Hackers took a lot of data from the French education ministry. (Anastassia Anufrieva - UnSplash)

Bureaucracy From the capitals

Cybercriminal claims massive data breach at French education ministry

4 minutes read

The Ministry of National Education confirmed in a statement on July 31 that it had suffered a fraudulent intrusion on the night of July 25.

A cybercriminal known as ZeroBytes has claimed responsibility for a large-scale breach of systems linked to France’s Ministry of National Education, alleging the theft of around 43 gigabytes of data covering millions of pupils, staff and related records spanning more than two decades. The claim appeared on a cybercrime forum on the night of August 17.

The actor, who recently claimed a separate intrusion into the French tax authority (Directorate General of Public Finances, DGFiP) that affected hundreds of thousands of taxpayers, stated that the education data comprises approximately 346 million raw lines, or 346,178,591 by his own count, across roughly 2,500 files.

Deduplicated figures cited in reports put the exposure at about 1.22 million distinct pupils (many of them minors), 4.35 million staff identifiers and around 602,000 academic network accounts. ZeroBytes has cautioned that the staff figure covers administrative employees, former agents and pensioners as well as serving teachers.

According to the specialised website French Breaches, ZeroBytes managed to break into the ministry’s internal networks via VPN access, which would have opened the doors to three large databases: systems of the Créteil academy, some of which are national in scope (24GB across 1,581 files), nearly 4.35 million staff identifiers of the 33 academies, France’s regional education authorities in mainland France and overseas, stored in I-Prof (17.8GB) and the directories of Créteil and Versailles (1.6GB).

Data allegedly obtained ranges from identity details, dates of birth and social security numbers to addresses, contact information, school histories, parental or guardian details, professional records for staff (including assignments, contracts and civil service rank), and in some cases hashed passwords.

The files are said to come from Base Élèves 1er Degré, the primary school pupil register, the secondary school system SCONET, the federated academic directory SCHAAF and I-Prof, the career management tool for ministry personnel.

A further set of databases is said to cover the individual monitoring of pupils in difficulty or at risk of dropping out in the Créteil academy, running from the 2020-2021 school year to 2025-2026.

Records are said to date from the early 2000s through to July 2026.

The Ministry of National Education confirmed in a statement on July 31 that it had suffered a fraudulent intrusion on the night of July 25.

Officials said the attack followed the takeover of a professional account and targeted an information system used for staff training. The ministry’s information systems security operations centre was alerted the following day.

They stated that data potentially exfiltrated concerned ministry agents who had worked in regional education authorities since 2001.

The ministry emphasised that the specific system involved did not contain bank details, passwords or pupil data. That perimeter is narrower than the one now claimed by ZeroBytes, which extends to pupil registers and to password hashes drawn from academic directories.

External access was suspended, a crisis team activated and a complaint filed, with the national information systems security agency (ANSSI) and the data protection authority (CNIL) notified. The ministry said checks had been extended across all its information systems to prevent the incident spreading and that those potentially affected would be informed as soon as possible.

As of August 18, the ministry had not issued a detailed public response confirming or denying the full scope of the latest ZeroBytes claims, which go beyond the staff-focused system described in the July statement. In that statement it said it had been working for several months to strengthen the security of its information systems.

Specialist sites and cybersecurity observers have noted the claims remain partially unverified pending independent assessment. French Breaches reported that ZeroBytes had responded to the publicity by claiming he had been detected without his access being cut off, allowing him to remain inside the systems.

The incident forms part of a series of cybersecurity problems affecting French public education systems in 2026.

Earlier breaches included an attack on the Compas human resources platform in March that exposed data on approximately 243,000 staff and trainees, and a separate incident involving pupil accounts linked to ÉduConnect disclosed in April.

The same actor’s claimed tax authority breach prompted a crisis cell convened by the French Prime Minister, Sébastien Lecornu, who chaired an interministerial meeting on August 17. The DGFiP has put the number of individuals and businesses affected at 678,000, while its director general, Amélie Verdier, described the operation as more sophisticated than anything the tax administration had previously faced.

Security experts have highlighted the risks of phishing, identity fraud and further intrusions arising from the combination of personal, professional and, if confirmed, pupil records. The presence of files linking pupils to their parents or legal guardians has been identified as among the most sensitive aspects of the claim.

Affected individuals have been advised by the ministry to monitor for suspicious communications and strengthen account security where possible. It said it never asked staff for login details, passwords or bank details by email, telephone or message. Investigations by French authorities continue.

Key Topics

More like this

From the capitals

Nearly 700,000 French taxpayers’ data stolen in cyberattack on tax authority

By Carl Deconinck

Culture war

Cambridge college issues content warning for Little Red Riding Hood over ‘themes of violence’

By Carl Deconinck

TikTok was fined 530 million euros ($600 million) by its lead EU privacy regulator on May 2 over concerns on how it protects user information and was ordered to suspend data transfers to China if its processing is not brought into compliance within six months. (Photo by Chesnot/Getty Images)
News

TikTok fined €530 million by EU regulator over data protection

By Reuters

Politics

French government refuses to publish results of mandatory drug tests on ministers and civil servants

By Carl Deconinck