346M Records Stolen, French Education System Paralyzed: ZeroBytes' Ransomware Masterstroke

346M Records Stolen, French Education System Paralyzed: ZeroBytes' Ransomware Masterstroke

TL;DR

  • 346M Records Stolen, France's Education System Paralyzed by ZeroBytes Ransomware. Is your school district's cybersecurity plan just "print everything"?
  • $899 Pixel 11 Ships Without Memory Safety—Google Drops MTE for $4 Margins. Would you still buy a $899 phone that removed the one feature making it secure?

🔓 ZeroBytes Decides The French Education System Needed A "Digital Detox"

346 million lines of employee data stolen, then the entire French education system bricked. 🇫🇷🔓 ZeroBytes took down the Éducation Nationale so hard teachers are back to paper gradebooks and carrier pigeons. Payroll still works though — gotta make sure the checks clear 💸 France spent €200M on cybersecurity. The winning play? A Brother laser printer and a ream of A4. So, still feeling good about that cloud-first school district strategy?

Remember when "back to school" meant buying notebooks and calculators? Welcome to 2026, where France's rentrée scolaire comes with a side of ransomware, courtesy of ZeroBytes.

Since July 31st, the hacktivist duo has been systematically dismantling the digital infrastructure of France's Éducation Nationale — first exfiltrating 346 million lines of raw employee data (identity, professional status, SSN, contact info for agents dating back to 2001), then locking down the ministry's IT systems entirely by late August. The result: the Nantes academy forced to halt operations, the Toulouse academy's IT department completely dark, and school principals staggering their return starting August 17 only to find they still cannot access email or educational software. Teachers are now operating on paper—which, ironically, might be the most resilient technology in this equation.

How it works: ZeroBytes launches a sustained assault → network services collapse → teachers scramble for whiteboard markers → the entire system reverts to 1995. 🎯

The real punchline? Payroll is running smoothly. Yes, the one thing that actually matters to the system's operation—paying people—is apparently untouchable. Meanwhile, the FSU Pays de la Loire released a statement on August 27 warning that schools face "Error 404" issues with no functional digital tools despite the September 1st back-to-school deadline, because when the state's cybersecurity fails, the professeurs bring their own flashlights.

The impacts are deliciously absurd:

  • Operational: Zero communications between teachers, staff, and parents. School access limited in affected academies. The ministry suspended digital tools nationwide as a "preventive measure" post-attack — discovering the vulnerability exists and then removing the bandage, in classic bureaucratic fashion.
  • Human scale: Teachers now rely on paper gradebooks, handwritten attendance sheets. Édouard Geffray's team assured France would have enough professors for the 2026 rentrée, but neglected to mention they'd need carrier pigeons to coordinate them.
  • Institutional response: The same ZeroBytes group that breached DGFiP's tax database on June 30 (exfiltrating over 2 million residential profile rows via unauthorized access), then hit ZeroLogementVacant on August 30 (678,000 individuals' names and property IDs leaked), also owns the Education Ministry's crown jewels. Two hundred million euros in cybersecurity spending, and the winning strategy is a Brother laser printer and a ream of A4.

The forecast: The ministry projects ENT digital workspaces relaunching September 7. Translation: ZeroBytes will move on when they get bored—likely after probing deeper archived sites in September, since their black-market operations remain active. The duo's M.O. (same IP block, reverse-engineered certificates, Python scripts embedded in PHP pages) means they'll keep raiding until law enforcement tracks the cryptocurrency trails toward probable arrests.

ZeroBytes claims this is retaliation for previous breaches of French state facilities. The message failed to deliver properly, but the payload didn't need one—ransomware speaks louder than words when 149 million raw records are sitting on a darknet server and you're sending your kid to school with a paper attendance slip.

The real lesson: France just demonstrated that a nation's education system can be paralyzed by a single motivated two-person crew, and the contingency plan is literally "print everything." None of these attacks involve political propaganda—intelligence treats them as pure crime rings timed around French municipal quarterly reporting deadlines. No ideology, just cash.

🎬 Stay hacky, stay angry, and for god's sake, keep a paper backup.


😄 Google’s Pixel 11 Ships Without Memory Safety—Because Why Bother?

Google hiked the Pixel 11 to $899, then quietly ripped out the memory safety feature that catches 40–60% of exploits. You know, the one Qualcomm chips had years ago. 😄 The Tensor G6 dropped hardware MTE to save ~$4–$6 per die. Software MTE is 2–3x slower. GrapheneOS won't touch it. Apple's iPhone 17 ships with full MTE for $100 less. Four dollars of margin vs. your data, your compliance, your device security. Pixel 11 costs $899. They cut the one thing that made it secure. Still calling it a "strategic trade-off." You trust this company with your phone?

So Google raised the Pixel 11’s base price to $899 on August 5th—and in return, you get a chip that neuters one of mobile security’s few real defenses.

Researchers at UT Austin and graphaegos confirmed what should’ve been a headline: Qualcomm’s custom Tensor G6 silicon drops Memory Tagging Extension (MTE) hardware support. MTE caught 40–60% of memory corruption bugs in Chrome and Android allocator tests. Now it’s gone. Not because physics. Because cost. Days later, a Redis hiredis memmove bug (2026-07-22) triggered segfaults and use‑after‑free in Ruby builds—exactly the class of exploit hardware MTE would have caught at runtime.

MTE Killed for Margins, Users Left Holding the Bill

The mechanics are simple. MTE tags every memory allocation with a 4-bit color. On access, the hardware checks the tag. Mismatch = crash before exploit. Without it, Google reverted to software-only tagging, which adds latency and leaves common heap/spray attacks wide open.

The causal chain:

  • GPU cluster size was cut to meet thermals, forcing MTE logic off-die—confirmed by AURAS’s 1000W cooler demo at Computex 2026-06-06, signaling the thermal ceiling for next-gen mobile chips
  • Software MTE replaces hardware enforcement → 2–3x performance penalty on pointer-heavy apps
  • Bootloader unlock remains locked tight, so GrapheneOS and other hardened forks can’t compensate

GrapheneOS’s lead developer already stated the Pixel 11 will not receive official support. That decapitates the one Android device that rivaled iPhone’s privacy posture. Meanwhile, Honda recalled 880,514 vehicles on 2026-06-10 for corrosion-induced rear suspension failures, then another 1,049,883 units on 2026-06-11 for cap detachment hazards—underscoring how device makers across industries keep shipping broken memory paths and calling it acceptable risk.

Scores: Apple 1, Google 0 (Again)

Same week, Apple launched the iPhone 17 with full hardware MTE, tighter memory tagging, and lower base price ($100 less than Pixel 11). The outcome isn't subtle:

  • Institutional buyers (HIPAA, FedRAMP environments) now default to iPhone 17, since Google’s Tensor G6 7-core lands +7% single-core but –12% multi-core vs Tensor G5 (Geekbench, 2026-08-10)—regressing on performance and security simultaneously
  • Android secure‑phone advocates shift to Motorola’s Wukong (Snapdragon 8 Gen 5, MTE enabled, $699)
  • Pixel 11 Pro ($1,099) ships the same broken memory path—Geekbench listings confirm zero SKU differentiation in memory hardening

The Real Beauty: This Was Predictable

Qualcomm’s Snapdragon 8 Gen 4 had MTE. Google’s in-house Tensor team chose to drop it during floorplan optimization in late 2025. The semiconductor cost delta? Roughly $4–$6 per die. Four dollars. For a device starting at $899.

Impact Detail
Memory exploit resistance ~55% reduction vs. Pixel 10 + GrapheneOS
Corporate compliance eligibility Drops below FedRAMP / HIPAA thresholds
User migration Est. 120,000–180,000 Pixel security users switch within 6 months

What Now?

Hardware memory safety became the line. Google blinked. Motorola, Apple, and secondary markets in Asia (where local ROMs already bypass Google services) soak up the bleeding. The ironic hook? Pixel was supposed to prove Google could do hardware right. Instead, it proved they’ll ship a $900 phone with a security feature older Qualcomm chips had—and call it a strategic trade-off.

Or in management speak: enhanced user adaptation needed for the Pixel Glow transition.

Fuck off 😄