Threat Actor ZeroBytes Claims Breach of French Housing Platform
A hacker alleges access to 149 million records from Zéro Logement Vacant, a platform linked to the French Ministry of Housing.
A threat actor known as ZeroBytes claims to have breached Zéro Logement Vacant, a platform associated with the French Ministry of Housing. The alleged incident represents a significant security event targeting national property data.
According to reports from Pasquale Pillitteri and cybersecurity outlets including Clubic and MacGeneration, the attacker claims to have accessed a massive dataset. Corrected data indicates the breach involves approximately 149 million records. The stolen information reportedly contains sensitive property-related details, though the specific nature of every data field has not been fully detailed in the public claims.
The Role of Zéro Logement Vacant
Zéro Logement Vacant is an entity focused on the critical social and economic goal of reducing vacant housing across France. Because the platform is associated with the ministère de la Ville et du Logement (Ministry of Housing), it serves as a centralized point for property-related data. The scale of the alleged breach is particularly striking given the volume of records claimed, which would encompass a vast portion of the country's property ownership and housing records.
Implications for National Security
The exposure of 149 million records constitutes a massive privacy failure and creates a systemic security risk for French citizens. When property data is leaked on this scale, it provides a goldmine for malicious actors to conduct highly targeted phishing campaigns. By combining official property records with other leaked datasets, criminals can craft convincing fraudulent communications to deceive homeowners into revealing financial information or granting access to their properties.
Furthermore, this incident highlights the vulnerability of government-linked platforms that aggregate sensitive citizen data. The potential for identity theft on a national scale is high, as property records often contain verified addresses and ownership details that are essential for verifying identity in legal and financial transactions.
Next Steps and Verification
As of now, the breach remains a claim made by the threat actor ZeroBytes. The French Ministry of Housing has not yet released a comprehensive public audit confirming the exact scope of the data exfiltration or the specific vulnerability used to gain access. Observers are now watching for official confirmation from French cybersecurity authorities and whether the data will be leaked on dark web forums or used for extortion. The primary concern remains whether the 149 million records include personally identifiable information (PII) that could lead to immediate financial fraud for millions of residents.