
Cybercriminal ZeroBytes claims to have exfiltrated 43 gigabytes of data concerning students, parents and teachers, a perimeter disputed by the ministry.
AI-generated summary
An intrusion into a training system for National Education personnel took place on the night of July 25 following account theft.
43 gigabytes, almost 2,500 files and 346 million lines. Cybercriminal ZeroBytes claims to have exfiltrated a massive amount of data belonging to National Education. The claimed files cover more than twenty years of history and concern students, parents, teachers and administrative staff. These figures must, however, be considered with caution, but the ministry has confirmed an intrusion that occurred on the night of July 25 after the theft of a professional account. On the other hand, he did not validate the extent of the leak claimed by ZeroBytes. We take stock of this new leak which is causing problems a few days before the start of the school year.
Students, teachers and parents in claimed files
According to the hacker, the extraction was carried out using VPN access allowing access to several internal environments. The data would represent exactly 346,178,591 raw, undeduplicated rows, spread across approximately 2,500 files.
Part of it would come from the 1st Degree Student Base, used for the administrative management of children in nursery and primary school. The files could contain identities, dates of birth, addresses, establishments attended, school careers and information on catering, transport or daycare. Links with parents and legal guardians would also be present.
Other extractions would come from SCONET, dedicated to secondary school students, and from systems ensuring individual monitoring of absences, summonses or dropout situations.
Nearly 17.8 GB would also concern I-Prof, the staff career management tool. ZeroBytes uses data from the 33 academies and approximately 4.35 million unique identifiers after partial deduplication. This figure would, however, include current agents, former staff, retirees and histories accumulated since the early 2000s.
Finally, directories linked to the academies of Créteil and Versailles bring together more than 602,000 account entries. Some would contain cryptographic password hashes. These are not plaintext passwords, but these fingerprints can sometimes be exploited when credentials are weak or reused.
A perimeter still contested by the ministry (but can we still believe it?)
The 346 million lines do not correspond to that many victims. The same person can appear in several databases and in many successive records. No reliable estimate of the total number of individuals affected is therefore available.
Above all, the claim goes well beyond the scope currently recognized by National Education. In its press release dated July 31, the ministry indicates that the intrusion targeted a system dedicated to staff training. The data likely to have been stolen concerns agents who have worked in the academy since 2001: identity, status, functions and, for some, address, telephone and social security number.
The ministry specifies that this system does not contain any student data, passwords or banking information. If the files described by ZeroBytes are authentic and indeed come from this attack, this would mean that the hacker reached systems other than the one initially identified.

Matt Hougan de Bitwise prévoit une multiplication par 10 à 100 des transactions blockchain, portée par l'automatisation des agents IA qui effectuent des micro-paiements et des rééquilibrages de portefeuilles en continu, dépassant largement l'usage humain actuel.

La blockchain MANTRA Chain a suspendu l'intégralité de ses transactions et endpoints par mesure de précaution suite à un incident non identifié. Aucun délai de rétablissement n'est annoncé, ravivant les craintes liées à un précédent effondrement en 2025.

La Wyoming Stable Token Commission a migré l'infrastructure cross-chain de son stablecoin FRNT vers Chainlink CCIP, abandonnant LayerZero après un audit de sécurité ayant révélé des lacunes dans la transparence et les pratiques opérationnelles.

L'Ethereum Foundation a lancé Platåberget, un testnet public dédié à la mise à niveau Glamsterdam. Ce réseau, opérationnel depuis le 13 août, testera l'ePBS et l'exécution parallèle des transactions avant un hard fork programmé le 20 août 2026.

SafePal, portefeuille crypto soutenu par Binance, a subi une fuite de données touchant près de 40 000 clients entre mars 2025 et avril 2026 en raison d'une faille dans son plug-in de suivi de commandes.

Près de sept semaines après l'intrusion, le ministère de l'Économie confirme le vol des données fiscales de 678 000 particuliers et professionnels par un pirate informatique, faisant craindre de nouvelles attaques contre les détenteurs de cryptomonnaies.