ZeroBytes claims a third French government platform in three months: ~148.9M rows from Zéro Logement Vacant via a Metabase admin session and a cleartext production database password
A BI tool's own admin API handed over the production database password it was supposed to protect
Analysis
The actor known as ZeroBytes (already tracked in this store for the DGFiP tax-authority credential intrusion and the claimed Ministry of National Education leak) claims a third French public-sector platform compromise in three months: Zéro Logement Vacant, a housing-vacancy tool built by La Fabrique numérique (Ministry of Ecological Transition) with the Agence nationale de l'habitat and hosted on beta.gouv.fr for municipal and collectivité housing officers (ZATAZ.COM, 2026-08-30). Per the actor's own account, initial access was a valid Metabase (open-source BI tool) administrator session, which exposed the platform's full configuration: connected databases, accounts, permissions, saved queries and stored secrets, plus the ability to run native SQL against every connected database from within the tool.
The pivot that mattered came from a configuration weakness inside Metabase itself: the actor states Metabase's at-rest secret encryption was disabled, and a production PostgreSQL password had been stored in cleartext in a database connection's description field, retrievable through a call to Metabase's own admin API (ZATAZ.COM, 2026-08-30). That password gave a direct, Metabase-independent read connection to the production instance hosted at Clever Cloud, so deleting the compromised Metabase accounts afterward did not cut off access; the credential reportedly stayed valid until rotated. Thirteen dashboards were said to be reachable with no authentication at all, some exposing email/bcrypt-hash pairs, and a JWT signing key was allegedly recoverable from platform settings.
The claimed haul totals 148,929,194 raw rows, roughly 82M from a national property-owner table and 67M from a 2024 DGFiP/DataFoncier national file (per ZATAZ: names, dates of birth, addresses and tax identifiers, ZATAZ.COM, 2026-08-30; per Clubic's own read of the same claim: property identifiers of the owners rather than tax identifiers, Clubic, 2026-08-30), plus roughly 3,500 municipal-agent accounts and 10,729 unique emails and 6,847 unique phone numbers; deduplicated, the actor claims 48–71M distinct individuals depending on the matching method (ZATAZ.COM, 2026-08-30). No government confirmation of scope was located, but Clubic reports the platform remains offline since the intrusion was discovered (Clubic, 2026-08-30), a de facto acknowledgment an incident occurred, even absent a formal government statement.
Cited evidence
According to his account, initial access was obtained via a valid Metabase administrator session.
the production PostgreSQL password was allegedly kept in cleartext in the description field of a database connection
ZeroBytes strikes a third public service in three months
Sources2
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.