Hackers claim to have accessed property-owner data on French official website

Warnings over phishing and scam attempts as data offered for sale

Glowing padlock icons hover above a laptop keyboard in a dark cyber security scene.
It is the latest in a string of major cyberattacks against the French government this summer

Hackers in France claim to have accessed a French government housing platform in the latest major cyberattack on government institutions. 

The ‘ZeroBytes’ hacking group said they accessed 149 million records on the ‘Zéro logement vacant’ website in a post on a cybercriminal forum.

The website is used by local authorities to help bring vacant homes back onto the property market. The site, which is not fully accessible to the public but used by local government authorities as well as owners of empty homes, was not accessible on Sunday afternoon.

The hacking group was behind a major attack on the French tax services earlier in August. 

The attack has not been confirmed by the French government.

Several datasets breached 

The exact nature of the records taken in the alleged breach is unknown, but French cybersecurity website FrenchBreaches – which reported on the alleged leak – says the hackers claim to have taken 149 million records.

Estimates of the number of individuals impacted vary wildly - from 47.9 million, to 71 million. Data sets contained potentially 82 million lines on ownership records, although this does not mean 82 million individual owners were affected.

One of the data sets taken originated from French tax authorities and reportedly contained more than 66 million records. 

Data sets are often shared between government institutions, and hackers were not able to further access more data or IT infrastructure of the French tax authorities.

The incident has raised wider concerns about security across interconnected government systems.

Warnings over scams

The ‘149 million’ figure – while striking – correlates to the number of ‘lines’ of data taken overall, and not the total number of accounts or people impacted.

The exact number is difficult to know due to the potential for duplicated information, as various tables and sources make up the 149 million records.

These records could contain names, dates of birth, postal addresses, and potentially various identifiers, which can be used to identify property owners.

The hackers also claim that among the data taken there are more than 10,700 unique emails and 6,800 phone numbers linked to account holders on the Zéro logement vacant website.

Information taken in the breach is reportedly being sold online to cybercriminals. 

It can be used in phishing attempts by scammers, claiming to be government workers or calling from your bank, etc, to increase their legitimacy and ask you to hand over sensitive information.

People in France should in general be on increased alert over the risk of these phishing schemes, however this is particularly the case if they have a record on the Zéro logement vacant website. 

Were passwords compromised?

The hackers also claim to have accessed sensitive data from around 3,500 account holders on the website.

This includes ‘bcrypt’ cryptographic password hashes – these are not passwords themselves but are used by websites to verify a correctly entered password without needing the password itself to be saved in plain writing. 

The group also claims to have information about log-in authorisations and data on over 1,600 session tokens classified as ‘active’. 

These tokens are used for recently logged-in accounts to avoid them having to put passwords in again for each function. 

They can, however, be revoked or expire before being able to be used by any third party.