ChimeraZ is a data-leak threat actor active on underground forums and primarily associated with claimed breaches affecting French organizations across real estate, legal services, e-commerce, travel, emergency services, municipal administration, automotive services, and sports associations. The actor appears to operate mainly as a leak publisher and intrusion claimant, repeatedly advertising allegedly stolen databases as free downloads or low-cost forum-gated releases, often accompanied by sample records and basic breach narratives. Activity attributed to this alias in 2026 shows a strong concentration on French targets, with at least one Swiss victim, and a recurring emphasis on sectors holding large volumes of personal and transactional data. Known aliases include ChimeraZ. Reported collaborators and co-posters include misere, NightBroker, and Cybernox. Joint activity has been observed in claims involving Litige.fr, Autosur, and Pachatours, suggesting either operational collaboration or a loose leak-sharing ecosystem rather than a fully defined formal group structure. ChimeraZ has been linked to multiple alleged leaks involving French real-estate platforms and service providers, including Capifrance, Amepi, TakTikimmo, and references to additional real-estate victims such as Leboncoin Immobilier and Proprietes-Privees. This pattern indicates sustained targeting or at minimum sustained interest in the French property sector. Other claimed victims include Allo.Solar, the French Firefighters Federation membership platform, Bebeboutik’s seller portal, Pachatours, Autosur, a Le Pontet municipal dataset, Litige.fr, and Lancy FC in Switzerland. The actor’s tradecraft, as publicly claimed in associated leak posts, includes exploitation of exposed web applications and access-control weaknesses, including allegations of unauthenticated data exposure and SQL injection in some incidents. In several cases, ChimeraZ or collaborators claimed access to backend databases, staff dashboards, or seller and membership platforms rather than merely scraping public content. However, many attributed incidents remain unverified, and in some cases the claimed victim description appears disputed or inconsistent with sampled data, indicating that assertions made by the actor should be treated cautiously unless independently corroborated. The data types associated with ChimeraZ’s leak claims are broad and often highly sensitive: personal identity information, contact details, dates of birth, addresses, legal-case information, travel records, passport-related data, vehicle inspection records, property transaction and mandate data, membership records, and agent or merchant information. In some cases the alleged datasets may also involve minors or guardian information, particularly in sports-club and emergency-services membership contexts. If authentic, such exposures would support phishing, impersonation, fraud, identity theft, account takeover, business email compromise, lead harvesting, and sector-specific social engineering. Operationally, ChimeraZ appears motivated by notoriety and public dissemination rather than exclusively private monetization. Several leak posts reportedly offered data for free, while others used minimal forum-point gates or reply-gated hidden content. The actor has also used topical or provocative framing around releases, including politicized or opportunistic messaging. Overall, ChimeraZ is best characterized as an underground leak actor focused on French-speaking targets, especially French organizations, with repeated involvement in publishing or co-publishing alleged stolen databases and promoting broad circulation of exposed data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed breach-and-leak actor that allegedly obtained and published Allo.Solar customer and order data for free on a forum, framing the release around the Gironde wildfire emergency.
Claims to be leaking allegedly stolen data from the French Firefighters Federation membership platform as a free-download breach listing.
Claimed breach and data leak operation targeting Litige.fr, allegedly exploiting unauthenticated access-control flaws and describing account takeover plus staff-dashboard access.
Claims to be leaking an allegedly stolen SQL dump from Bebeboutik's seller portal, offered as a free download; the content notes this alias has been seen in other recent French leaks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.