news.mlab.sh
Back to the feed
threat-intel

Zéro Logement Vacant visé par une fuite massive ?

High
Summary

A hacker claims to have compromised Zéro Logement Vacant, a service of beta.gouv.fr, and extracted approximately 149 million lines of data, including information attributed to the DGFiP. The attack exploited a compromised Metabase administrator account and a PostgreSQL password stored in plain text. The hacker alleges the service was running with disabled encryption at rest and exposed sensitive data, including personal information, addresses, and identifiers. This incident highlights the risks associated with weak passwords and compromised administrative accounts within business intelligence tools.

A hacker, operating under various pseudonyms including ZeroBytes, claims to have breached Zéro Logement Vacant, a service of beta.gouv.fr, on August 25, 2026, by exploiting a compromised Metabase administrator session. The initial access was gained via a valid Metabase administrator session, allowing the attacker to explore connected databases, users, permissions, and several technical secrets.

According to the hacker’s account, the attacker then gained direct access to a PostgreSQL database by leveraging a production PostgreSQL password stored in plain text within a Metabase connection description. This bypassed the Metabase dependency and provided full read-only access to the PostgreSQL instance hosted on Clever Cloud.

The hacker asserts that Metabase was running with disabled encryption at rest and exposed sensitive data, including nearly 149 million lines of data, divided into two sets. The first set, directly linked to Zéro Logement Vacant, included 3,538 user accounts, 3,448 bcrypt fingerprints, 1,636 active sessions, and 3,204 OAuth records. A public dashboard alone exposed 587 associations between email addresses and bcrypt fingerprints without authentication.

The second set, significantly larger, contained national data attributed to the DGFiP and DataFoncier, comprising 82,043,407 lines in a table named ‘owners’ and 66,874,995 lines from the national 2024 ‘df_owners_nat_2024’ file. These files reportedly contained names, dates of birth, addresses, and tax identifiers.

Consolidated, the hacker claims 148,929,194 lines of raw data, with a potential range of 47,948,974 individuals based on individual identification, 47,917,690 unique identifiers, and 71,065,268 people when combining name and date of birth. The hacker also claims to possess 32,528,110 individuals without a unique identifier. Email addresses were significantly fewer, with 4,329 unique email addresses and 6,847 unique phone numbers, alongside 3,450 unique bcrypt fingerprints. The hacker also claims to hold API key metadata, connection strings for various environments, and the JWT secret used by Metabase.

As evidence, the hacker provided a sample containing 1,000 owner records from each of the two main tables, along with 500 entries from several secondary sets related to emails, phones, sessions, registrations, prospects, senders, and relationships with organizations. The hacker emphasizes that this sample does not represent the entirety of the claimed data, with complete files and tables containing building data and technical logs not included.

Read the full article at ZATAZ