Decoding the world of cybersecurity

France investigates claimed student data theft

France’s Education Ministry is investigating claims that attackers obtained extensive student and teacher records, but the full scope and victim count remain unconfirmed.

France investigates claimed student data theft
Summary
  • ZeroBytes claims to have obtained data on millions of French students and tens of thousands of teachers.
  • Samples reviewed independently contained extensive recent personal information, although the full dataset and claimed scale have not been authenticated.
  • The claim follows a confirmed July intrusion and adds pressure to France's public-sector cybersecurity response.

France’s Ministry of National Education is investigating claims that attackers obtained extensive records on millions of students and tens of thousands of teachers, extending a run of cyber incidents that has placed the security of French government systems under intense scrutiny.

A group using the name ZeroBytes claims it extracted 346 million lines of data from education systems in an intrusion that took place several weeks ago. That figure does not represent 346 million individual people, and the full scale of the alleged theft has not been independently verified.

Samples examined by Le Monde could not be fully authenticated, but reportedly contained large amounts of recent personal information consistent with the attackers’ claims. The material included student and parent addresses, phone numbers and email addresses, class information, teacher comments, and records concerning students considered at risk of dropping out.

The attackers also claimed to hold detailed information on teachers in the Créteil and Versailles education districts. Those claims remain attributable to the group rather than confirmed findings from the French government.

The Ministry had already disclosed an intrusion in July after a professional account was compromised. Officials said at the time that the attack targeted a system associated with staff training and potentially exposed data concerning ministry employees who had worked in regional education authorities since 2001.

The new claims suggest the exposure could be substantially broader and may involve SIECLE, one of the central systems used for managing secondary-school student information. The ministry is still establishing whether the data offered by the attackers originated from that system and how the latest claims relate to the previously disclosed intrusion.

That uncertainty is important because large breach claims routinely combine genuine stolen information, duplicated records, historic material, and exaggerated victim counts. The existence of credible sample data can establish that an attacker obtained something significant without validating every number attached to a criminal advertisement.

The type of information described nevertheless creates a difficult exposure even before the final count is known. School records are persistent identifiers of children, parents, home addresses, educational history, and in some cases welfare or behavioural information. Unlike passwords, much of that data cannot simply be changed after a breach.

Education systems also present a structural security problem. National ministries sit above large networks of regional authorities, schools, staff, contractors, software systems, and administrative accounts. Access designed to let thousands of institutions share information can create complex trust relationships, while ageing systems and long retention periods increase the amount of data available when an account is compromised.

The latest claim arrives as the French government is already dealing with the theft of tax, business, and land-registry information from the DGFiP. In that separate incident, officials acknowledged weaknesses in government IT and announced accelerated authentication, detection, and audit measures.

The overlap does not establish a common technical cause across French public services, even where the same attacker name has been used. It does, however, create a wider accountability problem for the state: multiple public administrations hold datasets whose compromise can affect citizens for years, while the security of those systems depends on credentials, access pathways, and technology accumulated across long administrative lifecycles.

The Education Ministry’s next disclosure will therefore need to resolve more than the attackers’ headline victim count. The key questions are which systems were accessed, whether the July compromise provided the route into student records, how long that access persisted, and exactly which categories of data left government control.

×