The ZeroBytes group has claimed it stole roughly 43 GB of data from France’s Ministry of National Education and is offering part of the alleged haul for sale on a cybercrime forum. Reporting on the listing says the dataset purportedly contains 346,178,591 raw lines of data, including school system exports, staff exports from 33 academies, and two LDAP directory dumps with network account names and hashed passwords. The claimed records reportedly map to about 4.35 million staff identifiers and 1.22 million students after deduplication, with potentially sensitive information including names, addresses, school records, administrative data, and monitoring records tied to vulnerable or at-risk students.
French authorities have not confirmed the full scope of the breach, and the sale claim remains unverified because no sample data was publicly released. The ministry said it is still conducting technical analysis, but the incident appears connected to a late-July intrusion in which attackers accessed employee data through a compromised professional account before access was detected and blocked on July 26. The ministry has filed a complaint and is coordinating with CNIL and ANSSI on response and security reinforcement, while the alleged LDAP dumps raise concern that offline cracking of password hashes could enable continued unauthorized access if affected credentials remain valid.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
On August 17, 2026, a sale listing attributed to ZeroBytes was observed offering a partial database allegedly taken from the French Ministry of Education. The post claimed 346,178,591 raw lines of data, including records tied to 4,350,358 staff identifiers and 1,224,291 students, though the claim remained unverified.
The French Ministry of National Education said the unauthorized access tied to the earlier intrusion was identified and blocked on July 26, 2026. The ministry later said it filed a complaint and began working with CNIL and ANSSI on security reinforcement measures.
The French Ministry of National Education dated an earlier intrusion to the night of July 25, 2026, saying attackers gained access by impersonating or misusing a professional account. The compromised system exposed professional and personal data relating to ministry employees, including data dating back to 2001.
A threat actor using the alias ZeroBytes claimed to have breached Éducation Nationale and dated the intrusion to July 15, 2026. The actor said the stolen data included school system exports, staff exports from 33 academies, and two LDAP directory dumps with account names and hashed passwords.
At the end of July 2026, the administration reported an intrusion in its systems affecting a significant number of ministry agents. It said at the time that the compromised system did not contain banking data, passwords, or student-related data.
Following ZeroBytes' claim of stealing 43 GB of ministry data, the French Ministry of National Education said it was conducting technical analysis to determine the exact nature and extent of any exfiltrated data. The ministry said it would notify affected individuals, or legal guardians for students, if the leak is confirmed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.