Hollow is a French threat actor associated with the BreachForums cybercriminal ecosystem. The actor was publicly identified as one of four additional BreachForums administrators arrested by French authorities in June 2025 alongside ShinyHunters, Noct, and Depressed. Available reporting ties Hollow to the broader francophone underground scene that became a focal point in data-leak activity affecting French organizations after major law-enforcement disruption of BreachForums-linked actors and infrastructure in 2025. High-confidence public information on Hollow’s individual tradecraft, malware use, victimology, and operational history remains limited. The strongest corroborated attribution is Hollow’s role as a BreachForums administrator within a criminal marketplace centered on stolen data, leaks, and brokerage activity. In that context, Hollow is best understood as part of a cybercrime milieu oriented toward illicit data exposure and underground forum operations rather than ransomware or state-sponsored intrusion activity. There is no high-confidence evidence here that Hollow conducted ransomware campaigns, destructive operations, or a coordinated nation-state mission. Hollow is linked by context to a cluster of French or francophone actors whose activity was assessed as opportunistic and reputation-driven, with French entities receiving disproportionate attention during late 2025 and early 2026. However, specific operations attributable directly to Hollow are not established at high confidence from the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as one of the prominent French threat actors arrested in June 2025, part of the background trigger for subsequent France-focused underground activity.
Named as one of the additional BreachForums administrators arrested in June 2025 as part of the broader disruption of the stolen data marketplace.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.