Depressed is a French-linked cybercriminal persona associated with the BreachForums ecosystem. The actor is publicly noted as one of several prominent BreachForums administrators arrested by French authorities in June 2025 alongside ShinyHunters, Hollow, and Noct, indicating an operational role within a major underground marketplace centered on stolen data and cybercrime services. Available reporting ties Depressed to the forum-administration layer of BreachForums rather than to a distinct malware family or a separately documented intrusion set with well-attributed campaigns. The actor appears in the context of a broader francophone cybercrime milieu that was heavily involved in data-leak and notoriety-driven underground activity targeting French entities during late 2025 and early 2026. High-confidence public information supports association with the BreachForums criminal ecosystem and French law-enforcement action, but does not provide sufficient corroborated detail to attribute specific intrusion techniques, victim sectors, or an independent operational profile beyond that role.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of four prominent French actors linked to BreachForums whose arrests are described as an initial trigger for the later surge in data-leak claims against French entities.
Referenced as one of the prominent French threat actors arrested in June 2025, part of the background trigger for subsequent France-focused underground activity.
Depressed was an administrator of BreachForum, involved in the operation and facilitation of trading stolen data on the platform.
Named as one of the additional BreachForums administrators arrested in June 2025 as part of the broader disruption of the stolen data marketplace.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.