< Back to all clusters
[TECHNOLOGY] · France · 14 sources

started · updated

ZeroBytes cyberattack targets French government housing platform

The hacking group ZeroBytes has claimed responsibility for a massive cyberattack targeting the French government's ‘Zéro Logement Vacant’ platform. The breach, which resulted in the platform being taken offline on August 30, 2026, reportedly involved the theft of approximately 149 million raw data records.

Experts estimate that after deduplication, the leak could affect roughly 48 million distinct individuals. The compromised information includes sensitive personal and property data, such as full names, dates of birth, postal addresses, and property identifiers. A significant portion of the stolen data is believed to originate from the national DataFoncier 2024 registry.

This incident follows a series of coordinated attacks by ZeroBytes against French administrative infrastructure over a three-month period. The group previously targeted the Directorate-General of Public Finances (DGFiP) in mid-August, affecting approximately 678,000 individuals, and the Ministry of National Education in August. The investigation into the ‘Zéro Logement Vacant’ breach suggests the attackers exploited a critical vulnerability by accessing a Metabase business intelligence tool via a valid administrator session and discovering a PostgreSQL password stored in clear text.

Entities

DGFiP · Direction Générale des Finances Publiques · Directorate General of Public Finances · France · Ministry of Ecological Transition, City and Housing · Ministry of Ecological Transition, City, and Housing · Ministry of Housing · Ministry of National Education · ZeroBytes · Zéro Logement Vacant

Claims

What the coverage asserts, and how many sources carry each claim.

Sources

30 days ago
about 1 month ago