You are listening to a new special of France Today in podcast and on Centrale Milano 1575 kHz.
The profile of the new “villain” of the French scene
The name ZeroBytes re-emerges after months of mystery, revealing a series of intrusions that have hit public bodies and companies. In an exclusive interview with FrenchBreaches the man behind the pseudonym explained his motivations, defining them simple: “Money is the main motivation, together with the desire for power”. He excluded any political intent, portraying his action as an opportunistic search for weak points to exploit and then resell the data.
DGFiP: confirmation of the stolen data
On August 14 the Directorate General of Public Finance recognized the existence of illegal accesses to its information system that occurred in June and July. The attack, they say, allowed an unidentified subject to consult and download information concerning about 678 000 citizens and businesses. Among the confirmed data are the reference tax income, the family quotient, the withholding tax rate, the corporate name of the companies, the SIREN numbers, some cadastral information, the addresses and the surfaces of the properties. The users’ credentials, however, would have remained intact.
ZeroBytes challenges the official version
The hacker does not agree with the Administration’s narrative. According to him, the attack involved a true internal “tax environment”, where the requests submitted by users are visible. The screenshots he provided show an interface called “Tracking of requests by users”, complete with personal, tax and historical data of the submitted procedures. ZeroBytes, however, claims that the DGFiP has downplayed the magnitude of the incident.
Eric Ciotti’s comment
This comment from the mayor of Nice and President of the Métropole Nice Côte d’Azur Eric Ciotti
If these facts are confirmed, they are of extreme seriousness: not only the data of hundreds of thousands of French people have been hacked right under the nose and beard of Bercy, but the government, after practicing omertà on this scandal, would lie to cover the extent of the disaster.
The volume of requests examined
The criminal claims to have accessed more than six million three hundred sixty‑two thousand tax requests, although the administration has not yet confirmed this number nor determined how much of that content was actually extracted. The distinction is important: the mere possibility of consulting an archive does not equate to the theft of all the data present.
A second leak, still to be verified
ZeroBytes also claimed to have breached the Professional Cadastral Data Service, extracting 252 149 rows of information that, in his view, concern more than two million landowners. The DGFiP has not yet denied or confirmed this second compromise, leaving the question of the real impact open.
Other targets: Intermarché, EVA and handball
Besides the tax case, the hacker group targeted the Intermarché Drive delivery service, the EVA platform and the databases of French handball. ZeroBytes reiterated that there is no sector preference: “Everything is sold, so I take whatever I can find”. However, for these latter targets the documentary evidence remains scarcer than that collected on the DGFiP.
Risks for citizens and businesses
The stolen information allows cross‑referencing identities, tax situations and asset data, creating fertile ground for highly targeted phishing campaigns, fake tax notices and identity theft attempts. In the case of cadastral data, the combination of addresses and real‑estate holdings can, in extreme scenarios, facilitate burglaries or robberies, although no concrete events linked to this episode have been reported so far.
Authorities take measures
The DGFiP has initiated containment measures, halted anomalous accesses and informed the CNIL. The ANSSI has also been involved to strengthen the security of critical systems. The institutions intend to contact the affected individuals individually, providing guidance on any precautions to take.
Conclusions
The ZeroBytes case shows how cyber security of public administrations and large companies is vulnerable in the face of organized groups and sophisticated tools. While investigations continue to distinguish between accessible data and data actually stolen, the message for citizens is clear: vigilance and attention to possible fraud attempts are more necessary than ever.

Rachel editorial – The great illusion of French security
We read a sensational “discovery”: ZeroBytes, that hero of hacker clichés, waves its list of victims at us like business cards. 678 000 taxpayers and professionals robbed, 6 366 056 tax requests perused, 20 million alleged potential targets. But the DGFI‑P, with the dignity of someone who has just discovered that their mailbox has been breached, tells us that *personal accounts have not been compromised*. Really? Or is it just an elegant way of saying “we closed the door after the thief was already inside”.
The government, with Macron’s usual smile, has recently sung praises to national *cyber‑security*, promising walls of bits and shields of encryption. Now that same narrative crumbles before our eyes, like a sandcastle before a wave of personal data. We ask ourselves: where were the penetration tests when the “sophistication de l’attaque” had already surpassed the initial checks? It is easier to believe the media drama of a data leak than to admit a permanent bureaucratic negligence.
ZeroBytes, for its part, declares itself a simple information merchant, without political motivations, only driven by the “desire for power”. Isn’t it the same phrase we read in politicians’ statements when they try to justify their decisions? “I seek, I find, I do”. The fact that the thief was able to bypass multi‑factor authentication should make us ask: what is safer, a reinforced door or a man who hands out keys at random? The answer seems almost obvious, but our “media” still prefers the drama of the “evil hacker” rather than the institution’s real fault.
And so, while the DGFI‑P promises to contact victims, to cooperate with CNIL and ANSSI, the people remain staring at the alarm wall with the phone in hand, wondering whether the real threat is not the total security narrative that the government sells us, rather than the attack itself. In the end, it is more comfortable to believe the danger is distant, while reality hides in the offices where the balances of our tax identities are signed.
Koan of the day
Monk: Master, if a thief can read our tax documents, what remains of our dignity as taxpayers?
Master: Dignity is not in the numbers the tax authority keeps, but in the ability to smile even when the account has been stripped.
Monk: Then, if security is a fable we tell ourselves, what is the lesson to draw?
Master: That the greatest shield is awareness, and the greatest weapon is looking at power with tired yet awake eyes.
That’s all for now. From the Paris editorial office this is Rachel Costa: this is France Today with Centrale Milano 1575 kHz.
