff, students experiencing difficulty and around 600,000 academic network accounts.

The Ministry of National Education confirmed the incident, saying that it detected the incident on 26 July, a day after the intrusion.

“Within hours, the ministry suspended external access to the affected system and activated a crisis management team. Its technical teams have been working continuously ever since,” the statement said.

“The data that may have been exfiltrated concerns ministry employees who have worked in regional education authorities since 2001. This includes personal identification and professional information – status and job title. For some, this also includes contact details such as postal address and telephone number, as well as social security number. This information system does not contain bank details, passwords, or student data.”

The ministry said it had notified the National Cybersecurity Agency of France (ANSSI) and the National Commission for Information Technology and Civil Liberties (CNIL).

And it doesn’t stop there

Outside of government agencies, ZeroBytes has also targeted private sector organisations, including France’s second-largest telecommunications firm, SFR.

“We gained access to an internal SFR tool called NOVA. After obtaining access, we immediately started scraping customers with a home internet subscription, including their associated mobile account data. However, our activity was detected before we could complete the extraction, preventing us from obtaining the full dataset,” the threat actor said.

According to the listing, 2,104,093 lines of data were stolen, which the threat actor said relates to “data belonging to millions of customers”, based on estimates, as once again, the full data extraction was not completed.

SFR has yet to publicly comment on the incident.

The threat actor also breached two smaller private French companies, including eSports Virtual Arenas (EVA), through which ZeroBytes said they extracted 190,123 records, “including 70k unique email addresses along with IDs, usernames, full names, gender and phone numbers,” as well as birth dates, addresses, and countries.

The other was Bureau Vallée, a French discount retail chain that sells office supplies, computing goods, ink cartridges, and office supplies.

“I’m honestly too lazy to explain everything and make a long post like I do on every post, so I’ll keep it short: we found the access, and honestly it was probably the worst access to scrape,” the threat actor said.

“The API was responding in SECONDS (absolutely awful), and after scraping 55K I stopped because I had something else to do, thinking I’d resume when I woke up. Surprise: when I woke up the next day, the access was gone. So in the end, we only got 55K from an insane access that could’ve given us way more. That’s exactly why we’re giving this away for free.”

The threat actor did not specify what data was included in the post, but linked to the allegedly stolen data. Bureau Vallée has not publicly commented on the incident.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: