ZeroFox Intelligence Flash Report - ZeroBytes Targets French Agencies
|by Alpha Team

ZeroFox Intelligence Flash Report - ZeroBytes Targets French Agencies
Product Serial: F-2026-08-25a
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on a claimed breach of the French Ministry of Education by threat actor ZeroBytes, who alleges the theft of a 346-million-line database of staff and student records in a July 2026 intrusion.
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On August 13, 2026, threat actor “ZeroBytes” posted on the dark web forum PwnForums claiming to have breached France’s Ministry of National Education; several days later, the group reposted the claim on its public X profile.
- The Ministry of National Education disclosed a breach on July 25, 2026, but claims that no student information, bank details, or passwords were stolen in the breach.
- This is the largest breach claimed by ZeroBytes and the second French central-government-body victim the group has claimed in under two months.
- There is a roughly even chance the threat actor maintains access to the data. If ZeroBytes’ claim is legitimate, the group will almost certainly sell that access in addition to the exfiltrated data.
- ZeroBytes is almost certain to continue targeting French government agencies, and there is a roughly even chance the group will continue using social engineering and credential stuffing to gain ever-increasing levels of access to more secure data.
Tags: tlp:clear, dark web, data breach, threat actor