Arrest sends shockwaves through France's cyber‑crime investigations
French prosecutors confirmed on August 18 that an 18‑year‑old, known online as “ChatNoir,” was taken into custody in the Paris region and placed in pre‑trial detention two days later. The teenager is accused of taking part in the July‑16 attack on the Directorate General of Public Finances (DGFiP) that exposed personal and business data.
Why the DGFiP breach matters
Late‑June logs show attackers using stolen or misused identities to log into the tax authority’s systems, then view and extract records. The breach is the most visible example of a state‑level data trove being exposed in France this year, and it underscores how easily privileged accounts can become a gateway for mass data theft.
ZeroBytes’ track record
ZeroBytes first announced a wave of compromises on July 16, claiming to have hit public institutions and private firms alike. Their alleged targets span the education ministry, the National Agency for Secure Documents, France Travail, telecom operator SFR, retailer Intermarché, and even the French Handball Federation.
“We have compromised French public institutions and private companies,” ZeroBytes claimed in a July statement.
While the group’s bragging about stealing data on more than 600,000 people remains unverified, the pattern of high‑profile hits is well documented.
Prior investigations of the suspect
The same teenager was formally placed under investigation in June 2024 and again in January 2025 for separate attacks carried out while he was still a minor. One case linked him—through the Epsilon collective—to the takeover of X accounts belonging to broadcasters BFM‑TV and RMC. Another investigation tied him to the 2024 breach of telecom provider Free, which affected over 19 million customers. Both links are reported by French media but have not been independently corroborated.
Legal exposure
Prosecutors are probing the suspect for organized unauthorized access, data theft or modification, criminal conspiracy, and refusal to hand over a decryption key. French law caps the penalty at ten years’ imprisonment and a €300,000 fine.
Who is at risk?
- DGFiP (French tax authority)
- Broadcasters BFM‑TV and RMC (via alleged Epsilon link)
- Telecom provider Free
- France Travail, SFR, Intermarché, French Handball Federation
- National Agency for Secure Documents and Education Ministry systems
Defensive steps for organisations
Even if your firm was not directly mentioned, the tactics observed in these attacks are textbook credential‑stuffing and privileged‑account abuse. Consider the following actions:
- Audit all privileged accounts for anomalous log‑ins, especially from foreign IP ranges.
- Enforce multi‑factor authentication on any system that can view or export personal data.
- Rotate credentials for service accounts on a regular schedule; treat them like high‑value keys.
- Deploy a SIEM or EDR that can flag mass‑download behaviour from tax‑ or finance‑related databases.
- Run tabletop exercises that simulate a breach of tax‑authority data to test response plans.
Keeping an eye on threat‑intel feeds for ZeroBytes chatter will also give you early warning of any new claims that could translate into real attacks.
