CSIDB logo
Threat actor

ChatNoir

Attribution profile

Type
Undetermined
Location
-
Known incidents
1 incident
Sources
0 sources
First seen
2026-06-01
Last seen
2026-06-01
Updated
2026-09-09 01:42
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

ChatNoir is an alias used by an individual identified by French authorities in mid‑2026. The alias appears in law‑enforcement reports linking the actor to the hacking collective known as ZeroBytes. Prior to the 2026 arrest, the person was already known to police for previous offenses. No additional aliases or personal details have been disclosed in open sources.

Intrusions attributed to ChatNoir and ZeroBytes focused on the Directorate General of Public Finances as well as other public and private entities located in France. The compromised information consisted of names, tax identifiers, email addresses and financial details belonging to hundreds of thousands of individuals and businesses. Statements released by the group indicated that the stolen data was offered for sale to generate profit. This points to a financially motivated objective rather than espionage or disruption.

Investigators have explicitly described the arrested individual as a member of the ZeroBytes hacking group. No public evidence connects ZeroBytes to any state sponsor or foreign intelligence service. The group is characterized in reporting as a criminal enterprise driven by profit. Further hierarchical or organizational details about ZeroBytes have not been made available.

In June 2026, investigators linked ChatNoir to a security breach of the Directorate General of Public Finances’ internal networks. The incident resulted in the unauthorized acquisition of a large volume of records. The compromised information consisted of names, tax identifiers, email addresses and financial details belonging to hundreds of thousands of individuals and businesses. The arrest followed investigative confirmation that the suspect participated in the unauthorized acquisition of the described datasets.

Beyond this incident, open‑source sources do not describe additional campaigns, specific malware families, or particular initial‑access vectors associated with ChatNoir. Consequently, the public profile remains limited to the confirmed facts of alias, affiliation with ZeroBytes, the French tax‑data breach, and the resulting arrest. Any further characteristics would require speculation and are therefore omitted. This concludes the factual overview based on the currently available information.

Incidents

Attributed incidents are available to members.

1 incident

Sources

Sources available to members: 0 sources.

CSIDB