SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
▣ Breach FRENCH-EDUCATION-M 2026-08-18

French Ministry of Education: ZeroBytes Claims 43GB Breach of Pupil and Staff Systems

"France's Ministry of National Education has confirmed that data presented as originating from its systems is now circulating online, following a claim posted to a cybercrime forum on the night of 17 August 2026 by the…"

France's Ministry of National Education has confirmed that data presented as originating from its systems is now circulating online, following a claim posted to a cybercrime forum on the night of 17 August 2026 by the actor known as ZeroBytes. The ministry has confirmed the underlying intrusion, which it dates to the night of 25 July 2026, and says it has filed a criminal complaint against persons unknown with the Paris prosecutor's office and notified both ANSSI and the CNIL. What it has pointedly not confirmed is the actor's scale claim: roughly 43GB across about 2,500 files, 346,178,591 raw lines, 1.22 million distinct pupils and 4.35 million staff identifiers. On those figures, and on the central question of whether pupil records are in the set at all, the ministry says only that technical analysis continues to establish "the exact nature and extent of the exfiltrated data." All eight available sources on this incident are press or aggregator reporting; the ministry's own statements reach us secondhand through them.

What Happened

The confirmed baseline comes from the ministry's 31 July statement, reported by franceinfo. A "fraudulent intrusion" occurred during the night of 25 July 2026 following the takeover of a professional account, and targeted the information system dedicated to staff training. The ministry said personal data on a "significant number" of its agents may have been extracted, specifically agents who had served in an academy since 2001, teachers among them. At that point it could not put a number on the affected population and said explicitly that the system in question contained no banking data, no passwords, and no pupil data.

Three weeks later the picture shifted. On 17 August, ZeroBytes published a detailed inventory on a criminal forum, relayed by the specialist site French Breaches, claiming the intrusion as their own and asserting a far wider footprint than the training system alone. Le Figaro quotes the actor taunting the ministry directly: "You had detected me, but you did not cut me off. So I stayed inside, under your eyes." ZeroBytes presents itself as a French duo and is the same handle behind the recent DGFiP tax authority claim and, per Numerama, an earlier Intermarché Drive incident.

The ministry's 18 August update, obtained by Numerama and clicanoo, confirms that data presented as coming from the ministry has been posted online and that all staff potentially affected have now been individually notified. On the pupil claim it neither confirms nor denies. Clicanoo reports the ministry explicitly declining to confirm that all the claimed data corresponds to its systems, meaning the several-hundred-million-line volume is not a validated figure. Selectra frames the same tension more bluntly, noting the ministry has maintained since 31 July that no pupil data was involved while the actor now claims exactly that. Le Monde, cited via ZDNet, reviewed a sample of the leaked data and found records that appear to belong to pupils, but was not able to authenticate all of them. Accounts genuinely differ here, and the gap has not closed.

What Was Taken

Two tiers of information exist, and they should not be conflated.

The ministry-confirmed tier, from the 31 July statement: identity elements and professional information including status and functions, plus, for a portion of those affected, contact details, postal address, telephone number, and social security number. No banking data, no passwords, no pupil data.

The actor-claimed tier, reported consistently across Brussels Signal, Numerama, Le Figaro, Frandroid, ZDNet, and Selectra but confirmed by nobody: approximately 43GB, about 2,500 files, and 346,178,591 raw lines by ZeroBytes' own count, spanning more than two decades. After deduplication the actor claims 1,224,291 distinct pupils (Selectra's precise figure; other outlets round to 1.22 million), 4,350,358 staff identifiers, and around 602,000 academic network accounts, which Selectra reports include password hashes. Selectra also reports the data spans 33 academies and that thirteen database samples were published as proof.

Named systems in the claimed inventory, per Frandroid and Selectra: the Créteil academy set is the largest single lot at 24GB across 1,581 files, I-Prof (teacher administrative management) at 17.8GB across more than 1,000 files, BE1D and SCONET exports covering primary and secondary pupils, MGI/PELV2, two LDAP directories, and the livret scolaire holding grades and evaluations. Selectra notes that the credibility of the claim rests substantially on the fact that the system names cited are the ones French teachers actually recognise.

One important caveat from the actor themselves, flagged by Brussels Signal: the 4.35 million staff figure covers administrative employees, former agents and pensioners alongside serving teachers, so it is not a headcount of the current workforce.

Why It Matters

If the pupil claim holds, this is a breach whose primary victims are minors, with school records, disciplinary data and parental contact information attached to them. That is a category of exposure with no expiry date. A compromised adult can change a phone number; a nine-year-old whose identity, address, guardian details and academic history are now in a criminal dataset carries that exposure into adulthood. Notification obligations flow to legal representatives rather than the data subjects, and the ministry has said such notification would follow if the analysis confirms pupil involvement.

The second-order risk is the combination effect. Frandroid notes DGFiP has acknowledged the theft of data on 678,000 taxpayers, including tax number, reference income, family quotient and withholding rate, serious enough that Sébastien Lecornu convened a crisis cell. The same actor now claims both datasets. Cross-referenced tax records and education records give an unusually complete picture of a French household, and the presence of social security numbers on the education side makes targeted fraud and identity theft materially easier than either set alone would allow.

Third, this is a pattern, not an outlier. Frandroid characterises it as the third data leak at the ministry in 2026. A ministry taking three hits in a year with the same class of entry point is describing an identity and access management problem, not a run of bad luck.

The Attack Technique

The two accounts of initial access do not match, and this matters for defenders trying to draw the right lesson.

The ministry, per franceinfo, attributes the 25 July access to the usurpation of a professional account, with the staff training information system as the target. Frandroid notes this mirrors the DGFiP case exactly, where the tax administration also confirmed intrusion following the compromise of an agent's credentials. Same actor, same pattern, same class of entry point.

ZeroBytes, via French Breaches and reported by Brussels Signal, Numerama and Le Figaro, instead attributes initial access to VPN access into the ministry's internal networks, which the actor says opened the way to three large databases. Selectra adds a further discrepancy: the actor dates the intrusion to 15 July, ten days before the ministry's 25 July timestamp.

These are reconcilable but not reconciled. A stolen staff credential used to authenticate to a VPN would satisfy both descriptions, and the date gap would be consistent with the ministry detecting a later stage of an intrusion that began earlier, which is precisely what the actor's "you detected me but did not cut me off" boast asserts. That reading is inference, not established fact. What is established is that no source alleges exploitation of a software vulnerability. This was an access problem.

What Organizations Should Do

Treat detection without eviction as an open incident. The actor's central claim is persistence after being spotted. When an alert fires on an account, terminate every active session and refresh tokens for that identity rather than only resetting the password, and verify the intruder is actually gone before closing the ticket.

Enforce phishing-resistant MFA on remote access, without exception. Both this incident and the DGFiP case trace back to a compromised staff account. Prioritise VPN, remote desktop and federated SSO endpoints, and audit for accounts holding broad data access that are still exempt.

Inventory what a single training or administrative account can actually reach. The ministry initially scoped this to one training system; the claimed data touches I-Prof, SCONET, BE1D, LDAP directories and the livret scolaire. Map lateral reach from lower-tier systems into pupil and HR databases, and segment accordingly.

Alert on bulk read and export volume, not just on login anomalies. Extraction on the claimed scale, hundreds of millions of rows across thousands of files, should be visible in query and egress telemetry well before it appears on a forum. Baseline normal export sizes per role and alert on multiples of it.

Purge and archive historical records outside live systems. Data reaching back to 2001, covering pensioners and former agents, sat in a production-reachable store. Every year of retention beyond legal necessity is breach surface with no operational value.

Prepare minor-specific notification and fraud guidance in advance. If pupil data is involved, notifications go to legal representatives and the exposure is lifelong. Have the workflow, the templates and the guardian-facing guidance ready before you need them, and warn affected populations about the phishing wave that reliably follows a leak of this profile.

Sources: Cybercriminal claims massive data breach at French education minist... | Piratage de l'Éducation nationale : ce que ZeroBytes revendique, ce... | Élèves, enseignants, parents... Après le fisc, ZeroBytes revendique... | Piratage de l'Éducation nationale : une fuite de données expose 1,2... | Fuite de données : l’Éducation nationale dans le viseur du désorm ... | Potentiel vol de données personnelles d'un "nombre important" d'age... | Après le fisc, l'école : les données de 1,2 million d'élèves seraie... | Éducation nationale : le ministère confirme la fuite de données et...