zerofox logo
Advisories

ZeroFox Intelligence Flash Report - ZeroBytes Targets French Agencies

|by Alpha Team

banner image

ZeroFox Intelligence Flash Report - ZeroBytes Targets French Agencies

Product Serial: F-2026-08-25a

TLP:CLEAR

In this Flash Report, ZeroFox researchers report on a claimed breach of the French Ministry of Education by threat actor ZeroBytes, who alleges the theft of a 346-million-line database of staff and student records in a July 2026 intrusion.

Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • On August 13, 2026, threat actor “ZeroBytes” posted on the dark web forum PwnForums claiming to have breached France’s Ministry of National Education; several days later, the group reposted the claim on its public X profile.
  • The Ministry of National Education disclosed a breach on July 25, 2026, but claims that no student information, bank details, or passwords were stolen in the breach.
  • This is the largest breach claimed by ZeroBytes and the second French central-government-body victim the group has claimed in under two months.
  • There is a roughly even chance the threat actor maintains access to the data. If ZeroBytes’ claim is legitimate, the group will almost certainly sell that access in addition to the exfiltrated data.
  • ZeroBytes is almost certain to continue targeting French government agencies, and there is a roughly even chance the group will continue using social engineering and credential stuffing to gain ever-increasing levels of access to more secure data.

Tags: tlp:clear dark web data breachthreat actor