-
ZeroBytes claims it accessed Géofoncier through an authenticated account with API access and extracted 4,226,008 lines.
-
The alleged data includes surveyor details, firm records, office locations, land files and document metadata.
-
The claim hasn’t been confirmed yet by Géofoncier, and there’s no evidence that the number of records equals the number of people affected.
A hacker group called ZeroBytes recently claimed another attack against a French organization. This time, the target is Géofoncier, a platform that brings together land and property information.
In a post dated September 1, ZeroBytes claimed to have obtained 4,226,008 lines of data from the service. The hacker also shared samples to support the claim.
However, there is no public confirmation from Géofoncier that a breach occurred. FrenchBreaches, which tracks cybercrime claims, listed the incident as a claim rather than a confirmed breach.
That makes the exact impact hard to judge. The data may contain a mix of public information and records that normally require an account.
What ZeroBytes Says It Accessed
According to the claim, the stolen data falls into several groups. ZeroBytes says the archive contains information on 6,782 surveyors or other professionals. It also lists 2,151 offices and 6,448 firms or organizations.
The largest group contains about 4.2 million records tied to land files or property-related work. Together, the hacker puts the total at 4,226,008 lines.
The samples reportedly include firm names, office addresses, phone numbers and professional email addresses. Some records also contain professional numbers and the names of surveyors linked to firms.
The land records appear more detailed. Reported fields include file references, surveyor IDs, dates, municipality codes and the type of land operation.
Some records also contain geographic data. These fields can include latitude, longitude, map shapes and cadastral references. The information can therefore connect a land file with a location, date, firm and surveyor.
The Alleged Attack Path
ZeroBytes says it did not break directly into every part of Géofoncier. Instead, the hacker claims to have found an authenticated account with access to the platform’s API.
An API allows one system to request information from another system. Géofoncier confirms that it offers an API for professional software. Its platform also uses authenticated accounts for some services.
That makes the claimed attack path possible in principle. But it does not prove that ZeroBytes used this method or show how the account was obtained.
The hacker has not publicly explained whether the account belonged to a surveyor, another professional user, or a different type of customer.
The account’s permissions also remain unknown. If the account had broad access, an attacker could use automated requests to collect large amounts of information. If its access was limited, the real size and sensitivity of the exposure could be much smaller.
What the Samples Reveal
The reported samples contain several types of information. Some records concern firms and offices. They can include the legal name of a firm, an internal number, its legal structure, address, phone number and geographic position.
Other records concern individual surveyors. These can include a professional number, status, name, first name and professional email address. The samples also contain land-file information. Reported fields include file identifiers, dates, municipality codes, and references to the firm or surveyor involved.
Some entries contain information about documents linked to land files. One reported example refers to a boundary plan connected to a property subdivision. The sample appears to show document metadata rather than the PDF itself. It also reportedly marks the document as not visible.
That distinction matters. A reference to a private document does not prove that the attacker downloaded the document. Géofoncier says users can control access to shared documents. Its website states that users can decide who can view each document and limit access to authorized people.
Much of the Data may Already be Public
The claim also needs context because not every field appears secret. Géofoncier itself says the platform brings together data from institutional sources and surveyors. It also offers a public version of the service and has connected its platform with public geographic services.
Firm names, office addresses, business phone numbers, and some professional details can appear in public directories. Some land and geographic information can also come from open government datasets.
ZeroBytes reportedly acknowledged that some of the information may already be public. The hacker appears to have gathered different datasets into one archive. That still does not make the entire database public.
Internal references, account-linked records, document metadata, and information available only to authenticated users could carry more risk.
4.2 Million Lines does not Mean 4.2 Million Victims
The headline number may sound enormous, but it should not be treated as a victim count. One property can generate several records. The same firm or surveyor can also appear many times.
Géofoncier serves surveyors, notaries, real estate professionals, local authorities, major property owners and individuals. Its paid Expert service includes more than 200 data layers from official sources.
The real question is what the alleged account could access. When the archive is mostly public info, privacy risks stay pretty low. But if that account leaked files that were supposed to stay private, stuff meant only for logged-in users—then it turns into a much bigger problem.
Another ZeroBytes Claim in France
The Géofoncier claim follows several other attacks linked to ZeroBytes. The group has claimed responsibility for attacks involving French organizations, including the Directorate General of Public Finances and the Ministry of National Education.
The French tax authority confirmed that attackers compromised data involving at least 678,000 individuals and professionals. French authorities also investigated unauthorized access involving the education ministry, although the full scope of the data claimed by ZeroBytes remains unclear.
ZeroBytes claims to have stolen France’s DataFoncier 2024 file from a government housing platform, exposing roughly 48 million unique records with names, birth dates, property IDs, phones, and emails. The government hasn’t confirmed the breach, though PM Sébastien Lecornu has acknowledged systemic weaknesses in French state systems.
The Géofoncier case is different because public evidence has not yet confirmed the breach. For now, all we have is ZeroBytes’s claims of accessing Géofoncier and extracting 4,226,008 lines of data.
The samples suggest that the archive contains a mix of professional, geographic, and land-file information. But there is no evidence yet that 4.2 million private documents have been exposed. Only if the Géofoncier or any other reputable organization verifies this report can we say it is a fact.