-
A hacker claims to have stolen two databases tied to France’s Ministry of Ecological Transition.
-
The alleged files contain data on 8,166 users and 14,656 controller records.
-
Several ministry-linked government websites went offline as the ministry confirmed a sophisticated cyberattack.
France’s Ministry of Ecological Transition faces a cyberattack that has disrupted several government websites. Now, a threat actor claims responsibility for the breach. They claimed to have accessed thousands of entries connected to the systems of ministries.
The hacker made this claim on September 2, 2026, on a cybercrime forum. The user goes by the name “mondial.” The post says the attacker extracted two databases from systems tied to the developpement-durable.gouv.fr domain. The claimed data includes names, work email addresses, phone numbers, employee numbers, logins and other professional details.
French authorities have yet to confirm the data theft claim. However, the wider cyberattack is confirmed. The ministry told AFP on September 2 that its ministerial group suffered a “sophisticated cyberattack” the previous week.
Several Government Websites Go Offline
The attack came to light as several websites linked to the ministry became unavailable. Visitors to the affected sites saw maintenance notices and could not access normal services. The environmental public consultation platform was among the affected services. Several regional government sites also faced outages.
The outages added weight to reports of a serious security incident. The ministry initially described the disruption as an IT incident. It later confirmed the cyberattack to AFP.
The ministry said the attack targeted its messaging tools. It also said officials had taken special steps to contain the incident and strengthen its information systems. Additionally, the ministry has reported the case to prosecutors.
France’s National Cybersecurity Agency, ANSSI, is also helping with the response. ANSSI said the attack may have compromised some user accounts. It added that investigations and recovery work could cause temporary breaks in online services.
Hacker Claims Two Large Databases
The threat actor claims access to two files. The first file, called controllers.csv, allegedly contains 14,656 records linked to controllers. The samples shown in the hacker’s post include names, dates of birth, approval numbers, internal numbers, job roles, and mobile phone numbers. The second file, called all_users.json, allegedly contains information on 8,166 users.
The data shown in the samples goes well beyond email addresses. It comprises 8,166 unique email addresses, 5,278 landline numbers, and 3,642 mobile numbers. Moreover, the hacker says that this file contains 4,849 registration/employee numbers. In addition, the data also lists 942 units or departments.
Meanwhile, these data samples allegedly include names, professional e-mail addresses, phone numbers, and office information. It also contains professional addresses, user ID and login. In addition, there are some fields relating to an LDAP directory that is used by organizations for managing user accounts and organizational structure.
Some samples point to accounts linked to the General Commission for Sustainable Development, or CGDD, including staff in La Défense.
The Numbers Need Careful Reading
The figures in the hacker’s post do not prove that the same number of people suffered exposure. For example, 14,656 is the number of records claimed in controllers.csv. It does not mean 14,656 different people. Some records may belong to the same person.
The 8,166-user figure also comes from the alleged database. French authorities have not confirmed the file’s authenticity, its full scope or the number of people affected.
Also, reports suggest the attack didn’t compromise the entire ministry infrastructure. The exact date of the initial intrusion and the length of the attacker’s access remain unknown.
Claims of an API Flaw and OISO Attack
The hacker says a poorly configured API helped provide access to the systems. The post also claims an IDOR flaw in OISO, an application used for monitoring organizations. An IDOR flaw can let a user access another person’s data when a system fails to check permissions correctly.
Still, the technical claims need independent proof. The hacker has not provided enough detail to confirm the API problem or reproduce the alleged IDOR flaw. No password appears in the data samples reviewed in the source material.
Why the Alleged Leak Matters
If the data proves genuine, it could give criminals a strong base for targeted phishing. An attacker could combine a worker’s name, job, email address, phone number, department, and login details. That information could help create messages that look like they came from a colleague, manager or IT team.
The risk goes beyond generic spam. A criminal with accurate workplace details can craft a message around a real department or project. That can make a fake request harder to spot. For now, however, the data leak remains a claim.
What France has Confirmed
The key distinction is clear. France has confirmed the cyberattack, but it has not confirmed the hacker’s alleged data theft. The ministry told AFP that the attack hit its messaging tools the previous week. It also confirmed that officials reported the incident to prosecutors.
ZeroBytes is running wild in France. After hitting the Ecological Transition, they now claim a massive education ministry breach of 43GB of data, 346 million lines, affecting students, parents, and staff. The ministry admits an intrusion on July 25 via a compromised account but won’t confirm the damage. Summer of leaks.
At the same time, several ministry-linked websites remained inaccessible, while ANSSI worked with affected administrations. Those facts show that France is dealing with a real cyber incident. But they do not, on their own, prove that the hacker obtained all the data listed in the forum post.
The investigation will need to establish how the attacker entered the systems and what they accessed. Also, they’d need to determine whether the claimed databases came from ministry infrastructure. Until authorities confirm those points, the 8,166 users and 14,656 controller records remain alleged exposure figures, not confirmed victims.