~/f4n6 $ grep -r "French prosecutors confirm arrest of suspected ZeroBytes hacker behind tax cyberattack" ./investigations/ --include="*.md"

French prosecutors confirm arrest of suspected ZeroBytes hacker behind tax cyberattack

Jeff Davies 08 Sep 2026 5 min read

1. Executive summary

French prosecutors have confirmed the 18 August 2026 arrest in the Paris region of an 18-year-old suspected member of the French-speaking hacking group "ZeroBytes," held in pretrial detention since 20 August in connection with attacks on the Directorate General of Public Finances (DGFiP), which disclosed a data breach in August. A second suspect, under 16, was arrested 26 August and released pending device examination. ZeroBytes has claimed attacks on French government agencies, schools and companies since 16 July, including France Travail, SFR, Intermarché and the French Handball Federation; a member claiming the ZeroBytes name asserted theft of data on more than 600,000 individuals from DGFiP, including names, tax identification numbers, email addresses, family circumstances and tax status. Attribution to ZeroBytes as an organised group and the suspect's membership remain unconfirmed — the actor has no MITRE ATT&CK profile and the claims rest on a single vendor/media source. For EMEA financial services clients, the direct risk is limited to exposure of French taxpayer and business data held or processed via DGFiP relationships; the broader relevance is as a case study in identity-based initial access against a national tax authority.

2. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item. The trigger test fails: this is a French law-enforcement action against a third party (DGFiP and other French organisations), not an incident at a client entity. The DGFiP breach itself would engage DORA Art. 19 (reporting of major ICT-related incidents to competent authorities) and DORA Art. 18 (classification of ICT-related incidents and cyber threats) only for DGFiP as the affected entity — not for financial-sector clients receiving this advisory. Clients with French tax data exposure should treat this as a third-party data-exposure watch item under existing processes, not a reportable event in itself.

3. Technical analysis & attack chain

This is a law-enforcement action; the attack chain below is reconstructed from prosecutor and DGFiP statements as reported by Recorded Future News, and is incomplete.

  1. Initial access (late June 2026, per DGFiP): An attacker gained unauthorised access to DGFiP systems "by stealing or misusing someone's identity." No CVE, exploited component, or technical vector (phishing, credential stuffing, session hijack, insider misuse) is specified in the source material. The phrasing indicates identity/credential compromise rather than exploitation of a known software vulnerability, but the exact mechanism is unconfirmed.
  2. Data access and extraction: The attacker was able to "view and extract information belonging to individuals and businesses." No exfiltration tooling, volume, or method is described by authorities.
  3. Claimed scale: A hacker using the ZeroBytes name claimed theft of information on more than 600,000 people — names, tax identification numbers, email addresses, family circumstances, and tax status details. This figure is the actor's own claim, single-sourced via media reporting, and unverified by authorities in the source material.
  4. Group activity (16 July 2026 onwards): ZeroBytes first claimed attacks on a dark web site, stating compromise of both French public institutions and private companies. Suspected additional targets include French educational institutions, France Travail, SFR, Intermarché, and the French Handball Federation.
  5. Investigation and arrest: The 18-year-old suspect was arrested 18 August in the Paris region and placed in pretrial detention 20 August. Prosecutors are investigating organised unauthorised access to systems containing personal data, stealing and modifying data, participation in a criminal conspiracy, and refusing to provide authorities with a decryption key — indicating encrypted material or systems were seized or affected and the suspect did not cooperate. Penalties sought carry up to 10 years' imprisonment and a €300,000 fine.

Suspect history (context, single-sourced to French media via the report): The suspect was previously placed under formal investigation in June 2024 and January 2025 in two separate cases for attacks allegedly carried out as a minor, and was under judicial supervision in both when arrested. French media identify him by the alias "ChatNoir"; authorities have not disclosed his civilian identity. One prior case is linked to the Epsilon collective, including takeover of X accounts belonging to BFM-TV and RMC and data theft from several companies; the other concerns the 2024 breach of telecom provider Free, affecting reportedly more than 19 million customers.

Attribution caveat: ZeroBytes has no MITRE ATT&CK profile in our verified reference data; attribution of the DGFiP attack to this group, and of the suspect to the group, is unconfirmed and rests on prosecutorial suspicion and the actor's own dark-web claims. The 600,000-record figure is likewise unverified. Single-sourced; verify before enforcement action or client notification predicated on it.

4. Mitigation & containment

No client-side compromise is described. Actions are exposure-assessment and process controls, not technical containment of an active intrusion.

P1 — within 24h

  • If your organisation processes or holds French taxpayer data (payroll, retail banking with French individual/business clients, tax advisory), determine whether any client-facing workflows consume DGFiP-sourced data (tax identification numbers, tax status) and assess whether exposed fields (names, tax IDs, emails, family circumstances) could enable follow-on social engineering against your customers. No client-side patch or block applies.

P2 — within 72h

  • Fraud/AML teams: brief on the exposed data types. Names plus tax identification numbers plus family circumstances are high-quality material for impersonation and vishing pretexts against French retail customers. Review callback verification procedures for any customer contact referencing tax matters.
  • Confirm no third-party arrangement places your data within DGFiP-adjacent systems; if so, invoke contractual breach-notification clauses.

P3 — within 7 days

  • Treat the DGFiP initial-access vector — identity theft or misuse — as the actionable lesson: verify that service and administrator accounts with access to bulk personal-data repositories are covered by phishing-resistant MFA and that identity-proofing for high-privilege account recovery cannot be satisfied with publicly obtainable personal data (names, family details, national identifiers).
  • No vendor fix, CVE, or version action applies to this item.

5. Indicators of compromise

No indicators of compromise available in the source material.

Behavioural indicators

Behaviour Where to observe Confidence
Actor claims posted to a dark web site naming compromised French public institutions and private companies (first claims 16 July 2026) Dark web / leak-site monitoring, brand-intel feeds Medium — reported by prosecutors via media
Impersonation pretexts leveraging DGFiP-exposed data: names, tax identification numbers, email addresses, family circumstances, tax status Customer contact channels, fraud case review, call-centre QA Low — contingent on the unverified 600,000-record claim

6. Detection

Insufficient indicators to author detection rules.

7. Sources

  • Recorded Future News (The Record), "French prosecutors confirm arrest of suspected ZeroBytes hacker behind tax cyberattack," https://therecord.media/france-hacker-arrest-zerobytes, 2026-09-08

8. Adverse Trace position

Low direct severity for EMEA financial services clients: this is a confirmed arrest in an ongoing French prosecution, not an active threat campaign against the sector, and no CVE, malware, or client-side exposure is in scope. The material risk to clients is secondary — French-customer impersonation and fraud pretexts built on DGFiP-exposed personal data, contingent on an unverified actor claim of 600,000 records, and the demonstrated viability of identity-based initial access against a national tax authority. Attribution to ZeroBytes is unconfirmed (no MITRE profile; single-sourced claims), and we will not treat the group as a named threat actor in client threat models until corroborated. We will monitor the prosecution, any DGFiP disclosure of verified record counts, and emergence of corroborated IOCs from the seized devices, and will issue a follow-up note if the second suspect's device examination produces technical detail.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies