Summary
- An 18-year-old suspected ZeroBytes member was arrested on 18 August and placed in pretrial detention.
- A second suspect under 16 was arrested on 26 August and later released while seized devices undergo examination.
- The arrests are investigative developments and do not establish responsibility for every attack claimed under the ZeroBytes name.
French prosecutors have confirmed two arrests in an investigation into the ZeroBytes hacking cluster, moving the response to a series of public- and private-sector intrusions beyond technical containment and into criminal enforcement.
The investigation includes the compromise of the Direction générale des Finances publiques, France’s national public-finance administration, alongside attacks claimed against other French organisations.
An 18-year-old suspected member of ZeroBytes was arrested in the Paris region on 18 August and placed in pretrial detention two days later. A second suspect, aged under 16, was arrested on 26 August and subsequently released while investigators examine seized equipment.
Neither arrest establishes guilt, and the available evidence does not justify assigning every intrusion claimed under the ZeroBytes name to either suspect.
That distinction is particularly relevant to loosely organised cybercrime groups. Participants can use multiple aliases, share infrastructure, work with changing associates, exaggerate their role, or operate under a common brand without a rigid organisational structure. An arrest can remove an individual from an operation without resolving every attribution attached to the group.
Cyber Insider reported in August on the data exposure affecting France’s tax systems. The incident carried particular weight because the DGFiP processes extensive citizen, tax, and financial information, while the wider run of attacks placed additional pressure on French public administration.
The criminal investigation is now seeking to establish the relationship between individuals, online identities, technical infrastructure, and specific attacks. Those are separate evidential questions from determining that a government system was compromised.
The arrests also illustrate the overlap between incident response and law enforcement. Logs, seized equipment, credentials, communication records, and infrastructure data may all become evidence while affected organisations are simultaneously restoring systems and meeting regulatory or data-protection obligations.
That can create competing requirements. Systems need to return to service, but investigators may need forensic images and records preserved. Accounts may require urgent revocation while authentication data is also relevant to reconstructing the intrusion. Public disclosure may be necessary before the criminal case is sufficiently mature to support detailed attribution.
The age of the suspects adds another layer of caution. European cybercrime investigations have repeatedly involved young operators capable of causing serious disruption without belonging to mature ransomware or state-backed organisations. Technical capability, access to shared tooling, and online collaboration can allow small groups to reach systems with substantial public consequences.
Authorities have not established publicly that the two arrests have ended ZeroBytes-linked activity. Evidence cited in reporting indicates other aliases and activity remained under examination after the detentions, reinforcing the risk of treating an arrest announcement as equivalent to dismantling the wider operation.
The DGFiP compromise also retains its own accountability questions regardless of who is ultimately convicted. Authorities still need to establish the access path, the information exposed, the adequacy of detection and response, and whether related weaknesses existed elsewhere.
Criminal enforcement can disrupt an attacker, but it does not repair the systems that were entered or reduce the consequences of information already taken. France’s investigation is therefore progressing on two fronts: identifying the people behind the activity and addressing the weaknesses and exposures left behind by the attacks.





