ZeroBytes, also styled Zerobytes, is a French-speaking cybercriminal group associated with data theft targeting French government agencies, educational institutions, and companies. Its operations are financially motivated, with stolen databases advertised for sale on cybercrime forums. The group is associated with France and became publicly prominent through claims of attacks against French public institutions in July and August 2026. Its principal documented targets include the Direction générale des Finances publiques (DGFiP) and the Ministry of National Education. DGFiP intrusions exposed personal tax information, business identifiers, administrative correspondence, and cadastral records. The tax authority subsequently reported approximately 600,000 affected individuals, businesses, and professionals. ZeroBytes advertised the stolen information and made broader claims about the scale of its access and extraction. The group's documented intrusion methods center on compromised legitimate identities rather than advanced vulnerability exploitation. Operations used employee and authorized third-party credentials, including credentials stolen by infostealers from unmanaged devices. Attackers exploited missing multifactor authentication, bypassed email-based one-time-password authentication, and used a compromised Ministry of National Education environment to pivot into tax-administration systems through the French interministerial network. Automated scraping enabled two waves of tax-data exfiltration totaling approximately 14 GB in June and July 2026, followed by access to cadastral information. Excessive account permissions and inadequate network segmentation facilitated the intrusions. French authorities arrested an 18-year-old suspected member in August 2026 and placed him under formal investigation and pretrial detention. A separate minor suspect was questioned and released while investigators examined seized equipment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cybercriminal actor claiming theft and public disclosure of French tax-administration data, including data scraped from the DGFIP E-Contact user-management application and cadastral data accessed through the APEX portal. The reported intrusion used credentials compromised by infostealers, valid-account access, credential stuffing, pivoting through a compromised Ministry of Education environment connected to the French interministerial network, and MFA bypass through compromise of a surveyor's workstation.
Allegedly conducted intrusions against France's DGFiP using compromised state-agent accounts, resulting in the theft of personal data concerning 678,000 individuals and professionals.
Suspected of participating in the cyberattack against France’s Directorate-General for Public Finance (DGFiP), which exposed sensitive and personal data of an estimated 350,000 to 678,000 taxpayers.
Conducting unauthorized-access and data-theft attacks against French public-sector entities and private organizations. The group claimed to have exfiltrated personal and tax-related data on more than 600,000 individuals from DGFiP and is suspected of targeting educational institutions, an employment agency, a telecom operator, a retailer, and a sports federation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.