breach3d is a cybercriminal threat actor active in underground data-leak and data-sale activity, with a strong observed focus on French targets. The actor has been assessed as likely originating from France and was identified among the more active personas involved in the surge of alleged breach claims against French entities observed from late 2025 into early 2026. Reporting associated breach3d with approximately half of its observed posts targeting French organizations, indicating a notable but not exclusive concentration on France. breach3d has been publicly linked to claims involving the compromise of Agence Nationale des Titres Sécurisés (ANTS), also branded France Titres, a French government agency responsible for identity and registration documents. In April 2026, breach3d claimed responsibility for the ANTS intrusion and alleged possession of a very large dataset of citizen records, which was offered for sale on hacker forums. The actor was also named alongside EvilDump and ExtaseHunters in claims relating to the same ANTS breach, suggesting either collaboration or co-branding in underground sales activity. The actor’s observed behavior is consistent with financially motivated data-breach operations centered on unauthorized acquisition, exfiltration, and monetization of sensitive information rather than ransomware deployment. Reported ATT&CK-aligned behaviors tied to activity attributed or claimed by breach3d include exploitation of public-facing applications, collection of data from information repositories, and exfiltration over web services. The broader campaign environment in which breach3d appeared was characterized by notoriety-seeking and visibility on criminal forums, but the directly evidenced operational pattern for breach3d is the theft and attempted sale of stolen data affecting French public-sector entities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Identified as a notable actor in the surge, with half of observed posts targeting French entities and assessed as originating from France.
Claimed responsibility for the ANTS/France Titres data breach and offered allegedly stolen citizen data for sale on hacker forums.
Named as a collaborator in the claimed compromise of ANTS / France Titres involving alleged theft and sale of 18 million citizen identity records.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.