Education Ministry data leak: what is exposed and how the risk spreads to students and staff

A breakdown of the August 2026 data breach affecting the French Ministry of Education, detailing the scope of exposed records and the timeline of the intrusion.

Article prepared with AI assistance, then verified, edited, and approved by Nicolas Coutant.

The short version

This briefing covers the data leak reported in August 2026 involving the French Ministry of National Education. It is not a general commentary on state cybersecurity, nor a guide on how to evade digital tracking. The core issue is that an intrusion confirmed in late July 2026 has resulted in the exposure of personal data for both staff and students.

According to reports from Frandroid and FrenchBreaches, the leak involves roughly 43 Go of files containing data on 1.22m distinct students and 4.35m staff identifiers. The data reportedly includes names, postal addresses, phone numbers, and, for some individuals, social security numbers. While the Ministry confirmed the intrusion earlier, the specific scale involving students has only recently surfaced in public reporting.

How it works

The mechanism behind this exposure appears to follow a pattern seen in other recent French administrative breaches. Reports indicate the unauthorized access began in late July 2026 through a compromised professional account. The attackers targeted the system dedicated to staff training.

Once inside, the intruders allegedly extracted data from multiple systems used by the Ministry. The resulting dataset is described as containing records spanning over twenty years. The data is not limited to a single group; it reportedly encompasses students, teachers, administrative staff, parents, and legal guardians.

The leak has been attributed to the cybercriminal group ZeroBytes, the same group that has claimed responsibility for recent attacks on the tax administration (DGFiP). The timeline suggests a swift escalation: the intrusion was confirmed by the Ministry in late July, but the revelation that student data was included came to light in the days following the tax administration leaks in mid-August 2026.

What is sourced

The figures and scope of the leak are drawn from specific claims made by the attackers and reported by digital security outlets. According to Frandroid, the leak includes:

  • 43 Go of files.
  • 4.35m staff identifiers.
  • 1.22m distinct students.
  • 602000 academic accounts.

FrenchBreaches corroborates the volume, citing roughly 43 Go of data. They note that the raw data contains hundreds of millions of lines, though these are not de-duplicated, meaning the same person may appear multiple times throughout the records.

The content of the data reportedly includes identity information, postal coordinates, and telephone numbers. Crucially, for a portion of the people concerned, the data includes social security numbers. The leak has been identified as the third major data breach affecting the Ministry in 2026.

This event occurs in the shadow of the tax administration attacks. Actu.fr reported that the Ministry of Public Accounts presented apologies on 18 August 2026 regarding the tax leak, while simultaneously acknowledging a "third leak" of data related to inheritances. The Education Ministry leak surfaced shortly after these developments, creating a cluster of high-profile administrative breaches.

Caveats

It is essential to distinguish between confirmed facts and reported claims. The Ministry confirmed the intrusion in late July 2026 but did not initially release a precise balance sheet regarding the number of affected individuals. The specific figures regarding the 1.22m students are based on the claims made by the attackers and the analysis of the data by third-party observers like Frandroid and FrenchBreaches.

ZDNET highlights that the critical question remains whether the data of students is definitively affected by this specific leak, or if the exposure is limited to staff. Until the Ministry provides an official confirmation, the extent of the student data exposure should be treated as reported rather than officially verified.

Furthermore, the data volume cited (43 Go) represents the size of the files claimed to be stolen. The actual number of unique individuals affected may differ from the raw line counts provided by the attackers. The presence of social security numbers is reported to apply to "a portion" of the people concerned, not necessarily every record.

What’s next

If the leak involving student data is confirmed, the Ministry has indicated that it will notify the affected individuals individually. In the case of students, the notification will be sent to their legal representatives.

The situation mirrors the response to the tax administration breaches, where the state has acknowledged the intrusion and the subsequent data exposure. The focus will likely shift to verifying the specific contents of the stolen files and assessing the potential for identity theft or fraud.

For parents and staff, the immediate step is to remain alert to communications from the Ministry. If the data has been confirmed to include sensitive identifiers like social security numbers, the risk extends beyond simple spam to potential identity fraud. However, no specific instructions on how to "fix" the data are available yet, as the situation is still evolving.

Going further

Sources

Found an error? Email us — we correct factual mistakes and note significant updates on the article. Contact us

Keep exploring