Massive Data Breach Hits France's Education Ministry: Millions Affected, Cybersecurity Concerns Rise

August 18, 2026
Massive Data Breach Hits France's Education Ministry: Millions Affected, Cybersecurity Concerns Rise
  • A cybercriminal duo known as ZeroBytes claims a massive data breach of France’s Ministry of National Education, alleging the theft of about 43 gigabytes of data covering millions of pupils, staff, and related records dating from the early 2000s through July 2026.

  • The sample data described by ZeroBytes includes extensive personal details for students and parents (addresses, emails, phone numbers), student options, and teacher assessments, with some files listing home addresses and personal emails of teachers in the Créteil academy, as reviewed by Le Monde.

  • Experts urge independent verification of ZeroBytes’ claims, noting that the exact timeline and scope are still under assessment by authorities and cybersecurity researchers.

  • The Education Ministry warns affected individuals to monitor for suspicious communications and to strengthen account security, stressing it never asks for login credentials, passwords, or bank details by email, phone, or text.

  • The ministry had previously confirmed a July 25 fraudulent intrusion targeting staff training systems, affecting ministry agents in regional authorities since 2001, with external access suspended and investigators alerted.

  • The breach is part of a broader pattern of cyberattacks against state services, underscoring suspected systemic vulnerabilities in public sector cyber defenses.

  • Investigations by French authorities continue, with coordination between ANSSI and CNIL to assess scope and mitigate impact.

  • Security experts warn of heightened risks including phishing and identity fraud, noting that combining access to personal, professional, and pupil data could expose guardians and students to broader threats.

  • Officials say if additional individuals are found affected, they will be notified individually, with guardians informed for students, as part of a broader security reinforcement plan for the ministry’s information systems.

  • Some observers believe authorities underestimated the breach’s scale and highlight ongoing concerns about cybersecurity in French administrations.

  • Outlets note the exposure could include identities, dates of birth, social security numbers, addresses, school histories, and hashed passwords from major databases, with data circulating on the dark web.

  • ZeroBytes has previously linked the Education Ministry breach to a broader campaign including the DGFiP attack, signaling a pattern of high-profile government breaches.

Summary based on 6 sources


Get a daily email with more World News stories

Sources


More Stories