French police arrested an 18-year-old suspected member of the ZeroBytes hacking collective, known online as “ChatNoir,” in connection with the compromise of France’s Directorate General of Public Finances (DGFiP). Prosecutors said the suspect was arrested on August 18, formally placed under investigation on August 20, and remanded in pretrial detention. A second suspect, younger than 16, was questioned and released; investigators retained that person’s computer equipment for forensic examination.
The DGFiP breach exposed data on more than 678,000 individuals and businesses. Investigators believe the intrusion relied on impersonating internal staff accounts with excessive permissions rather than exploiting a technical vulnerability. DGFiP is urgently deploying USB security tokens to strengthen multifactor authentication as authorities pursue other possible ZeroBytes members. More than 1,200 affected people have joined a GDPR damages action.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
The Paris prosecutor's office publicly disclosed the case involving the suspected ZeroBytes member and the DGFiP data-theft investigation.
Authorities detained and questioned a second suspect under age 16, then released the minor while retaining computer equipment for forensic examination. Authorities did not identify the minor as a ZeroBytes member.
The 18-year-old suspect was formally placed under investigation for organized unauthorized access, data modification/extraction/transmission, and criminal association offenses connected to the DGFiP case. He was remanded in pretrial detention.
French police arrested an 18-year-old Paris-region suspect on suspicion of affiliation with ZeroBytes. French media identified the suspect's online alias as “ChatNoir”; he was already under judicial supervision and had previously faced two formal investigations for alleged cyberattacks committed as a minor.
A coordinated GDPR-based compensation action brought together more than 1,200 people affected by the DGFiP compromise, seeking damages from the French state for moral harm and identity-theft prevention costs.
DGFiP began urgently deploying USB tokens to strengthen multifactor authentication for its agents following the account-compromise incident.
A compromise of a critical French Directorate General of Public Finances (DGFiP) database exposed data relating to more than 678,000 individuals and professionals. DGFiP said the intrusion relied on impersonated internal accounts with overly broad permissions rather than a technical exploit.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.