Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
🇫🇷 FR

HexDex

Also known asHexDex

HexDex is a threat actor associated with a series of data breach and data sale claims targeting French public institutions, sports federations, and private-sector organizations. French authorities arrested a 20-year-old suspect in western France in an investigation led by the cybercrime unit of the Paris prosecutor’s office; prosecutors said the suspect admitted using the HexDex alias to claim responsibility for hacks and to publish stolen data on BreachForum and Darkforum. Authorities linked the actor to dozens of breaches, with local media reporting roughly 100 website breach reports since late 2025, and alleged victims including multiple French national sports federations, food banks, Logis Hôtels France, Brit Hotel, the Philharmonie de Paris, and the French Ministry of National Education’s Compas database. Investigators also suspect involvement in a breach of a government firearms information system. In the Compas incident, exposed data reportedly included names, addresses, phone numbers, and employee absence records affecting about 243,000 employees, mostly teachers. HexDex has been specifically named in breach sale listings involving French organizations including the Federation Francaise de Basket-Ball (FFBB), Allopneus, Airsoft-Entrepot, and Therapeutes.com. In the FFBB case, the actor claimed to be selling data on approximately 1.9 million members and about 800,000 parents, including personal, contact, federation, medical, physical, and parental information, including records tied to minors. In the Allopneus case, HexDex claimed to be selling customer data including hundreds of thousands of customer profiles, phone numbers, and email addresses. In the Airsoft-Entrepot case, the actor claimed to be selling more than 10 database files spanning customer, order, invoice, supplier, delivery, accounting, B2B order, and warehouse or inventory data. In the Therapeutes.com case, HexDex claimed to be selling patient and appointment records, including especially sensitive consultation and therapy-reason fields. Across the reporting, HexDex is described as advertising stolen datasets for sale, typically on a make-offer basis, providing proof links and sample data, and using qTox and Session for buyer negotiations; one report also states the actor recommended escrow. Reported ATT&CK mappings in the source material include exploitation of public-facing applications, collection from information repositories, gathering victim identity data such as email addresses, possible use of valid accounts, access to cloud-stored data, and exfiltration over web services. No nation-state attribution is stated in the provided content. Known alias in the content: hexdex.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Consumer Services
  • Food, Beverage & Tobacco
  • Government & Administration
  • Academia & Research

Where they target

Geographies tied to known operations.

  • 🇫🇷 France

Where they're from

Attributed origin per open-source reporting.

  • FR
MITRE ATT&CK

Tradecraft

10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

7 of 15 tactics14 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1589
Gather Victim Identity Information
T1589.002×4
Email Addresses
TA0001
Initial Access
2 techniques
T1078×4
Valid Accounts
T1190×5
Exploit Public-Facing Application
TA0003
Persistence
1 technique
T1078×4
Valid Accounts
TA0004
Privilege Escalation
1 technique
T1078×4
Valid Accounts
TA0005
Stealth
1 technique
T1078×4
Valid Accounts
TA0009
Collection
3 techniques
T1005
Data from Local System
T1213×6
Data from Information Repositories
T1530×2
Data from Cloud Storage
TA0010
Exfiltration
3 techniques
T1041×5
Exfiltration Over C2 Channel
T1537
Transfer Data to Cloud Account
T1567×6
Exfiltration Over Web Service
T1567.001×3
Exfiltration to Code Repository
ACTIVITY FEED

Recent activity

5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping10

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.