The Ministère de l'Éducation nationale disclosed on April 14, 2026 that an attacker impersonated the account of an authorised staff member and used it to reach the pupil account management service linked to ÉduConnect, France's national identity service for schoolchildren and their families. The ministry described a targeted cyberattack that caused a leak of pupils' personal data, and stated that the exact number affected was still being evaluated.
The account impersonation took place at the end of 2025. The ministry's own teams identified the underlying vulnerability in December 2025 and fixed it. They were too late. The statement is explicit that the flaw had already been used before the fix shipped: "Une faille de sécurité dans ce service, identifiée en décembre 2025 et corrigée par les services du ministère, a été exploitée peu avant sa résolution." Roughly four months then passed between that patch and the public disclosure. Two days before that disclosure, a criminal group had already listed the data for sale.
KEY FACTS
- WhatAn attacker impersonated an authorised staff account and exploited a vulnerability in the pupil account management service linked to ÉduConnect to download pupil personal data.
- WhoMinistère de l'Éducation nationale, France. Affected individuals are schoolchildren, a population composed almost entirely of minors.
- HowImpersonation of the account of a "personnel habilité" at the end of 2025, followed by exploitation of a service flaw identified and patched in December 2025 but exploited before that fix.
- DataFirst name, surname, ÉduConnect identifier, school and class, email address where the pupil had supplied one, and activation codes for accounts not yet activated.
- ActorDumpSec claimed the data and listed it for sale on April 12, 2026. No formal technical attribution has been issued. CERT-EU records "an unknown threat actor."
- ImpactNot quantified. The ministry has published no victim count. Under French law the ministry faces neither an administrative fine nor an astreinte.
WHAT HAPPENED
At the end of 2025 an attacker obtained use of the account of an authorised member of ministry staff and used it to reach the pupil account management service tied to ÉduConnect. The ministry has not said how that account was taken, and has not said whether multi-factor authentication was in force on it.
Holding a legitimate staff identity, the attacker then exploited a vulnerability in the service itself. Two distinct failures were chained: an identity failure that supplied trusted access, and an application flaw that converted that access into bulk data retrieval. Neither alone would have produced this outcome.
In December 2025 the ministry's own teams found the vulnerability and corrected it. This is the detail that defines the incident. The flaw was not reported by an outside researcher and was not surfaced by an attacker going public. The ministry found it internally, fixed it, and on its own later account the flaw had already been exploited by that point. Patching closed the hole. It did not undo the theft, and it did not trigger prompt public notification.
On April 12, 2026 the group DumpSec announced it had put an ÉduConnect database up for sale. Journal du Geek reported the listing on April 16: "Ce 12 avril 2026, un groupe de hackers connu sous le nom de DumpSec a annoncé avoir mis en vente une base de données." The ministry's statement followed on April 14, two days after the listing appeared and roughly four months after the patch. The sequencing is worth stating plainly: the public disclosure came after the data was already being advertised, not before.
The ministry says it acted on the technical side. It suspended access to the affected service, carried out a full reset of access codes, and blocked all accounts not yet distributed and activated: "le ministère a immédiatement suspendu l'accès au service concerné" and "le ministère a procédé à une réinitialisation complète des codes d'accès. L'ensemble des comptes non encore distribués et activés a par ailleurs été bloqué." It also said it had begun work to strengthen access security through a double authentication mechanism.
A criminal complaint was filed. Reporting on the April statement also refers to ANSSI being notified.
CERT-EU logged the incident in Cyber Brief 26-05, published May 4, 2026: "On April 14, France's Ministry of Education reported a targeted cyberattack involving impersonation of an authorised staff account and exploitation of a vulnerability in an EduConnect-related student account management service. An unknown threat actor downloaded pupils' personal data, including names, EduConnect identifiers, school/class details, and optional e-mail addresses; some activation codes for inactivated accounts were exposed. " Three weeks after disclosure, the count was still open.
THE VICTIM COUNT DOES NOT EXIST
No official figure has been published. The ministry said in April that the number was under evaluation, and CERT-EU recorded it as under assessment in May.
The figures in circulation come from the seller. DumpSec's April 12 listing, surfaced through the specialist site French Breaches and reported by Journal du Geek, claims a database concerning "plus de 3,5 millions d'élèves, quasi exclusivement des mineurs," together with "7,2 millions de bulletins scolaires, 400 000 rapports ASSR2."
These are marketing claims by a party selling the goods, and the volume is the product. Note also that the listing asserts categories the ministry's own field list does not contain: the ministry names no school reports and no ASSR2 road safety certificates among the affected data. Either the listing overstates its contents, or the ministry's published scope is incomplete. Both possibilities matter, and neither is resolved. No sample has been independently validated in any source retrieved here. These numbers are not a victim count and should not be cited as one.
WHY THE ACTIVATION CODES CHANGE THE SEVERITY
Most of the exposed fields are descriptive: a name, a school, a class, an identifier, sometimes an email. Damaging in aggregate, particularly as a targeting set for social engineering against families, but static.
The activation codes are a different class of data. They were exposed only for accounts "non encore activés par l'élève au moment de l'incident," which is exactly what makes them dangerous. An activation code is not a description of an account. It is the credential that lets whoever holds it complete first-time enrolment and set the password. For an account no pupil has ever activated there is no incumbent user to notice a stranger taking possession, no established password to fail, and no login history to look wrong.
The exposure hands an attacker a pre-positioned account takeover capability against the accounts of children.
The ministry's remediation confirms this reading better than any outside analysis could. It did not merely monitor the affected accounts. It reset every access code and blocked every account not yet distributed and activated. An organisation resets an entire code set only when it accepts that each code is independently sufficient to seize the account it belongs to.
THREE INTRUSIONS IN FOUR MONTHS
This was not an isolated event. The ministry disclosed three separate intrusions between March and July 2026, and each began the same way, with an attacker in possession of a legitimate account.
" The ministry was informed on the evening of Thursday March 19. The data covered "environ 243 000 agents, stagiaires ou titulaires" and included identity elements, contact details comprising address and telephone number, absence periods without health information, and the identity and professional telephone numbers of tutors. ANSSI and CNIL were notified and a complaint was in progress.
Three weeks later came the ÉduConnect disclosure analysed here, following impersonation of an authorised staff account.
On July 31, 2026 the ministry disclosed a third intrusion, into the staff training information system, occurring during the night of July 25 to 26, 2026 following the usurpation of a professional account. The security operations centre was alerted on July 26, external access was suspended and a crisis cell activated. Exposed were identity elements and professional information covering status and functions, and for some staff postal addresses, telephone numbers and social security numbers. The ministry stated the system contained no banking data, no passwords and no pupil data.
The population concerned is agents who served in an académie since 2001. Again no total was given.
The pattern is the story. Three intrusions in a little over four months, each starting from a legitimate account in the wrong hands: an external account in March, an authorised staff account in the ÉduConnect case, a professional account in July. The ministry announced work on a double authentication mechanism in April. Whatever that work covered, it did not prevent a third intrusion through the same class of weakness fourteen weeks later.
An announced control that does not stop the recurrence it was announced for is a weaker position than silence, because the ministry had already identified the problem and said so.
WHAT WAS EXPOSED
The ministry lists the affected fields precisely: "prénom, nom, identifiant ÉduConnect, établissement et classe, adresse email (uniquement si renseignée par l'élève), code d'activation (uniquement pour les comptes non encore activés par l'élève au moment de l'incident)."
- First name and surname of the pupil.
- ÉduConnect identifier, the persistent national handle for the pupil's account.
- School and class, which locates a named child at a specific physical address during predictable hours and identifies their year group and peers.
- Email address, only where the pupil had supplied one.
- Activation code, only for accounts the pupil had not yet activated. These are enrolment credentials, not descriptive attributes.
The ministry's April statement concerns pupils. The staff exposures belong to the separate March and July incidents.
TECHNICAL FAILURE CHAIN
An authorised staff account was taken over at the end of 2025 and used for fraudulent access. The ministry has not disclosed the method or whether phishing-resistant multi-factor authentication was enforced on accounts reaching national pupil records. The March and July intrusions began from an external account and a professional account respectively, which places the failure at the level of account security across the estate rather than in one system.
Once the attacker held one legitimate staff identity they were positioned against the pupil account management service. There is no published indication that access to pupil records was segmented, quorum-gated, or scoped to legitimate need for the compromised role.
Valid staff credentials alone should not yield a downloadable population of pupil records. A flaw in the service converted authorised access into bulk export. Its class has not been disclosed and no CVE has been assigned.
Enrolment credentials for unactivated accounts sat in the same data set as descriptive fields and came out with them. Credentials of this kind should be stored as verifier hashes, or issued just in time, so that reading a record does not yield a usable code.
Accounts pupils had never activated remained outstanding with valid activation codes attached. Codes expiring on a short clock, or accounts auto-voiding when unclaimed, would have reduced the exploitable set to near zero at the moment of the breach.
The exfiltration was not stopped while it happened. The vulnerability was found later by internal review, not by an alert on anomalous volume from a single account.
The flaw was identified and corrected in December 2025 in a system holding minors' personal data. Public notification followed roughly four months later, and only after the data appeared for sale. Discovering a live flaw in an internet-facing identity service should start a forensic retrospective and a notification decision, not end the matter.
INDICATORS OF COMPROMISE
- Affected systempupil account management service linked to ÉduConnect, Ministère de l'Éducation nationale.
- Initial access classimpersonation of an authorised staff account, "usurpation d'identité du compte d'un personnel habilité."
- Exploited weaknessan unclassified vulnerability in the pupil account management service, identified December 2025, corrected December 2025, exploited prior to correction. No CVE assigned.
- Exposure windowend of 2025 through the December 2025 fix.
- Actor aliasDumpSec, claiming the data and listing it for sale on April 12, 2026.
- Claim surfaced viaFrench Breaches.
- Disclosure dateApril 14, 2026.
- Related systemsCOMPAS trainee management, fraudulent access March 15, 2026 via an external account. Staff training information system, intrusion the night of July 25 to 26, 2026 via a professional account.
REGULATORY EXPOSURE
- GDPR Article 5(1)(f) and Article 32, integrity, confidentiality and security of processing. Account takeover plus an application flaw yielding bulk export of minors' records, repeated across three systems in four months, goes directly to the appropriateness of technical and organisational measures.
- GDPR Article 33, notification to the supervisory authority within 72 hours of awareness. The 72-hour clock runs from awareness of the personal data breach, which is not necessarily the date the vulnerability was patched. The ministry has published no awareness date, and that omission is what prevents the obligation from being assessed.
- GDPR Article 34, communication to data subjects without undue delay where risk is high. Exposed enrolment credentials for minors' accounts is a high-risk exposure on its face. Roughly four months elapsed between the December 2025 patch and the April 14, 2026 statement, and the statement followed the appearance of the data for sale rather than preceding it.
- GDPR Article 8 and Recital 38. Children's personal data merits specific protection because children are less aware of the risks and of their rights. The affected population is almost entirely minors, which raises rather than lowers the Article 32 standard.
- Loi Informatique et Libertés, Article 20, IV. This is the decisive provision and it points away from any financial consequence. Sub-point 7° provides for "À l'exception des cas où le traitement est mis en œuvre par l'Etat, une amende administrative ne pouvant excéder 10 millions d'euros ou, s'agissant d'une entreprise, 2 % du chiffre d'affaires annuel mondial total de l'exercice précédent, le montant le plus élevé étant retenu." Sub-point 2° carries the identical carve-out for the periodic penalty attached to an injunction: an injonction "peut être assortie, sauf dans des cas où le traitement est mis en œuvre par l'Etat, d'une astreinte dont le montant ne peut excéder 100 000 € par jour de retard." Where the processing is carried out by the State, both the fine and the daily penalty are excluded. The Ministère de l'Éducation nationale is the State.
- What remains available against a ministry. The rappel à l'ordre under 1°, an injunction under 2° with no astreinte behind it, limitation of processing under 3°, and suspension of data flows under 5°. Note the drafting: 3° and 5° carve out only processing that concerns "la sûreté de l'Etat," while 2° and 7° carve out State processing as such. The exemption is deliberate and targeted, not an accident of drafting.
- The carve-out is narrow, and CNIL's register proves it. On January 22, 2026 CNIL fined an "établissement public administratif" 5 million euros with an injunction. Public bodies are fined in France. What the statute exempts is l'État specifically. The contrast with the ministry's position is exact: on March 12, 2026 CNIL sanctioned a "ministère" on grounds including "défaut de sécurité des données" and the outcome was a rappel à l'ordre and an injunction with no financial penalty. A public establishment pays 5 million euros for data protection failings. A ministry, for a data security failing, is reprimanded. A private edtech operator losing the same pupil records would face GDPR Article 83(5) exposure of up to 20 million euros or 4 percent of annual global turnover.
- Criminal exposure is not empty. Code pénal Article 226-17 punishes processing personal data without implementing the measures prescribed by, among others, GDPR Article 32, with "cinq ans d'emprisonnement et de 300 000 euros d'amende." That is the same Article 32 obligation engaged by this breach, and the offence attaches to persons rather than to the administrative fine regime the State escapes. Whether it is ever charged here is a separate question, and no prosecution has been reported.
INTELLIGENCE GAPS
The ministry said the figure was under evaluation on April 14, 2026, CERT-EU recorded it as under assessment on May 4, 2026, and no ministry figure appears in any source retrieved for this analysis. The scale of this breach is genuinely unknown.
The 3.5 million pupils, 7.2 million bulletins scolaires and 400,000 ASSR2 reports rest on a sale listing surfaced through French Breaches. No sample has been independently validated. The listing also asserts data categories absent from the ministry's field list, which is unresolved in both directions: the seller may be inflating, or the ministry's published scope may be incomplete.
Whether it knew data had been exfiltrated in December 2025 when it patched, or established that only later, determines whether the Article 33 and Article 34 clocks were met. Only the ministry can close this gap.
The ministry statement as retrieved contains a sentence recording that ANSSI and CNIL were notified, but the identical sentence appears on the March and July notices, and April-specific secondary coverage does not corroborate the CNIL element. A criminal complaint is well corroborated and ANSSI notification is reported. The CNIL element for April should be treated as unconfirmed pending the délibération or an archived copy of the page.
The ministry published no figure for attempted or successful takeovers.
Phishing, credential stuffing, infostealer logs and insider misuse are all consistent with "usurpation." Whether multi-factor authentication was enforced is not stated in any of the three notices.
The ministry said in April it had begun strengthening access security through a double authentication mechanism. Whether that covered the systems breached in July, and whether it had been deployed by July 25, is not published.
Whether it was a broken access control, an insecure direct object reference, or an export function missing authorisation checks is not stated, and no CVE was assigned, so other operators cannot check for the same pattern.
The legal texts underpinning the regulatory analysis are primary and were retrieved directly: Loi n° 78-17 Article 20 and Code pénal Article 226-17 from Legifrance, the sanctions register from CNIL, and Cyber Brief 26-05 from CERT-EU. The incident facts are not primary. education.gouv.fr returns HTTP 403 to direct retrieval, and the ministry notices quoted here were obtained through a text-extraction proxy and corroborated against independent outlets rather than read from the source. Quoted French from those notices should be treated as corroborated secondary text, not as verified verbatim from the ministry.
ZERO|TOLERANCE Advisory
Store them as verifier hashes rather than retrievable values, so that reading a record does not yield a usable code. Bind each code to the single identity it provisions, give it a short expiry measured in days, make it single use, and deliver it out of band from the identifier it activates. A database read should never return a working key to an account.
The exploitable population here was defined entirely by accounts pupils had never activated. Void unissued accounts and their codes on a fixed schedule and require reissue on demand. That turns a standing inventory of takeover primitives into a set that is empty most of the time.
Three intrusions in four months began with a legitimate account in an attacker's hands, and one of those accounts was external. Scoping a rollout to the system that was breached last leaves the next one open.
The March intrusion came through an external account into a trainee management system. Third-party identities reaching ministry data must meet the same authentication standard as internal ones, with access time-boxed and reviewed.
A role with legitimate need to view individual pupil accounts should be technically incapable of bulk retrieval. Gate mass export behind a distinct privileged path with second-person approval, and rate limit record access per account so a session reading thousands of pupils is refused rather than logged.
Detection failed because a validly authenticated session behaved abnormally and nothing objected. Baseline per-account read volume on pupil record systems and treat statistical excess as an incident in progress, with automatic session termination rather than a report generated afterwards.
When a flaw is found in an internet-facing system holding minors' data, assume prior exploitation until access logs for the full exposure window show otherwise, and retain logs long enough to answer the question. The ministry patched in December 2025 and disclosed in April 2026, after the data was already for sale.
Article 34 does not wait for a final count, and the absence of a victim number is not a reason to withhold notice from families whose children's enrolment credentials are in circulation. Publish what is known, publish the date of awareness, and revise as the scope firms up.
SOURCES
- Ministère de l'Éducation nationale, "Incident de sécurité affectant les données de certains élèves de l'Éducation nationale," April 14, 2026, https://www.education.gouv.fr/incident-de-securite-affectant-les-donnees-de-certains-eleves-de-l-education-nationale-504443
- Ministère de l'Éducation nationale, "Incident de sécurité affectant les données de certains personnels de l'éducation nationale," March 24, 2026, https://www.education.gouv.fr/incident-de-securite-affectant-les-donnees-de-certains-personnels-de-l-education-nationale-470657
- Ministère de l'Éducation nationale, "Incident de sécurité affectant les données de personnels de l'éducation nationale," July 31, 2026, https://www.education.gouv.fr/incident-de-securite-affectant-les-donnees-de-personnels-de-l-education-nationale-505407
- CERT-EU, Cyber Brief 26-05, published May 4, 2026, covering April 2026, https://cert.europa.eu/publications/threat-intelligence/cb26-05
- Legifrance, Loi n° 78-17 du 6 janvier 1978, Article 20, https://www.legifrance.gouv.fr/loda/article_lc/LEGIARTI000037822794
- Legifrance, Code pénal, Article 226-17, https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000006417963
- CNIL, "Les sanctions prononcées par la CNIL," https://www.cnil.fr/fr/les-sanctions-prononcees-par-la-cnil
- Journal du Geek, "Piratage massif de l'Éducation nationale," April 16, 2026, https://www.journaldugeek.com/2026/04/16/piratage-massif-de-leducation-nationale-les-donnees-de-35-millions-deleves-mineurs-ont-fuite/