French police arrested an 18-year-old suspected member of the ZeroBytes hacking collective, known online as “ChatNoir,” in connection with the compromise of France’s Directorate General of Public Finances (DGFiP). Prosecutors said the suspect was arrested on August 18, formally placed under investigation on August 20, and remanded in pretrial detention. A second suspect, younger than 16, was questioned and released; investigators retained that person’s computer equipment for forensic examination.
The DGFiP breach exposed data on more than 678,000 individuals and businesses. Investigators believe the intrusion relied on impersonating internal staff accounts with excessive permissions rather than exploiting a technical vulnerability. DGFiP is urgently deploying USB security tokens to strengthen multifactor authentication as authorities pursue other possible ZeroBytes members. More than 1,200 affected people have joined a GDPR damages action.

See the reporting duties and controls this puts on the clock.
12 events from the most recent confirmed update back to the earliest known activity.
The Paris prosecutor's office publicly disclosed the case involving the suspected ZeroBytes member and the DGFiP data-theft investigation.
Authorities detained and questioned a second suspect under age 16, then released the minor while retaining computer equipment for forensic examination. Authorities did not identify the minor as a ZeroBytes member.
The 18-year-old suspect was formally placed under investigation for organized unauthorized access, data modification/extraction/transmission, and criminal association offenses connected to the DGFiP case. He was remanded in pretrial detention.
French police arrested an 18-year-old Paris-region suspect on suspicion of affiliation with ZeroBytes. French media identified the suspect's online alias as “ChatNoir”; he was already under judicial supervision and had previously faced two formal investigations for alleged cyberattacks committed as a minor.
DGFiP detected a third intrusion in which an attacker exploited a technical vulnerability in a DGFiP-developed statistical-processing deployment system. The incident enabled access to data relating to vacant estates or unclaimed inheritances.
ZeroBytes first claimed on July 16 that it had compromised French public institutions and private companies. Prosecutors subsequently said the suspected campaign targeted government agencies, schools, companies, SFR, Intermarché, and the French Handball Federation, in addition to previously reported targets.
A confidential Senate inquiry found that attackers compromised a National Education employee account, accessed the interministerial RIE network, and then targeted DGFiP's portal and e-contact application. The inquiry identified absent MFA, infostealer-compromised credentials on personal devices, and insecure remote-work access as key weaknesses; ANSSI activated Operation REACTIV to push MFA and hardware security keys across ministries.
ZeroBytes claimed responsibility for the DGFiP data compromise affecting more than 678,000 individuals and professionals. The report also states that the group claimed attacks against France's Education Nationale and France Travail, without providing incident dates or verifiable technical details.
Reporting identified the second DGFiP suspect as Casquette and described Casquette and the suspected ZeroBytes actor ChatNoir as former members of the Epsilon group. The report also linked ChatNoir to prior Epsilon-related proceedings and data-leak activity.
A coordinated GDPR-based compensation action brought together more than 1,200 people affected by the DGFiP compromise, seeking damages from the French state for moral harm and identity-theft prevention costs.
DGFiP began urgently deploying USB tokens to strengthen multifactor authentication for its agents following the account-compromise incident.
A compromise of a critical French Directorate General of Public Finances (DGFiP) database exposed data relating to more than 678,000 individuals and professionals. DGFiP said the intrusion relied on impersonated internal accounts with overly broad permissions rather than a technical exploit.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
7 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcezdnet.fr
Open sourcetherecord.media
Open sourcezdnet.fr
Open sourcecyberveille.ch
Open sourcedatabreaches.net
Open sourcezdnet.fr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.