Who is ZeroBytes
ZeroBytes is the alias of a hacker who has, since August 12, 2026, claimed a series of intrusions into French systems. They present themselves as a duo, with no stated motivation beyond money: "Money is the main motivation," according to their own words as reported by specialist media. Their real identity is not publicly known.
Timeline
The third leak: vacant-succession records
On August 18, 2026, the DGFiP announced a third leak within a week — this time on the vacant-succession portal, the public service that lets any creditor of a deceased person check whether they should turn to an heir. Unlike the first two episodes, this flaw is not claimed by ZeroBytes: it was independently identified by security researcher LunarisSec, and reported by FrenchBreaches.
⚖️What was exposed
Identities, postal and email addresses, dates and places of death, marital status, and inheritance- and estate-related information — sensitive data that, combined, lets someone precisely target a person in mourning, a moment when vigilance against scams is particularly low.
Source: FrenchBreaches, 08/18/2026. Accessed 08/18/2026.🔓The flaw itself
A vulnerability allegedly allowed access to certain information without prior authentication — meaning no account or credentials were needed, unlike the service's normal operation. The flaw has since been fixed.
Source: FrenchBreaches (citing researcher LunarisSec), 08/18/2026.The other claimed targets
The DGFiP is not the only organization named by ZeroBytes. Other French targets were named in the same wave of claims, in mid-August 2026 — without public confirmation from the organizations concerned at the time of writing, and without the level of technical detail provided for the DGFiP attack.
🛒Intermarché Drive
ZeroBytes claims an intrusion targeting the Intermarché Drive online ordering service. No data volume or precise intrusion date has been made public by the hacker or by Intermarché; the retailer has not publicly confirmed an incident to date.
Source: FrenchBreaches, 08/15/2026 (claim reported, unconfirmed).🤾French Handball Federation — updated 08/21
Correction, August 21: when this case file was first written, the FFHandball had not confirmed an intrusion. Since then, the federation has confirmed detecting unauthorized access to Gest'Hand, its federal licence-management software, on August 10, 2026. The CNIL was notified, ANSSI alerted, and access to the software temporarily suspended. What FFHandball confirms is the unauthorized access — not the volume. The claimed 1.36 million rows and 311,000 documents (ID cards, passports, medical certificates) remain the hacker's own claim; the federation says the exact scope is still under evaluation. FFHandball's official statement names no attacking group — the ZeroBytes attribution comes solely from the hacker's own forum signature.
Source: FFHandball statement, 08/10-21/2026; FrenchBreaches, 08/15/2026 (volume claim, unconfirmed).🏕️Sport 2000 — added 08/21
On August 19, 2026, ZeroBytes claims a new target: Sport 2000's internal booking tool, "Pilot," with 17,851 reservations extracted (identities, addresses, emails, phone numbers, trip details and amounts). The hacker claims to still hold active, undetected access at the time of publication. Sport 2000 has not publicly confirmed the incident as of writing — like Intermarché, EVA and handball, this is a claim not independently verified.
Source: FrenchBreaches, 08/19-20/2026 (claim reported, unconfirmed).🎓Éducation nationale — added 08/21
On August 18, 2026, a claimant using the name ZeroBytes put up for sale on a criminal forum what they present as part of the database of France's Ministry of Education: 346,178,591 raw rows, spread across roughly 2,500 files and 43GB, covering a period of more than twenty years (some records date back to 2002-2005). FrenchBreaches derives a count of 1.22 million identified students, 4.35 million staff identifiers, and roughly 602,000 accounts with password hashes. In late July 2026, the ministry had confirmed a fraudulent intrusion into one of its information systems, acknowledging that access could have led to the exfiltration of personal data — without confirming the claimed volume. The 346 million rows do not correspond to that many victims: the same person can appear across multiple databases and successive records.
Source: Cyberattaque.org, FrenchBreaches, CNEWS, 08/18-21/2026 (intrusion confirmed by the ministry in late July; claimed volume, unconfirmed).📇EVA
A third target, named "EVA" in the hacker's claim, rounds out the list. The exact context of this target (sector, nature of the data) is not specified in the sources available at the time of writing.
Source: FrenchBreaches, 08/15/2026 (claim reported, unconfirmed).How access was obtained
According to the hacker's own account — not independently verified — initial access relied on a combination of human error and exploited flaws, with multi-factor authentication bypassed. The DGFiP, for its part, describes impersonated staff credentials that allowed a connection to an internal lookup tool. Once access was obtained, extraction was reportedly partly automated, ahead of an attempted resale to buyers on a specialist forum.
Why this case matters to you
Unlike the Lazarus case (see related dossier below), which mostly targets crypto-asset platforms, a leak like this one directly exposes the identity and tax situation of hundreds of thousands of French residents. This kind of data then fuels far more convincing phishing campaigns: a text or call that cites your correct tax number or correct address passes for legitimate far more easily.
Frequently asked questions
Who is ZeroBytes?
A hacker operating under this alias, presenting themselves as a duo with no particular motivation other than money. Their real identity is not publicly known.
Which ZeroBytes attacks are confirmed, and which are only claimed?
Two DGFiP breaches are now officially confirmed by the administration: 678,000 individuals and businesses for the first intrusion, and 1.8 million accounts for the land registry batch — a figure distinct from the one claimed by ZeroBytes (roughly 2 million property owners). The other claims — the Ministry of Education (346 million rows claimed, but only the intrusion itself is confirmed by the ministry), plus Intermarché Drive, EVA and the French handball federation — remain the hacker's own statements, not confirmed in volume by the targeted organizations at the time of writing.
Is the third leak, on inheritance records, linked to ZeroBytes?
No. This flaw, revealed on August 18, 2026, was independently identified by security researcher LunarisSec and reported by FrenchBreaches — with no established link to the hacker ZeroBytes. It concerns the public vacant-succession portal, where a missing authentication check allegedly allowed access to several million rows of data without a password. The DGFiP confirmed the incident while publicly downplaying it as lesser in scale.
What does this have to do with the scams an ordinary person receives?
A direct one: stolen data (identity, address, tax situation) later fuels far more convincing phishing and impersonation campaigns, by text, call or messaging app, posing as the tax authority or a bank.
Go further
Egidio — The Threat Laboratory, "ZeroBytes: what we know about the hacker behind France's tax breach", egidio.app/en/laboratoire/zerobytes-france-tax-breach/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.