news.mlab.sh
Back to the feed
threat-intel

Deux suspects interpellés après le piratage du fisc

High
Summary

French authorities have arrested two suspects linked to the ZeroBytes group, a hacking collective suspected of targeting French government agencies and various organizations. The arrests, following a series of cyberattacks attributed to ZeroBytes, including targeting the French tax administration (DGFiP) and the Education Ministry, are part of a wider investigation into the group's activities. One suspect, an adult, has been placed in custody, while a minor was released to allow investigators to examine his equipment. The investigation aims to identify other involved parties and reconstruct the group's operations, with a focus on linking online claims with seized digital evidence.

French authorities have arrested two suspects linked to the ZeroBytes group, a hacking collective suspected of targeting French government agencies and various organizations. The arrests, following a series of cyberattacks attributed to ZeroBytes, including targeting the French tax administration (DGFiP) and the Education Ministry, are part of a wider investigation into the group's activities. One suspect, an adult, has been placed in custody, while a minor was released to allow investigators to examine his equipment. The arrests follow a period of heightened activity by ZeroBytes, who claimed to have stolen millions of data points related to the Education Ministry, affecting students, parents, teachers, and administrative staff.

According to the Paris Prosecutor’s Office, the first suspect, an 18-year-old resident of the Paris region, was arrested on August 18th and subsequently placed in custody. He is accused of participating in cyberattacks against the French tax authority and belonging to the ZeroBytes group. The suspect had previously been under judicial control in two separate cases in 2023 and 2024, related to previous hacking incidents.

Another suspect, a minor under 16, was released after a brief detention, allowing investigators to analyze his computer equipment. This phase of technical investigation is crucial for reconstructing the digital activities of the group and identifying potential connections between individuals involved.

The investigation extends beyond the initial attack on the DGFiP. Since July 16th, ZeroBytes claimed to have launched several operations targeting websites belonging to the French state and various companies. Following complaints received on July 31st, the cybercrime section of the Paris Prosecutor’s Office opened an investigation, which was subsequently assigned to the Office anti-cybercriminalité (Ofac).

ZeroBytes’ claims have implicated a wide range of organizations, including France Travail, the French Handball Federation, Intermarché, SFR, Bureau Vallée, and Pulsy. The Prosecutor’s Office emphasizes that these claims, made on the dark web, are not conclusive proof of attribution and that judicial work must carefully compare these statements with seized digital evidence and establish individual responsibilities. The investigation is now focused on identifying and arresting other potential participants, linking online claims with seized digital evidence, and reconstructing the organization and operations attributed to ZeroBytes.

Read the full article at ZATAZ