French Ministry of National Education Hit by Massive Data Breach, 43GB of Sensitive Records Allegedly Stolen
A cybercriminal operating under the alias ZeroBytes has claimed responsibility for a large-scale breach of France’s Ministry of National Education, alleging the theft of 43GB of data containing records on millions of pupils, staff, and academic accounts spanning over two decades. The claim surfaced on a cybercrime forum on August 17, just weeks after the same threat actor targeted France’s tax authority (DGFiP), exposing data on 678,000 taxpayers.
According to ZeroBytes, the stolen education data includes 346 million raw records across 2,500 files, with deduplicated figures estimating 1.22 million distinct pupils (many minors), 4.35 million staff identifiers, and 602,000 academic network accounts. The compromised data encompasses identity details, dates of birth, social security numbers, addresses, school histories, parental/guardian information, and professional records including staff assignments, contracts, and civil service ranks. Some files also contain hashed passwords.
The breach reportedly originated from VPN access, granting the attacker entry to three key databases:
- Créteil academy systems (24GB, 1,581 files), some with national scope.
- I-Prof, the career management tool for ministry personnel (17.8GB), containing 4.35 million staff identifiers across France’s 33 academies.
- Directories of Créteil and Versailles academies (1.6GB).
Additional files include pupil monitoring records from the Créteil academy, tracking at-risk students from the 2020-2021 to 2025-2026 school years, as well as data from Base Élèves 1er Degré (primary school registers), SCONET (secondary school systems), and SCHAAF (federated academic directories). Records date from the early 2000s through July 2026.
The Ministry of National Education confirmed a cyber intrusion on July 31, stating that a fraudulent takeover of a professional account on July 25 targeted a system used for staff training. While the ministry initially reported that only staff data since 2001 was exposed excluding bank details, passwords, or pupil records ZeroBytes’ claims suggest a far broader scope, including pupil data and password hashes.
In response, the ministry suspended external access, activated a crisis team, and filed a complaint, notifying France’s ANSSI (cybersecurity agency) and CNIL (data protection authority). Investigations are ongoing, with checks extended across all ministry systems to prevent further spread. The ministry has pledged to inform affected individuals but has not yet publicly verified ZeroBytes’ full claims.
Cybersecurity observers note that the breach’s sensitivity is heightened by the inclusion of parent-child links, raising risks of phishing, identity fraud, and targeted attacks. The incident follows a series of cyberattacks on French education systems in 2026, including a March breach of the Compas HR platform (exposing 243,000 staff) and an April compromise of ÉduConnect pupil accounts.
ZeroBytes has also taunted authorities, claiming to have remained undetected inside systems despite the ministry’s response. Meanwhile, the DGFiP tax authority breach also attributed to the same actor prompted an interministerial crisis meeting led by French Prime Minister Sébastien Lecornu, with officials describing the attack as unprecedented in sophistication. Investigations into both incidents continue.
French Ministry of National Education TPRM report: https://www.rankiteo.com/company/ministère-de-l-education
Compas HR platform TPRM report: https://www.rankiteo.com/company/compass-group-france-holdings-sas
"id": "mincom1787049734",
"linkid": "ministère-de-l-education, compass-group-france-holdings-sas",
"type": "Breach",
"date": "7/2026",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '1.22 million distinct pupils, '
'4.35 million staff identifiers, '
'602,000 academic network '
'accounts',
'industry': 'Education',
'location': 'France',
'name': 'French Ministry of National Education',
'size': 'Large (national scope)',
'type': 'Government Ministry'}],
'attack_vector': 'VPN access, fraudulent takeover of a professional account',
'customer_advisories': 'Ministry pledged to inform affected individuals',
'data_breach': {'data_encryption': 'Partial (hashed passwords)',
'data_exfiltration': 'Yes (43GB stolen)',
'number_of_records_exposed': '346 million raw records (1.22 '
'million distinct pupils, 4.35 '
'million staff identifiers)',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High (personally identifiable '
"information, minors' data, "
'parent-child links)',
'type_of_data_compromised': ['Identity details',
'Dates of birth',
'Social security numbers',
'Addresses',
'School histories',
'Parental/guardian information',
'Professional records (staff '
'assignments, contracts, civil '
'service ranks)',
'Hashed passwords']},
'date_detected': '2024-07-25',
'date_publicly_disclosed': '2024-08-17',
'description': 'A cybercriminal operating under the alias *ZeroBytes* has '
'claimed responsibility for a large-scale breach of France’s '
'Ministry of National Education, alleging the theft of 43GB of '
'data containing records on millions of pupils, staff, and '
'academic accounts spanning over two decades.',
'impact': {'brand_reputation_impact': 'Heightened risks of phishing, identity '
'fraud, and targeted attacks',
'data_compromised': '43GB of sensitive records',
'identity_theft_risk': 'High (social security numbers, addresses, '
'parental/guardian information)',
'operational_impact': 'Suspended external access, crisis team '
'activated',
'payment_information_risk': 'None (bank details not exposed)',
'systems_affected': 'Créteil academy systems, I-Prof, directories '
'of Créteil and Versailles academies, Base '
'Élèves 1er Degré, SCONET, SCHAAF'},
'initial_access_broker': {'entry_point': 'Fraudulent takeover of a '
'professional account'},
'investigation_status': 'Ongoing',
'post_incident_analysis': {'root_causes': 'Fraudulent account takeover, VPN '
'access vulnerabilities'},
'ransomware': {'data_exfiltration': 'Yes'},
'references': [{'date_accessed': '2024-08-17',
'source': 'Cybercrime forum post by ZeroBytes'}],
'regulatory_compliance': {'regulations_violated': ['GDPR'],
'regulatory_notifications': 'Notified CNIL (French '
'data protection '
'authority)'},
'response': {'communication_strategy': 'Notified ANSSI and CNIL, pledged to '
'inform affected individuals',
'containment_measures': 'Suspended external access, checks '
'across all ministry systems',
'incident_response_plan_activated': 'Yes',
'law_enforcement_notified': 'Yes (complaint filed)'},
'stakeholder_advisories': 'Interministerial crisis meeting led by French '
'Prime Minister Sébastien Lecornu',
'threat_actor': 'ZeroBytes',
'title': 'French Ministry of National Education Hit by Massive Data Breach',
'type': 'Data Breach'}