
AI-generated summary
The Paris prosecutor's office confirmed this Friday, September 4, the indictment and placement in pre-trial detention of a man suspected of belonging to the ZeroBytes hacker group, the claimed author of the massive hacking of the DGFiP this summer. A second suspect, a minor under 16 years old, was released after his custody.
A second release... A teenager who has become an adult in the meantime, an administration once again caught at fault, and a lead which ultimately leads to a name. The Paris prosecutor's office confirmed this Friday, September 4, the indictment and placement in pre-trial detention of a man suspected of belonging to the ZeroBytes hacker group, the claimed author of the massive hacking of the DGFiP this summer. A second suspect, a minor under 16 years old, was released after his custody. Here is what we know about this legal progress, and why it directly concerns cryptocurrency holders.
ZeroBytes, an 18-year-old suspect, not unknown to the justice system
The main person concerned is 18 years old. This is all that the Paris prosecutor's office has delivered on its identity in the elements relayed by BFMTV.
Furthermore, two files are already weighing on his locker:
a first indictment in June 2024,
a second in January 2025.
Both for acts of piracy committed when he was still a minor. At barely 18 years old, he would already be on his third affair. Rare speed, or a sign that justice had simply never let him go.
A pseudonym is already circulating on the sidelines of the investigation, ChatNoir. According to information from Seb Latombe (@seblatombe), cybersecurity journalist and above all founder of FrenchBreaches, the suspect would be a face already known in the small world of French-speaking hacking, presumed co-founder of the Epsilon collective. Already in March 2024, a group claiming to be from Epsilon, with among its members a certain ChatNoir, had hijacked the BFMTV and RMC X accounts to broadcast their own messages. If the link is confirmed, the teenager would indeed have multiplied the targets well before attacking the tax authorities.
The second suspect arrested is under 16 years old. Released after his custody, he is not exonerated yet. His computers remain in the hands of investigators, who intend to examine their contents.
A leak of 678,000 files, blessing for crypto robbers
It all started with two intrusions, at the end of June then at the end of July, which the DGFiP ended up admitting on August 13. Rather artisanal method on paper: usurping an agent's access, then sucking up in bursts what the internal search tool wants to deliver. The loot is not at all, artisanal. 678,000 individuals and professionals are there, with names, dates of birth, addresses, reference tax income and withholding tax rate.
Spotting a wealthy target becomes child's play with this kind of file in hand. However, France already concentrates the majority of wrench attacks recorded in the world, these attacks where the victim is forced under threat to transfer their cryptocurrencies. A taxman who knows who has money and where they live becomes, in this specific context, a weapon. ZeroBytes also claims to have a second base, cadastral this time, covering several million people. The DGFiP has neither confirmed nor denied it.
“Taxes were just the beginning,” warns ZeroBytes
Two pirates, no political banner, greed as their only standard. Asked about their motivations, the duo cite money and, just as frankly, a taste for power. Before attacking the tax authorities, ZeroBytes had already claimed responsibility for attacks against Intermarché and the French Handball Federation. The group also says it got its hands on data from a major telephone operator and a hotel group this summer, without these companies having confirmed anything yet.
Part of the tax loot has even already changed hands. The group claims, in comments reported by AFP, to have sold files to two buyers for several thousand euros, with the idea that the same database can be resold as many times as there are customers. ZeroBytes warned about X, bluntly: taxes were just an appetizer.
AI outlook — possibilities, not facts
New arrests could come in the investigation into the ZeroBytes group as investigators analyze seized computers.
Likely · Within weeks
The DGFiP could be required to strengthen its internal security protocols after this admission of hacking.
Possible · Within months

Berlin refused to pay a ransom of 30 bitcoins to the Rhysida group after a computer hack. In retaliation, hackers published 1.4 million confidential files on the dark web, exposing sensitive personal and administrative data.

In Vern-sur-Seiche, attackers kidnapped and assaulted a family, thinking they were targeting the owner of the house, a cryptocurrency holder who was absent from the premises. An investigation is underway by the Rennes Research Section.

In San Francisco, former Google engineer Linwei Ding was sentenced to 12 months in prison for the theft of 1,255 confidential documents on AI. The judge dropped the economic espionage charges due to lack of evidence of a direct link with Beijing.

Ukrainian police and the SBU have dismantled a network of fake crypto investment platforms based in kyiv. Led by a 25-year-old computer scientist, the group defrauded 62 victims in more than 20 countries, generating up to $1 million a month.

Gwangju police arrested four Uzbek nationals in April suspected of financing the terrorist group Katibat Tawhid wal Jihad by sending 4,267 USDT in seven transfers between August 2024 and April 2025. The alleged ringleader received cryptocurrencies from the group, converted them into eleven used cars and two excavators shipped to Syria, and is now in pre-trial detention in court. The other three are being prosecuted without incarceration. The investigation is based on South Korea's anti-terrorist financing law and the travel rule, while the suspects claim that the money was used to support family needs.

A fraudulent site imitating a GTA 6 fan page is offering a “leaked” copy of the game to steal cryptocurrencies. The site uses a “wallet drainer” to siphon assets from users connecting their digital wallet.