Depressed is an alleged French cybercriminal associated with the BreachForums ecosystem. The actor was publicly identified as one of several suspected BreachForums administrators arrested by the French cybercrime unit BL2C in June 2025, alongside ShinyHunters, Hollow, and Noct. Available reporting ties Depressed to the administration of a major stolen-data marketplace rather than to a distinct malware family or a clearly documented standalone intrusion set. High-confidence public information about Depressed’s individual tradecraft, victimology, and operational history remains limited. The strongest corroborated association is with BreachForums administration and the broader francophone cybercrime milieu that became a focal point after French law-enforcement action in 2025. In that context, Depressed has been referenced among prominent French threat actors whose arrests were considered significant to disruption of the underground data-leak and cybercrime marketplace. There is no high-confidence evidence in the available material that Depressed operated ransomware, conducted destructive attacks, or acted on behalf of a state. The actor is best characterized as part of a financially motivated cybercriminal ecosystem centered on illicit data trading and forum-based cybercrime services.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as one of the prominent French threat actors arrested in June 2025, part of the background trigger for subsequent France-focused underground activity.
Depressed was an administrator of BreachForum, involved in the operation and facilitation of trading stolen data on the platform.
Named as one of the additional BreachForums administrators arrested in June 2025 as part of the broader disruption of the stolen data marketplace.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.