The remarkable thing about this message is not the number. It is the question at the end — and the fact that, as of this writing, no institution in France is in a position to answer it with a record.
Between late June and late July 2026, the actor operating as ZeroBytes claimed intrusions into three French state systems: two at the DGFiP — the tax and land authority — and one at the Ministère de l’Éducation Nationale. The claims were not anonymous rumors; the same pseudonym published samples, named internal systems, and eventually put data online. French press coverage and official communiqués confirmed, in each case, that an intrusion had occurred.
What the official record confirms is narrow and precise. What the actor claims is broad and specific. The two accounts do not meet.
The Ministry of Education, officially: the fraudulent access happened during the night of July 25, via a compromised professional account, against the staff-training information system. The ministry’s security operations center was alerted the following day, July 26. The ministry states it “suspended external access to the affected system” and activated a crisis cell. Disclosure came on July 31: the intrusion “may have led” (« a pu conduire ») to the exfiltration of personal data of “a significant number” of its agents. No count. Three weeks later, the ministry’s communiqué of August 18 states its technical analysis of “the exact nature and extent of the exfiltrated data” is still ongoing — while the data had already appeared online the previous day.
The actor, publicly: entry on July 15 — ten days before the officially acknowledged access — through recovered VPN credentials. Persistence for several weeks after being detected. 346,178,591 raw lines across roughly 2,500 files; by the actor’s own admission heavily duplicated, deduplicating to some 4.35 million staff identifiers and 1.22 million student records spanning two decades. An independent outlet that reviewed the released sample found exports naming genuine ministry systems — consistent with the actor’s claimed categories, but far short of verifying the claimed volume.
Every load-bearing cell in this table is disputed: the entry date, the vector, the dwell time, whether access was cut after detection, and what actually left. And the dispute is not resolvable — not because the truth is complicated, but because only one party kept a complete record, and it is not the defender.
The DGFiP case removes the comfortable explanation. There, per press reporting of the official account, detection worked: the fraudulent access — via compromised credentials of an agent and of an authorized third party — was detected and cut. But the exfiltration itself was not identified at detection. It was confirmed only after ZeroBytes published the data on August 12–13. The confirmed scope: fiscal reference data of some 678,000 individuals, including revenue figures and withholding rates.
Read that sequence again. The defender detected the actor, expelled the actor, and then learned what the actor had taken from the actor’s own publications. Detection succeeded. The record of conduct — what this identity did, touched, and moved while inside — did not exist on the defender’s side of the wire.
This is the pattern in both incidents, and it is worth stating plainly: the intruder operates with a complete private log of its own actions. The defender operates with fragments. When the two accounts diverge — on dates, on dwell time, on volume — there is no independent record against which either can be tested. The taunt is only possible because the actor knows this.
France did not arrive at this exposure by accident or neglect. It arrived by policy — arguably the most deliberate open-government data policy in Europe.
The « État plateforme » doctrine was formalized by decree on August 1, 2014, unifying the state’s information systems around exchange. The api.gouv.fr catalog followed in 2016, referencing the APIs of public administrations in one place. And on October 7, 2016, the Loi pour une République numérique made openness the legal default: public data open as the rule, not the exception, with full effect by October 2018. A decade of engineering went into making state data reachable — for citizens, for developers, for authorized third parties. It is, on its own terms, an achievement.
But openness is a statement about the sender side: what the state exposes, to whom, under what consent. Nothing in that decade of legislation built the corresponding capability on the receiver side: an independent, continuous record of what each actor — human, credentialed, automated — actually does once inside the perimeter. The access surface was opened by law. The conduct record was left to each ministry’s internal tooling, which is precisely the record that, in August 2026, cannot answer a public question about its own intrusion.
To be clear about what this note does not claim: these intrusions did not come through the public API catalog. The vectors, in every account, were compromised credentials — an ordinary door, opened with an ordinary stolen key. That is what makes the lesson general rather than an argument against openness. The failure mode is not the aperture. It is asymmetric bookkeeping: a state that can enumerate everything it exposes, and cannot enumerate what a specific actor did inside it for eight weeks.
ZeroBytes, by every indication, is human — patient, manual, working on a timescale of weeks. The dwell-time dispute in the Education case spans days and weeks: July 15 or July 25, cut on detection or weeks later.
An autonomous agent running the same playbook — credential replay, lateral movement, bulk export — does not need weeks. The same dispute, replayed at machine speed, spans hours: by the time a communiqué says “we suspended external access,” the window in question is no longer measured in press cycles. Every element of this case — the contested entry date, the unverifiable volume, the defender reconstructing its own loss from the attacker’s posts — gets worse under compression. The only element that changes the structure is a record of conduct that exists before the dispute does, held by neither party.
The actor asked the ministry: « Un avis à dire là-dessus ? » — anything to say about that?
Institutions on the receiving side of the next such question might consider what answering it would require. Not a better detector — detection, in the DGFiP case, worked. An answer requires a record: independent of the intruder’s log and of the defender’s fragments, continuous across the window in dispute, and strong enough to be put on the table when the other party is lying — or when it isn’t.
As of this writing, the French state’s technical analysis is ongoing.