Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > French Land Data Platform Géofoncier Faces 4.2M-Record Breach Claim

French Land Data Platform Géofoncier Faces 4.2M-Record Breach Claim

By: Morgan Cipher Senior Privacy Journalist

Last updated: September 3, 2026

Human Written
French Land Data Platform Géofoncier Faces 4.2M-Record Breach Claim
  • ZeroBytes claims it accessed Géofoncier through an authenticated account with API access and extracted 4,226,008 lines.

  • The alleged data includes surveyor details, firm records, office locations, land files and document metadata.

  • The claim hasn’t been confirmed yet by Géofoncier, and there’s no evidence that the number of records equals the number of people affected.

A hacker group called ZeroBytes recently claimed another attack against a French organization. This time, the target is Géofoncier, a platform that brings together land and property information.

In a post dated September 1, ZeroBytes claimed to have obtained 4,226,008 lines of data from the service. The hacker also shared samples to support the claim.

However, there is no public confirmation from Géofoncier that a breach occurred. FrenchBreaches, which tracks cybercrime claims, listed the incident as a claim rather than a confirmed breach.

That makes the exact impact hard to judge. The data may contain a mix of public information and records that normally require an account.

What ZeroBytes Says It Accessed

According to the claim, the stolen data falls into several groups. ZeroBytes says the archive contains information on 6,782 surveyors or other professionals. It also lists 2,151 offices and 6,448 firms or organizations.

The largest group contains about 4.2 million records tied to land files or property-related work. Together, the hacker puts the total at 4,226,008 lines.

The samples reportedly include firm names, office addresses, phone numbers and professional email addresses. Some records also contain professional numbers and the names of surveyors linked to firms.

The land records appear more detailed. Reported fields include file references, surveyor IDs, dates, municipality codes and the type of land operation.

Some records also contain geographic data. These fields can include latitude, longitude, map shapes and cadastral references. The information can therefore connect a land file with a location, date, firm and surveyor.

The Alleged Attack Path

ZeroBytes says it did not break directly into every part of Géofoncier. Instead, the hacker claims to have found an authenticated account with access to the platform’s API.

An API allows one system to request information from another system. Géofoncier confirms that it offers an API for professional software. Its platform also uses authenticated accounts for some services.

That makes the claimed attack path possible in principle. But it does not prove that ZeroBytes used this method or show how the account was obtained.

The hacker has not publicly explained whether the account belonged to a surveyor, another professional user, or a different type of customer.

The account’s permissions also remain unknown. If the account had broad access, an attacker could use automated requests to collect large amounts of information. If its access was limited, the real size and sensitivity of the exposure could be much smaller.

What the Samples Reveal

The reported samples contain several types of information. Some records concern firms and offices. They can include the legal name of a firm, an internal number, its legal structure, address, phone number and geographic position.

Other records concern individual surveyors. These can include a professional number, status, name, first name and professional email address. The samples also contain land-file information. Reported fields include file identifiers, dates, municipality codes, and references to the firm or surveyor involved.

Some entries contain information about documents linked to land files. One reported example refers to a boundary plan connected to a property subdivision. The sample appears to show document metadata rather than the PDF itself. It also reportedly marks the document as not visible.

That distinction matters. A reference to a private document does not prove that the attacker downloaded the document. Géofoncier says users can control access to shared documents. Its website states that users can decide who can view each document and limit access to authorized people.

Much of the Data may Already be Public

The claim also needs context because not every field appears secret. Géofoncier itself says the platform brings together data from institutional sources and surveyors. It also offers a public version of the service and has connected its platform with public geographic services.

Firm names, office addresses, business phone numbers, and some professional details can appear in public directories. Some land and geographic information can also come from open government datasets.

ZeroBytes reportedly acknowledged that some of the information may already be public. The hacker appears to have gathered different datasets into one archive. That still does not make the entire database public.

Internal references, account-linked records, document metadata, and information available only to authenticated users could carry more risk.

4.2 Million Lines does not Mean 4.2 Million Victims

The headline number may sound enormous, but it should not be treated as a victim count. One property can generate several records. The same firm or surveyor can also appear many times.

Géofoncier serves surveyors, notaries, real estate professionals, local authorities, major property owners and individuals. Its paid Expert service includes more than 200 data layers from official sources.

The real question is what the alleged account could access. When the archive is mostly public info, privacy risks stay pretty low. But if that account leaked files that were supposed to stay private, stuff meant only for logged-in users—then it turns into a much bigger problem.

Another ZeroBytes Claim in France

The Géofoncier claim follows several other attacks linked to ZeroBytes. The group has claimed responsibility for attacks involving French organizations, including the Directorate General of Public Finances and the Ministry of National Education.

The French tax authority confirmed that attackers compromised data involving at least 678,000 individuals and professionals. French authorities also investigated unauthorized access involving the education ministry, although the full scope of the data claimed by ZeroBytes remains unclear.

ZeroBytes claims to have stolen France’s DataFoncier 2024 file from a government housing platform, exposing roughly 48 million unique records with names, birth dates, property IDs, phones, and emails. The government hasn’t confirmed the breach, though PM Sébastien Lecornu has acknowledged systemic weaknesses in French state systems.

The Géofoncier case is different because public evidence has not yet confirmed the breach. For now, all we have is ZeroBytes’s claims of accessing Géofoncier and extracting 4,226,008 lines of data.

The samples suggest that the archive contains a mix of professional, geographic, and land-file information. But there is no evidence yet that 4.2 million private documents have been exposed. Only if the Géofoncier or any other reputable organization verifies this report can we say it is a fact.

Share this article

You might also like

Cyberattacks Target U.S. Water Systems as Critical Infrastructure Threats Escalate

Foreign cyber actors have set their sights on crucial infrastructure in the US, with an emphasis on power grids, digital…

September 3, 2026
Russian National Faces US Charges Over Malware Sent through 255 Fake Accounts

Russian National Faces US Charges Over Malware Sent through 255 Fake Accounts

Federal authorities extradited 40-year-old Russian national Searzhudin Tamirlanovich Aktulaev from Cyprus to face serious computer fraud and identity theft charges…

September 2, 2026
13 Malicious Packagist Packages Target iPhones With Spyware and Crypto Stealer

13 Malicious Packagist Packages Target iPhones with Spyware and Crypto Stealer

Security researchers discovered 13 trojanized Composer theme packages on Packagist that target movie and comic streaming websites to inject harmful…

September 2, 2026

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.