Published on . 10 min read.

The French education ministry had its students stolen

A hacker claims 346 million rows on French students, the ministry promises to notify affected parents, and my daughter's school handed me the same forms again.

On Tuesday, September 1, my daughter's school handed me the same stack of forms as last year. Both parents' identities, landlines and cell phones, work numbers and personal ones, an email address, permission to photograph her, permission for field trips, and an extract from the family record book for good measure. I filled it all out in pen on the corner of a table, like millions of French parents that week, thinking about what I had read over the summer. Since July 25, someone has been walking around with the equivalent of those forms for a little over a million students, and nobody has written to tell me whether my daughter is one of them.

Stone facade of a former boys' school turned preschool, with a tall white double door, ivy trailing from the lintel, a plaque reading "École maternelle Meynis," and two glass-fronted notice boards filled with sheets of paper.
A preschool in Lyon, late August 2026. The glass notice board has never needed a security patch (photo Sebleouf / Wikimedia Commons, CC BY-SA 4.0).

One stolen login and 346 million rows

The ministry told the story in installments, which does not make it easier to follow. On the night of July 25, someone logged in with a staff member's credentials to the system that manages teacher training, a peripheral service that should matter only to teachers on a course. The ministry's security center raised the alarm on the 26th, external access was cut within hours, and a crisis unit was set up. The July 31 statement specified that the system held "no banking data, no passwords, and no data on students," only the identity and job details of staff, plus for some of them a home address, a phone number, and a social security number[1].

On August 17, a hacker going by ZeroBytes posted what they said they had taken, and the list went far beyond the announced scope. They claim 43 GB across some 2,500 files, or 346 million raw rows spanning two decades, and once duplicates are removed, 1.22 million distinct students, 4.35 million staff identifiers, and 602,000 academic accounts. The files include exports from SCONET, the tool that manages middle and high school students, for the 2024-2025 and 2025-2026 school years, and extracts from the elementary school student database for the Créteil school district, along with grades, assessments, and details on legal guardians scattered through the files[2]. The data reportedly comes mostly from the Créteil and Versailles districts, plus I-Prof, the career management tool for teachers[3]. My district is Versailles, and my daughter is in preschool.

The next day the ministry published a second statement. All potentially affected staff had been notified individually, forensic work was continuing to establish "the exact nature and extent of the exfiltrated data," and should students turn out to be involved, their legal guardians would be informed "under the same conditions as staff"[4]. Three weeks later I am still waiting to learn whether that conditional applies to me. On August 12, the same ZeroBytes had claimed the theft of 678,000 tax records from the French tax authority, confirmed by the agency the following day, again through a staff member's stolen credentials[5]. One summer, two ministries, the same key.

The school year opened on paper

As a precaution, the ministry reset every login to its services, and at the end of August it announced that 28 of its 30 school districts were back to normal. In Toulouse and Nantes, staff email and professional applications stayed down until further notice, families had lost access to the school portal, and timetables would be handed to students "in paper format"[6]. The OTP-ODA keys, the strong-authentication tokens that give some staff a one-time code, had also been disabled on orders from ANSSI, the national cybersecurity agency[7]. Principals described preparing the school year blind, with no way to see which teachers had been assigned to them, no way to send out the supply list, and no way to pay the summer's invoices[3:1].

Where we live, in a district reportedly spared on the service side, none of that showed. School opened on time, the app that connects the school, the after-school program, and the parents never went down, and the administration asked again in September for what it has held since last year, without asking the one question that would have reassured me, "is this information still correct?" We are used to it. Except that this year, between the two collections, a copy of the first one may have landed on a forum, and no line on the forms mentions it.

Spring had already served as a rehearsal

This is not the year's first incident, or even the first to touch students. On April 14, the ministry acknowledged a "targeted cyberattack" on the service that manages ÉduConnect accounts, the single sign-on for students and their parents. There too, everything started with the hijacked account of an authorized staff member, in late 2025, exploiting a flaw "identified in December 2025 and fixed by the ministry's teams" shortly before it was patched. Last names, first names, identifiers, schools, classes, email addresses, and activation codes for accounts not yet opened had leaked, for a number of students "still being assessed." The statement announced "work to strengthen access security through a two-factor authentication mechanism"[8].

Three months later, another hijacked account opened another service, and the statement used the same verbs. The FSU, the largest federation of teachers' unions, calls it "culpable negligence" and counts this as the third known breach, while the Sgen-CFDT, a union of education staff, points out that the ministry runs some 400 applications, each one a door to watch, and asks for IT staff hired in-house rather than contractors[9]. I don't know the headcount of the ministry's digital department, but I can count doors.

One key, every door

My job is to get IT projects delivered, not to secure them, so I am speaking here as a user who has read the statements. Three things in them stand out.

The path, first. In both of the summer's cases, at the tax authority and at the education ministry, the intruder forced no door. They borrowed a staff member's key and walked in through a side service, teacher training here, an internal search tool there, before reaching millions of records that had nothing to do with that service. An account should open only what its holder needs, and a training coordinator has no need for the grades of students in Créteil.

The volume, next. Pulling 346 million rows means running automated queries for hours, which no employee does by hand. A bank blocks a card the moment three payments land too close together in two different countries. That a staff account could siphon off two decades of data without tripping an alarm suggests that nothing was watching the flow rate, on top of the lock that gave way.

The year, last. In 2026, you can still get into the French education ministry's systems with a username and a password, which is to say with what a successful phishing email collects in ten seconds. Strong authentication[10] has been around for years, a temporary code on your phone or, better, a passkey[11] that cannot be replayed on a fake site. The ministry promised it in April for ÉduConnect and hands out OTP keys to some of its staff, which did not stop a hijacked account from opening the door in July, and the app my daughter's school uses to write to me offers none at all. July's hijacked account says plainly that the work is not finished.

What I did while waiting for the letter

With no news, I did what a parent can do, which is not much. I changed the password on the school app, just in case, and noticed along the way that it offers no second factor. Then I spent an evening walking my partner through the risk, because a stranger who knows our phone number only becomes dangerous the day they use it. A hacker who has the school's name, the class, the child's first name, and the parents' cell numbers writes a far more convincing text message than a fake parking fine. The 678,000 files from the tax authority hand them the other half of the script.

The rules fit on three lines, which I repeat here for anyone who wants to stick them on the fridge. Never scan a QR code that arrives by mail or text; type the address of the tax site or the school portal yourself. If there is no other way, read the full address before entering anything, and at the slightest doubt, wait for the person in the family who does this for a living to take a look. The ministry says the same thing in one sentence, it never asks for logins, passwords, or bank details by email, phone, or text[4:1], and that sentence is about the only one it has addressed to families since July 25.

What I would have liked to receive takes even fewer words. A message, even one that says "we don't know yet," rather than a conditional buried in a statement parents never read. And, on the September stack, a box reading "is this information still correct?" in place of the annual collection of what the administration already holds. High schools banned phones on the first day of class, and the state wanted to verify the age of every internet user to protect children from social media. I would like it to protect what it has already asked them for just as carefully.

Notes

  1. French education ministry, "Incident de sécurité affectant les données de personnels de l'éducation nationale" (in French), statement of July 31, 2026. ↩︎

  2. The figures are the hacker's own claims, examined by Cyberattaque.org in "Éducation nationale, ZeroBytes revendique le vol de 346 millions de lignes de données" (in French), August 18, 2026, and picked up by CNews in "Piratage massif de l'Éducation nationale, ce que l'on sait de l'attaque" (in French). The ministry has neither confirmed nor denied them as I write. ↩︎

  3. Franceinfo, "La cyberattaque dans l'Éducation nationale complique la préparation de la rentrée scolaire dans certaines académies" (in French), August 22, 2026. ↩︎ ↩︎

  4. French education ministry, "Incident de sécurité affectant des données détenues par le ministère de l'Éducation nationale" (in French), statement of August 18, 2026. ↩︎ ↩︎

  5. Silicon, "Piratage de la DGFiP, ce que l'on sait vraiment" (in French). The intrusion dates back to late June, the claim to August 12, and the tax authority's confirmation to August 13. ↩︎

  6. French education ministry, "Cyberattaques contre le ministère de l'Éducation nationale, point de situation à l'approche de la rentrée" (in French), August 31, 2026. ↩︎

  7. Génération-NT, "Chômage technique à l'école, la cyberattaque de l'Éducation nationale paralyse la rentrée" (in French), August 24, 2026, which also notes that the Paris and Versailles districts were relatively spared by the outages. ↩︎

  8. French education ministry, "Incident de sécurité affectant les données de certains élèves de l'Éducation nationale" (in French), statement of April 14, 2026. ↩︎

  9. Le Café pédagogique, "Éducation nationale, une fuite des données qui inquiète" (in French), August 24, 2026, for the FSU and SNES reactions, and the Sgen-CFDT federation, "Cyberattaques dans l'Éducation nationale, la stratégie numérique en question" (in French), September 1, 2026. ↩︎

  10. Strong authentication requires, on top of the password, proof that you hold something, most often a temporary code generated by an app on your phone. A stolen password alone no longer gets anyone in. ↩︎

  11. A passkey replaces the password with a pair of cryptographic keys stored on your phone or computer and unlocked by fingerprint or face. It only works on the genuine site, which makes a phishing site useless. ↩︎

  1. High school hangs up as AI enrolls

  2. France's teen social media ban never reached September

  3. Banning teens from social media without knowing how