The French government is dealing with a major cybersecurity crisis after a significant data breach impacted the platform zerologementvacant.beta.gouv.fr, which was taken offline on August 30, 2026. A cybercriminal group called ZeroBytes claims to have stolen nearly 149 million lines of data, including personal details of tens of millions of property owners and files from the national real estate register known as DataFoncier. The platform's administrators have not yet publicly addressed the incident.
According to data compiled by French Breaches, the attackers exploited a critical flaw in how information was managed, with the initial entry point being a tool called Metabase, used for business intelligence. From a high-privilege session, the hackers accessed a password for a PostgreSQL production database, which was stored in plain text in the connection description. This password allowed them to directly query the server hosted on Clever Cloud, bypassing the usual protections. In addition to real estate data, the breach included the theft of critical authentication elements such as 3,450 hashed passwords, 3,204 OAuth records, 1,636 active session tokens, and other security keys.
The large volume of data stolen is partly due to the centralization of information from multiple government agencies within a single service. The Zéro Logement Vacant platform, for example, included data from the Direction générale des Finances publiques (DGFiP), which alone accounted for over 66.8 million data lines. This centralization, without proper compartmentalization, means that even a small vulnerability in one system can expose data from many other systems, including tax information.
Luis Costa, a researcher at Surfshark, noted that the difference in the number of cyberattacks between Germany and France is partly due to the more decentralized nature of public computer systems in Germany, managed by regional authorities known as Länder. This event occurs in a year where France has become the most affected country in Western Europe by data breaches.
Trade unions are growing increasingly frustrated with the government’s budgetary priorities, particularly those that prioritize efficiency and cost-cutting over infrastructure resilience. Staff representatives criticize a policy that reduces staffing levels, making it harder to maintain secure systems. In 2025, the DGFiP allocated 445 million euros to its IT budget, but cyberattacks have surged, rising from 2,579 in 2023 to 6,972 in 2025. Public sector organizations struggle to recruit and retain cybersecurity experts, as they cannot match the salaries offered in the private sector, leaving existing teams overwhelmed by technical challenges.
Prime Minister Sébastien Lecornu has directly intervened with the National Cybersecurity Agency (ANSSI) after the government acknowledged an “unacceptable” level of security in most ministries. He has ordered the creation of a first-line cyber unit within the agency to respond proactively to any suspicious threats to state systems. Lecornu emphasized the urgency of developing a more reactive and robust response to the cyberattacks currently facing the government.
French Government Faces Growing Cybersecurity Crisis Amid Major Data Breach
AI-rewritten from original reportingHow it works
cybersecuritydata-breachfrancegovernmentmetabasezerobytes



