CTIPilot

Zéro Logement Vacant data breach (France, 2026)

incident · incident:zero-logement-vacant-breach-2026-08 single-source

ZeroBytes claims compromise of the French government's Zéro Logement Vacant housing-vacancy platform (beta.gouv.fr) on 2026-08-25 via a Metabase administrator session and a cleartext PostgreSQL production password, exfiltrating ~148.9M raw rows including DGFiP/DataFoncier property-owner records covering an estimated 48-71M individuals; platform taken offline (ZATAZ, Clubic, 2026-08-30).

Coverage timeline
2
first 2026-08-15 → last 2026-08-31
Peak priority
high
2 high
Sources cited
12
7 hosts
Sections touched
1
active-threats
Co-occurring entities
8
see Co-occurring entities below
ATT&CK techniques
4
pinned v19.2 · see below
2026-08-152 appearances2026-08-31

Hunting pivots

ATT&CK techniques
Affected products

ATT&CK techniques

4 techniques observed across 2 entries, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-15/france-dgfip-tax-authority-credential-intrusion · ATT&CK page ↗

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-08-15/france-dgfip-tax-authority-credential-intrusion · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-15/france-dgfip-tax-authority-credential-intrusion · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-15/france-dgfip-tax-authority-credential-intrusion · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-15/france-dgfip-tax-authority-credential-intrusion · ATT&CK page ↗

Credential Access TA0006

T1552.001Unsecured Credentials: Credentials In Files×1

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-08-31/zero-logement-vacant-metabase-breach-zerobytes · ATT&CK page ↗

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-08-31/zero-logement-vacant-metabase-breach-zerobytes · ATT&CK page ↗

Story timeline

  1. 2026-08-31ZeroBytes claims a third French government platform in three months: ~148.9M rows from Zéro Logement Vacant via a Metabase admin session and a cleartext production database password
    active-threatsA BI tool's own admin API handed over the production database password it was supposed to protect
  2. 2026-08-15France's tax authority cut the intruders' accounts in June and July and found no data theft, it took the criminal's sale listing two months later to establish that 678,000 records had already gone
    active-threatsDGFiP confirms a 678,000-record theft via a stolen agent account and a third party's credentials, missed by its own post-intrusion access checks

Where this entity is cited

  • active-threats2

Source distribution

  • zataz.com5 (42%)
  • presse.economie.gouv.fr2 (17%)
  • clubic.com1 (8%)
  • franceinfo.fr1 (8%)
  • occrp.org1 (8%)
  • radiofrance.fr1 (8%)
  • theregister.com1 (8%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (12)

Entries about Zéro Logement Vacant data breach (France, 2026) (2)

2026-08-15 · view entry permalink →

HIGHupdatedNATOA1

France's tax authority cut the intruders' accounts in June and July and found no data theft, it took the criminal's sale listing two months later to establish that 678,000 records had already gone

France's Ministry of Economy and Finance confirmed on 2026-08-14 that a malicious actor had obtained illegitimate access to the information system of the Direction générale des Finances publiques (the national tax authority) during June and July 2026, on the basis of credential impersonation of a DGFiP agent and of an authorised third party (Ministère de l'Économie et des Finances, 2026-08-14). Investigations conducted since 2026-08-12 established that before the accesses were cut, they had been used to view and extract data on a total of 678,000 individuals and businesses: tax data including the reference taxable income, the family quotient and the withholding-tax rate, and for companies the registered name and SIREN identifier, along with cadastral data on the addresses and surface areas of properties. DGFiP states that users' own Espaces Finances publiques accounts were not compromised, and it notified the CNIL as soon as the data theft was identified (Ministère de l'Économie et des Finances, 2026-08-14).

The operationally interesting part is the sequence, and it is a failure mode worth copying into a playbook. DGFiP detected the intrusions and immediately cut off every account involved, the containment step worked. But in the ministry's own words, the access reviews carried out at that point did not reveal that the intrusions had led to data theft, which it attributes to the sophistication of the attack. What surfaced the exfiltration was external: an actor using the alias ZeroBytes advertised the dataset on a cybercrime forum on 2026-08-12, and only the deep investigations that followed established the scope (Ministère de l'Économie et des Finances, 2026-08-14 · The Register, 2026-08-14). Between containment and discovery lay roughly two months in which the organisation believed it had handled the incident. Two of the actor's claims go further than anything the government confirms, and the gap between them is worth holding onto. ZeroBytes advertised the database as containing details of more than 2 million French taxpayers (against the 678,000 the ministry has established) and claimed the access was obtained using stolen credentials and a multi-factor-authentication bypass technique; it also claimed to retain access to DGFiP's systems and offered to sell that alongside the data (The Register, 2026-08-14). DGFiP disputed the claim that ZeroBytes retained access in its statement of the following day (The Register, 2026-08-14); its own published statement addresses neither that claim nor the multi-factor element, and records instead further precautionary cut-offs of access to sensitive information systems while investigations continue to determine the precise nature and volume of extracted data (Ministère de l'Économie et des Finances, 2026-08-14).

The access path carries no vulnerability: it is a valid agent account plus an authorised external party's credentials, which is the same shape as the compromised professional account at France's Ministère de l'Éducation nationale in July and the external service-provider account at Żabka. DGFiP's teams are working with the ministries' senior defence and security official and with ANSSI, and the authority will file a criminal complaint and contact each affected individual and business directly (Ministère de l'Économie et des Finances, 2026-08-14).

Triage: a legitimate tax-administration account queries citizen and business records all day, so record access is not the signal. The discriminators are volume and shape against that account's own baseline; sustained bulk retrieval or export where the role's normal pattern is individual case lookups, activity outside the agent's working hours, and an authorised third-party account reaching record classes its contracted purpose never needed.

Mercredi 12 et jeudi 13 août 2026, un acteur malveillant a revendiqué des accès illégitimes au système d'information de la Direction générale des Finances publiques (DGFiP), intervenus en juin et juillet 2026, reposant sur des usurpations d'identifiants d'un agent de la DGFIP et d'un tiers habilité.

Néanmoins, les contrôles d'accès réalisés à cette occasion n'ont pas permis de détecter que ces intrusions avaient conduit à des vols de données, en raison de la sophistication de l'attaque.

Ministère de l'Économie et des Finances 2026-08-14

Les données susceptibles d'avoir été exfiltrées concernent les agents du ministère ayant exercé en académie depuis 2001.

Pour une partie d'entre eux s'y ajoutent des coordonnées, adresse postale et numéro de téléphone, ainsi que le numéro de sécurité sociale

Ce système d'information ne contient ni données bancaires, ni mots de passe, ni données relatives aux élèves.

Ministère de l'Education nationale, quoted by franceinfo

Un accès frauduleux à un compte professionnel a permis à un cybercriminel de récupérer des fichiers contenant 3 millions de numéros de téléphone, dont 600 000 inscrits sur Bloctel.

DGCCRF

Full restoration could take around two weeks.

ZATAZ.COM

We risk finding ourselves on 1 September with classes lacking teachers in quite a few schools.

ICI / France Bleu (Radio France) 2026-08-26

These hacks must be treated as claims published by Cybernox. A line displayed on an underground forum does not demonstrate that an organization itself suffered a full intrusion. (translated from French)

ZATAZ.COM

the first suspect was arrested on 18 August. Aged 18 and resident in the Paris region, he is suspected of having taken part in the cyberattacks against the tax administration and of belonging to

A second suspect was arrested on 26 August. He is a minor under 16.

After his police custody, he was released.

ZATAZ.COM (Damien Bancal) 2026-08-30
Updaterun 2026-08-21T0410Z-intelentitiesevidencereferencessectorssourcesbody

The earlier entry recorded that France's Direction générale des Finances publiques confirmed intrusions in June and July 2026 using stolen credentials of a DGFiP agent and of an authorised third party, and that only the attacker's sale listing (two months later) established that data on 678,000 individuals and businesses had gone. The delta is that the same actor's footprint now reaches a second French government system, and that the ministry involved has put its own words to what was taken.

The Education Ministry link. ZeroBytes claimed on 18 August to have absorbed 346 million raw lines from the Ministry of National Education some weeks earlier, asserting it had been detected but not cut off. Contacted directly by franceinfo, the minister's office confirmed the claim corresponds to the fraudulent intrusion into one of its information systems that the ministry had already announced on 31 July (franceinfo, 2026-08-18). The linkage of the two thefts to one actor comes from French media reporting rather than from any authority, and this entry carries it at that weight.

What the ministry itself said about the data is the materially new fact. The information at risk concerns ministry staff who worked in an académie since 2001 (identity elements and professional information, status and functions) and for a portion of them the ministry adds contact details, postal address, telephone number and the French social-security number. It also draws a boundary: that information system contains no banking data, no passwords and no student data. On the actor's separate assertion to hold student records, the ministry's position is that its technical examination continues, pending, not a denial. The social-security-number exposure is a detail the earlier DGFiP-only coverage did not carry, and it changes the downstream risk for the affected staff from contactability to identity fraud.

The third breach, and why it is not part of this story. In the same period France's consumer-protection directorate disclosed a separate incident: "Un accès frauduleux à un compte professionnel a permis à un cybercriminel de récupérer des fichiers contenant 3 millions de numéros de téléphone, dont 600 000 inscrits sur Bloctel", a fraudulent access to a professional account let a cybercriminal retrieve files containing 3 million phone numbers, 600,000 of them registered on the Bloctel telemarketing opt-out list (DGCCRF, 2026-08-12). DGCCRF states no personal data such as name or address was disclosed, that the compromised account was blocked as soon as the incident was noticed and all professional accounts subsequently reviewed, and that the Bloctel database itself was not compromised.

It is worth being explicit about what is not established, because the opposite was circulating: no source names an actor for Bloctel, and none ties it to ZeroBytes. The "same hacker" claim in international coverage traces, through its own hyperlink, to a French broadcast report that discusses only the tax authority and the Education Ministry (OCCRP, 2026-08-20). Nor does any source describe one investigation spanning all three; the national anti-cybercrime unit is placed on the DGFiP breach.

Triage: across the intrusions where a mechanism is stated at all, the access is a legitimate account used by someone who should not have it, an agent's and an authorised third party's credentials at DGFiP, a professional account at DGCCRF. There is no malware, no exploited vulnerability and no CVE anywhere in this cluster, so nothing here produces a detection signal on an endpoint. The discriminator is behavioural on the identity plane: a valid account performing bulk record retrieval at a volume and rate no human workflow generates, from a session that is otherwise unremarkable. The DGFiP case established the harder half of the problem, its own post-intrusion access reviews, run when the accounts were cut, did not reveal that data had already been taken. The Education Ministry case adds the same shape from the other side: the actor's claim to have been detected without being evicted is unaddressed by the ministry's published statements.

Updaterun 2026-08-31T0411Z-intelentitiessourcesevidencebody

The delta here is operational, not technical. The Ministry of National Education's precautionary decision to cut network and mailbox access for affected académies, taken after the intrusion this entry already tracks, is still causing real disruption to the 2026 school-year start more than a month later. As of 2026-08-30, most académies report normal access restored, but Toulouse and Nantes remain significantly impacted: at Toulouse, professional mailboxes and applications stay cut "until further notice," family access to the digital workspace is also suspended, the rector describes it as an unprecedented start of term, and "full restoration could take around two weeks", all translated from French (ZATAZ.COM, 2026-08-30), with the digital workspace targeted for relaunch on 7 September. Because substitute-teacher assignment orders are sent by email, the mailbox shutdown has left some substitute and contract teachers without their assigned school days before term starts; teacher unions warn some classes may open in September with no assigned teacher: "we risk finding ourselves on 1 September with classes lacking teachers in quite a few schools" (translated from French) (Thomas Cabioch, SNES-FSU Mayenne, via ICI/France Bleu, 2026-08-26). Toulouse has fallen back to paper timetables and phone or messaging-app communication with families (ZATAZ.COM, 2026-08-30). The ministry states payroll will still be paid on the usual schedule, and the Toulouse rector separately states all students will be accommodated in schools on the planned dates, allowing for possible last-minute adjustments, both translated from French (ZATAZ.COM, 2026-08-30).

Updaterun 2026-09-02T0411Z-intelentitiessourcesevidencebody

A plausible, unconfirmed link has surfaced for the third breach this entry has so far declined to attribute. ZATAZ reported on 2026-08-07 (five days before DGCCRF's public warning) that an actor using the handle Cybernox, jointly with a second handle presented as "don't call me," claimed to have leaked a database tied to Bloctel, France's telemarketing opt-out registry, containing exactly 3,032,386 phone numbers (ZATAZ.COM, 2026-08-07). That figure and timing are consistent with DGCCRF's own disclosure of a leak affecting roughly 3 million phone numbers, 600,000 of them Bloctel registrants, taken via a fraudulently accessed professional account. ZATAZ's own reporting is explicit that this does not establish attribution: "these hacks must be treated as claims published by Cybernox. A line displayed on an underground forum does not demonstrate that an organization itself suffered a full intrusion" (translated from French) (ZATAZ.COM, 2026-08-07). Neither DGCCRF nor ZATAZ names Cybernox as the actor behind the DGFiP-adjacent Bloctel incident, so this entry records the correlation without upgrading it to attribution.

Updaterun 2026-09-06T0409Z-intelupdated_atentitiessourcesevidencebody

France's Paris public prosecutor's office confirms two arrests in the ZeroBytes cluster this entry tracks. The first suspect, an 18-year-old resident of the Paris region, was arrested on 2026-08-18, is suspected of participating in the cyberattacks against the tax administration and of belonging to ZeroBytes, and was placed under judicial examination and pretrial detention two days later (ZATAZ.COM, 2026-09-04). ZATAZ identifies him under the handle "ChatNoir," a presumed co-founder of the earlier Epsilon hacking collective, whose name already appears in prior proceedings tied to intrusions at Free, LDLC and the hijacked broadcast accounts of BFM-TV and RMC (ZATAZ.COM, 2026-09-05). Epsilon's own 2023-2024 breaches separately include a database of more than four million Sport 2000 customer records, and the collective has been associated with WaveStealer, an infostealer sold cheaply on Telegram and Discord that harvests locally-stored credentials and session cookies (ZATAZ.COM, 2026-09-05). A second suspect, a minor under 16, was arrested on 2026-08-26; after his police custody, he was released, with his computer equipment seized for forensic analysis (ZATAZ.COM, 2026-09-04). ZATAZ names him under the handle "Casquette," aged 15, and describes him as a known associate of ChatNoir (ZATAZ.COM, 2026-09-05). The first suspect is charged with unauthorized access to and persistence in an automated data-processing system containing personal data, an offence aggravated by acting as part of an organized group, alongside data modification, extraction, transmission and reproduction offences and a possible conspiracy charge, together carrying up to ten years' imprisonment; the investigation into a criminal association is ongoing (ZATAZ.COM, 2026-09-04). The second suspect was released without indictment at this stage, pending the forensic analysis of his seized devices (ZATAZ.COM, 2026-09-05).

The prosecutor's office's own victim list extends materially beyond the DGFiP/Éducation nationale/Bloctel thread already tracked here, and beyond ZeroBytes' separately claimed Zéro Logement Vacant compromise this store also tracks: France Travail, the French Handball Federation, Intermarché, SFR, Bureau Vallée and Pulsy are named among the organizations the cluster claimed on dark-web forums (ZATAZ.COM, 2026-09-04). ZATAZ's own alias-mapping (built on account histories, observed relationships between users, pseudonym changes and overlapping activity periods rather than resemblance alone) traces the first suspect to a cluster of aliases including Saturne, near, Nears, ChatNoir7331 and blackcat, and the second to a separate cluster converging on xMetah, xReyna and F7001 (ZATAZ.COM, 2026-09-05); the same source separately treats xMetah as a distinct, uninvolved third individual (see below), so this alias cluster's membership is itself unsettled. The timing corroborates the arrests: a message on the cluster's own forum records that "ChatNoir" stopped communicating around 18–19 August, matching his arrest window, and several ZeroBytes-adjacent forum accounts were subsequently banned or closed (ZATAZ.COM, 2026-09-05). Neither correlation by itself proves which individual controlled which account.

The arrests have not ended the campaign. The alias xMetah was not arrested, and ZATAZ assesses him as very likely responsible for a further data-leak post made on 2026-09-01, after both arrests (ZATAZ.COM, 2026-09-05). That single fact is the operational takeaway: a loosely affiliated, multi-alias extortion cluster can lose two members to arrest, including one identified as a co-founder of its predecessor collective, and continue publishing new leaks days later under a surviving alias. Law-enforcement disruption of one identity is not disruption of the cluster.

incident15 Aug 04:47Zmulti-sourceOpen finding ↗

2026-08-31 · view entry permalink →

HIGHNATOB3

ZeroBytes claims a third French government platform in three months: ~148.9M rows from Zéro Logement Vacant via a Metabase admin session and a cleartext production database password

The actor known as ZeroBytes (already tracked in this store for the DGFiP tax-authority credential intrusion and the claimed Ministry of National Education leak) claims a third French public-sector platform compromise in three months: Zéro Logement Vacant, a housing-vacancy tool built by La Fabrique numérique (Ministry of Ecological Transition) with the Agence nationale de l'habitat and hosted on beta.gouv.fr for municipal and collectivité housing officers (ZATAZ.COM, 2026-08-30). Per the actor's own account, initial access was a valid Metabase (open-source BI tool) administrator session, which exposed the platform's full configuration: connected databases, accounts, permissions, saved queries and stored secrets, plus the ability to run native SQL against every connected database from within the tool.

The pivot that mattered came from a configuration weakness inside Metabase itself: the actor states Metabase's at-rest secret encryption was disabled, and a production PostgreSQL password had been stored in cleartext in a database connection's description field, retrievable through a call to Metabase's own admin API (ZATAZ.COM, 2026-08-30). That password gave a direct, Metabase-independent read connection to the production instance hosted at Clever Cloud, so deleting the compromised Metabase accounts afterward did not cut off access; the credential reportedly stayed valid until rotated. Thirteen dashboards were said to be reachable with no authentication at all, some exposing email/bcrypt-hash pairs, and a JWT signing key was allegedly recoverable from platform settings.

The claimed haul totals 148,929,194 raw rows, roughly 82M from a national property-owner table and 67M from a 2024 DGFiP/DataFoncier national file (per ZATAZ: names, dates of birth, addresses and tax identifiers, ZATAZ.COM, 2026-08-30; per Clubic's own read of the same claim: property identifiers of the owners rather than tax identifiers, Clubic, 2026-08-30), plus roughly 3,500 municipal-agent accounts and 10,729 unique emails and 6,847 unique phone numbers; deduplicated, the actor claims 48–71M distinct individuals depending on the matching method (ZATAZ.COM, 2026-08-30). No government confirmation of scope was located, but Clubic reports the platform remains offline since the intrusion was discovered (Clubic, 2026-08-30), a de facto acknowledgment an incident occurred, even absent a formal government statement.

According to his account, initial access was obtained via a valid Metabase administrator session.

the production PostgreSQL password was allegedly kept in cleartext in the description field of a database connection

ZATAZ.COM

ZeroBytes strikes a third public service in three months

Clubic
incident31 Aug 04:55Zsingle-sourceOpen finding ↗