ZeroBytes is a French-speaking cybercriminal group active since at least July 2026. It has claimed intrusions targeting French public-sector organizations, educational institutions, and private companies. French authorities arrested an adult suspected member and a second minor suspect during an investigation into the group’s activity; the adult suspect was placed in pretrial detention. French media has associated the adult suspect with the online alias ChatNoir. ZeroBytes claimed responsibility for a confirmed breach of France’s Directorate General of Public Finances (DGFiP). French authorities established that attackers used compromised credentials belonging to a DGFiP employee and an authorized third party to access internal systems during June and July 2026, consult data, and extract tax, business, and cadastral information affecting approximately 678,000 individuals and professionals. The group advertised alleged stolen data for sale in cybercrime forums and stated that exfiltrated files had been sold, consistent with a financially motivated data-theft operation. The group has also claimed attacks against the French Ministry of National Education, France Travail, a government housing-data service, and other French entities. Several of these additional claims, including the asserted scope of allegedly exfiltrated data and technical access details, have not been independently verified. Reported intrusion activity centers on abuse of legitimate or compromised accounts, including alleged MFA bypasses, followed by access to internal data resources and data exfiltration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Allegedly conducted intrusions against France's DGFiP using compromised state-agent accounts, resulting in the theft of personal data concerning 678,000 individuals and professionals.
Suspected of participating in the cyberattack against France’s Directorate-General for Public Finance (DGFiP), which exposed sensitive and personal data of an estimated 350,000 to 678,000 taxpayers.
Conducting unauthorized-access and data-theft attacks against French public-sector entities and private organizations. The group claimed to have exfiltrated personal and tax-related data on more than 600,000 individuals from DGFiP and is suspected of targeting educational institutions, an employment agency, a telecom operator, a retailer, and a sports federation.
Claimed responsibility for the compromise of France's DGFiP, reportedly exposing data belonging to more than 678,000 individuals and organizations. The group also claimed attacks against the French Ministry of Education and France Travail. The reported DGFiP intrusion relied on compromised internal accounts with overly broad permissions rather than an advanced technical exploit.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.