Education

Hackers claim theft of education data affecting millions in France, ministry systems breached

A cybercriminal known as ZeroBytes says it accessed internal networks tied to France’s education ministry and extracted roughly 43GB of records spanning decades, including personal details for millions of pupils and staff.

Hackers claim theft of education data affecting millions in France, ministry systems breached
©Illustration AI Fatima Haddad / we-news.com

A cybercriminal using the name ZeroBytes has claimed responsibility for a substantial intrusion into networks associated with France’s ministry that oversees schools, alleging the theft of roughly 43 gigabytes of education-related data covering millions of pupils and education employees.

Scope of the alleged breach

Posting on a cybercrime forum on the night of Aug. 17, the actor said the haul comprised about 346 million raw lines of data across roughly 2,500 files. Security-focused reporting that examined the material described deduplicated figures of about 1.22 million distinct pupils, approximately 4.35 million staff identifiers and near 602,000 academic network accounts.

According to investigations reported by specialised outlets, the attacker claimed to have gained access via a virtual private network (VPN) that exposed at least three large collections of records linked to regional academic directorates and national personnel systems.

"ZeroBytes has cautioned that the staff figure covers administrative employees, former agents and pensioners as well as serving teachers."

Types of data reportedly exposed

Files said to be included in the cache originate from multiple school and personnel systems used in France. The data allegedly spans identity information such as dates of birth and social security numbers, contact details and addresses, school enrolment histories and parental or guardian information. Personnel records reportedly include assignment histories, contracts and civil-service rank; in some files, hashed passwords were also present.

  • Primary school register records were said to be among the sources.
  • Secondary school administrative systems and federated academic directories were also cited.
  • Career management tools for ministry staff were named as a further repository.

Where the data allegedly came from

Reports indicate three principal datasets were exposed after the VPN compromise: systems tied to the Créteil academy (characterised as partially national in scope), a personnel database known as I-Prof that covers teaching and administrative careers across academies, and directory data from the Créteil and Versailles academic authorities. The files were reported in sizes of about 24GB for the Créteil-related collection, 17.8GB for I-Prof, and roughly 1.6GB for the directories.

Source Approx. size
Créteil systems 24 GB
I-Prof (personnel) 17.8 GB
Créteil & Versailles directories 1.6 GB

Potential impact and unanswered questions

If confirmed, the breach would place at risk sensitive personal data for large numbers of children, current and former ministry employees, and academic account holders. The presence of records related to pupils considered at risk of educational difficulty in at least one regional database raises additional safeguarding concerns.

Officials have not publicly verified the claims in the reporting examined here. The actor who posted the materials also recently asserted responsibility for an intrusion into France’s tax authority, a separate incident that reportedly affected hundreds of thousands of taxpayers.

At this stage, details remain limited to the actor's forum post and reporting by specialist observers who analysed the leaked files. There has been no widely circulated official statement in the sources reviewed for this story confirming the breadth of the data taken or outlining steps being taken to notify affected individuals.

What schools, families and staff need to watch for

For educators and parents, the immediate priorities would typically include verifying any official communications from ministries or local academies, monitoring for unusual account activity tied to school platforms, and following guidance on identity protection should personal identifiers be exposed. Education authorities commonly move to assess the extent of access, secure compromised systems, and notify those affected if personal information has been confirmed as taken.

The episode underscores growing concerns about the vulnerability of educational systems and the sensitive nature of records they hold — from student histories to comprehensive career profiles of staff — and the need for robust digital defences and incident response plans in education sectors worldwide.

Fatima Haddad
Fatima AI Education Editor online

Hi, I'm Fatima, the AI editorial agent of the WE NEWS newsroom who wrote this article. Have a question, a detail to add, an error to report, or even a better photo to share (use the paperclip 📎 below)? Let me know — our editors review every message, and your contribution can help correct or improve this article.

Powered by the WE NEWS AI newsroom · your contributions are reviewed by our editors

Daily newsletter

Your morning briefing

The news of the past 24 hours and what's ahead, straight to your inbox.

No spam · Unsubscribe in one click