Unverified claim: On the night of 17 August 2026, a cybercrime-forum persona called ZeroBytes advertised roughly 43 gigabytes of data allegedly stolen from France’s Ministry of National Education (Éducation nationale). Trade reporting cites deduplicated figures of about 1.22 million pupils (many minors) and 4.35 million staff identifiers, plus academic network accounts and hashed passwords. The ministry had not publicly confirmed pupil registers at indexing — it had confirmed a narrower 25 July intrusion into a staff-training system with no pupil data in that environment.
Parents, teachers, and anyone who ever attended a French public school should treat this as a high-risk phishing season, not as proof that every child file is already on a paste site. Canonical records: confirmed July staff SI — france-education-nationale-agents2026; unverified August forum scope — france-education-nationale-zerobytes2026.
What ZeroBytes claimed in the August 17 listing
According to Brussels Signal and specialist site French Breaches, ZeroBytes — the same handle linked to the mid-August DGFiP tax-authority claim — said the education haul spans about 2,500 files and 346 million raw lines before deduplication.
Reporter summaries of the listing describe several ministry systems:
- BE1D (Base Élèves 1er Degré) — primary pupil register
- SCONET — secondary-school pupil system
- SCHAAF — federated academic directory
- I-Prof — career management for ministry personnel across 33 académies
- Large Créteil and Versailles academy data sets called national in scope in some reporting
- Monitoring files on pupils “in difficulty” in Créteil from 2020–2021 through 2025–2026
Alleged field types include names, dates of birth, numéros de sécurité sociale (NIR), addresses, phones, school histories, parental or guardian links, professional records for staff, and in some directories hashed passwords. Records are said to stretch from the early 2000s into July 2026.
What this is not (yet): a ministry attestation that 1.22 million children’s rows were exfiltrated. It is an actor marketing a package while France’s government is already in crisis mode over ZeroBytes’ tax claim.
What the ministry already confirmed on 31 July
On 31 July 2026, Éducation nationale confirmed a fraudulent intrusion overnight 25 July via a usurped professional account into the personnel-training information system. Potentially exposed: identity and professional data for agents who worked in académies since 2001; for some, address, phone, and NIR.
The communiqué — summarized in July press and on education.gouv.fr — is explicit about limits:
- No pupil data in that training SI
- No passwords or bank details in that SI
- No attested headcount yet for how many agents were copied
That confirmed incident is catalogued separately. The August ZeroBytes claim describes a wider perimeter — pupil registers and directory hashes — that the July statement says was out of scope for the training application.
As of 18 August 2026, reporting noted the ministry had not issued a detailed public response confirming or denying ZeroBytes’ full pupil-and-directory narrative.
Why pupil data changes the stakes
Staff NIR exposure is already serious for impersonation and administrative fraud. Pupil registers add minors, parental links, and school-location context — fuel for targeted grooming-adjacent scams, fake “school fee” messages, and convincing ÉduConnect or PRONOTE lures.
French Breaches and Brussels Signal highlight files tying pupils to parents or guardians as among the most sensitive alleged contents. Even if only a subset is real, attackers need partial rows to sound credible.
Separately, March 2026’s Compas trainee-system theft (~243,000 agents) and April ÉduConnect pupil-account reporting show Éducation nationale was already a repeated target before ZeroBytes’ August marketing push. See Compas 243k.
Timeline — three layers, one brand
- March 2026 — Compas trainee SI; ~243,000 agents reported stolen.
- 25–31 July 2026 — Staff-training SI intrusion confirmed; agents since 2001 potentially exposed; no pupil data in that SI per ministry.
- 12–17 August 2026 — ZeroBytes tax claim on DGFiP; government crisis cell; 678,000 attested by Economy Ministry.
- 17 August 2026 (night) — ZeroBytes education forum listing with pupil + staff scale claims.
- 18 August 2026 — International trade press amplifies; ministry silent on full pupil scope.
Do not merge these into one “all French schools dumped” headline. Each layer has different verification status.
ZeroBytes as a campaign, not a one-off
Linking DGFiP and Éducation nationale claims under one forum handle suggests either a sustained intrusion campaign against French public-sector identity systems or a deliberate branding exercise timed for maximum political impact during the tax crisis.
Specialist reporting says ZeroBytes responded to publicity by claiming detection without immediate cut-off — a detail that matters for defenders (persistent access) but remains unverified.
BreachHistory stores recordsAffected 4350000 on the unverified education row as the reporter-cited deduplicated staff-identifier figure, with the ~1.22 million pupil count described in prose — not added into one fake “5.5 million people” total.
What was not confirmed at indexing
- Whether BE1D/SCONET extracts are authentic ministry exports or stitched samples
- Whether hashed directory passwords are crackable or stale
- Whether the 346 million “raw lines” are unique people or log/event noise
- Whether CNIL will publish an attested census for pupils
- Whether ZeroBytes will drop a public torrent or only sell privately
Forum claims can be inflated, recycled, or partially true. The July ministry confirmation proves some staff-system exposure; it does not prove all pupil registers walked out the same door.
Who is at risk — by audience
Current pupils and recent graduates. If pupil registers were exfiltrated, expect scams quoting school name, class level, or sibling details. Parents should brief children not to click “school account reset” links from SMS.
Parents and guardians. Alleged linkage files are high-value for “your child’s file is locked — pay here” fraud. Verify through the school switchboard, not a QR code in WhatsApp.
Teachers, admins, and retirees since 2001. The confirmed July training-SI incident already put NIR-class data in play for many agents. ZeroBytes adds alleged directory passwords and I-Prof career rows — still treat as unverified until notices arrive.
IT staff in académies. Expect spear-phish pretending to be ANSSI or CNIL with malicious “VPN patch” attachments.
People outside France. Copycat templates will use the headline anyway. If you have no French public-school tie, you are not automatically in the claimed extract — but you may still get spam.
Phishing you should expect
- Fake ÉduConnect or PRONOTE password resets with real school names
- SMS about “student monitoring files” or “Créteil academy security audits”
- Calls impersonating recteurs or HR demanding NIR “re-validation”
- Emails citing ZeroBytes or “678k taxpayers” to confuse adults who follow both stories
- Fake CNIL compensation forms asking for ID photos and card scans
The ministry states it never asks for login credentials or bank details by email or phone. Any message that does is hostile even if it quotes your académie correctly.
What parents and teachers should do now
- Use only bookmarked portals — education.gouv.fr, educonnect.education.gouv.fr — never search-ad links after breach headlines.
- Turn on MFA where professional or parent portals allow it.
- Talk to children about not sharing one-time codes or clicking “homework unlock” links.
- Watch official notices — the July communiqué promised affected agents would be informed; a wider pupil notice may follow if scope is confirmed.
- Do not upload NIR scans to third-party “breach checker” sites or Telegram bots offering “see if your child leaked.”
- Report phishing to your académie IT channel and Signal Spam (33700) for SMS.
- If you were in the March Compas cohort too, assume elevated targeting — multiple 2026 MEN incidents, not one.
- Freeze or monitor credit for adults whose NIR may be exposed; minors’ fraud often surfaces as bogus phone contracts or tax anomalies later.
How this compares to the DGFiP ZeroBytes claim
The tax administration later attested 678,000 individuals and professionals after ZeroBytes’ forum post forced deeper forensics. Education may follow a similar arc — initial narrow confirmation, later census revision — or the pupil registers may remain unconfirmed if the listing is mostly bluff.
Read our DGFiP breach guide for the parallel ZeroBytes playbook: actor post first, ministry count later, phishing immediately.
Regulators and political context
ANSSI and CNIL were engaged after the July intrusion. Prime Minister Sébastien Lecornu chaired an interministerial crisis meeting on 17 August amid the tax fallout — the same window ZeroBytes posted the education claim. Expect coordinated communications if pupil impact is confirmed.
Until then, journalists and parents should label claims unverified in every headline, even when the ministry’s July confirmation makes “Éducation nationale hacked” feel inevitable.
Was my child affected?
There is no public lookup portal. Signals that you may eventually be in scope:
- An official education.gouv.fr or académie letter (not a forum screenshot)
- CNIL notification if pupil data is confirmed under French law
- School-directed communication through known headteacher channels
Absence of mail today does not prove safety if the August claim is true — but panic-uploading family documents to random sites creates new risk.
For school IT and union reps
Publish one internal FAQ: July confirmed staff-training SI vs August unverified ZeroBytes pupil claim. Tell staff not to paste NIR lists into shared spreadsheets “to check who leaked.” Disable legacy VPN paths if not already done post-July.
Union inboxes will fill with forwarded Telegram files. Delete binaries; link only to education.gouv.fr.
Canonical record and sources
Unverified August scope: france-education-nationale-zerobytes2026.
Confirmed July staff SI: france-education-nationale-agents2026.
Sources: Brussels Signal, French Breaches, education.gouv.fr Jul 31 notice, Midi Libre.
FAQ
Did the ministry confirm 1.22 million pupils exposed? Not as of 18 August in sources indexed here. ZeroBytes and trade press cite that figure; the July communiqué denied pupil data in the confirmed training SI only.
Is this the same as the July 25 incident? Related institution, different claimed scope. July = confirmed staff-training SI. August = unverified wider registers.
Are ÉduConnect passwords in the dump? Allegedly hashed directory passwords appear in actor descriptions; not confirmed by the ministry.
Should I pull my child out of ÉduConnect? No — harden accounts, use MFA, and ignore cold reset links.
What about Compas and 243,000 agents? Separate March incident — Compas row.
Bottom line
France’s schools were already on breach watch after July’s confirmed staff-system intrusion. ZeroBytes’ 17 August listing escalates the claimed scale to millions of pupils and staff identifiers — unverified, politically timed, and dangerous for phishing regardless of final forensic truth.
Parents and teachers should act on security hygiene now and wait for official French notices before treating forum counts as census. When the ministry or CNIL publishes numbers, BreachHistory will update the canonical row — until then, label the pupil-register story unverified and prioritize protecting minors from SMS scams that exploit their school names.
The Éducation nationale data breach search cluster for 2026 now spans Compas, July agents, and August ZeroBytes claims. Read each label carefully; your next phishing message will not.
International readers and diaspora families
French citizens abroad with children in the public system, or adults who taught in France since 2001, remain in the potential populations described in July and August reporting. Consulate spam pretending to be “Ministère de l’Éducation — dossier expatrié” is predictable. Verify through official consular channels only.
English-language headlines may round “1.22 million pupils” to “millions of French students hacked.” Prefer the labeled BreachHistory pages when sharing in PTA or expat groups so verification status travels with the number.
Researchers should not republish sample child rows even if samples circulate. Minors’ data deserves the same redaction discipline as PHI.
If independent analysts confirm or debunk the listing, update the catalog — but do not let urgency bypass child-safety norms in the rush to prove authenticity.
Defenders outside France should still brief staff: French suppliers, teachers on exchange programs, and EU education partners may receive targeted mail citing this incident.
ZeroBytes wins if confusion makes everyone click. Clarity — confirmed July staff SI, unverified August pupil claim — is the defense.
Technical systems named in the listing — what they do
Understanding the acronyms helps you judge whether a phishing message is plausible without treating the forum post as gospel.
BE1D (Base Élèves 1er Degré) is the national primary-school pupil register. If authentic extracts exist, they would tie children to schools, classes, and administrative identifiers used across académies. That is why reporters emphasize minors and parental linkage — not because every row is already public, but because the claimed source system is built for longitudinal school records.
SCONET covers secondary education. Alleged SCONET content would extend the same risk to collège and lycée cohorts — older teens who may have their own phones and are less likely to ask a parent before clicking a “bulletin” link.
SCHAAF is described in trade press as a federated academic directory — usernames, organizational units, and in some reporting hashed credentials. Directory dumps rarely include lesson plans; they enable password-spray and impersonation against staff portals.
I-Prof manages careers for ministry personnel across France’s 33 académies. Combined with the July training-SI confirmation, defenders should assume staff-facing identity data is a recurring target in 2026, even if the August pupil scale remains unverified.
Créteil and Versailles academy sets appear in French Breaches’ summary as unusually large regional bundles. Regional académies process local admissions and staffing; a regional leak can still contain pupils who later moved — which is why “I left that school years ago” is not a reliable safety signal until official notices clarify retention.
Legal and notification outlook under French law
France’s GDPR implementation and sector rules require notification to CNIL when personal data breaches pose risk to individuals. The July communiqué already framed agent notification and support measures. If pupil registers were confirmed exfiltrated, expect:
- CNIL publication or guidance on scale and categories
- Targeted communication through académies or schools rather than a single national email blast on day one
- Heightened scrutiny of minors’ data because NIR and parental links compound harm
- Political pressure parallel to the DGFiP crisis — same actor brand, different ministry
Until those steps appear, treat Brussels Signal and French Breaches as secondary sources documenting an actor claim, not as replacements for education.gouv.fr.
How to verify messages claiming to be from your school
After major breach headlines, attackers copy real school letterhead from PDFs posted online. A practical verification ladder:
- Channel match: Did past official mail come from the same sender domain? Hover links; do not trust display names.
- Callback: Use the phone number on the school’s official website — not a number in the suspicious email.
- No secrets in reply: Real notices may ask you to log into a portal; they should not ask for your NIR, password, or payment card in the body of an email.
- Children’s accounts: Reset passwords only from bookmarked ÉduConnect or PRONOTE entry points after discussing with the school if unsure.
This ladder applies whether the ZeroBytes claim is fully true, partially true, or mostly marketing. July’s confirmed staff incident already justifies vigilance; August’s listing raises the urgency of scams, not the certainty of every child’s file leaking.