DumpSec is a French cybercriminal group active from at least November 2025 and associated with a wave of data-leak and intrusion claims directed overwhelmingly at French organizations. The group has been linked to attacks and claimed compromises affecting local-government service platforms, staffing and logistics firms, retail brands, healthcare-related entities, and software providers. French authorities assessed the group as responsible for significant downstream harm across dozens of organizations and more than a thousand secondary victims. The actor is characterized as a young, notoriety-driven criminal collective rather than a state-backed operation. Reporting links its members to underground forum activity, media engagement, and public self-promotion, including interviews. French investigators stated that the suspects were minors or very young adults and did not appear to rely on advanced in-house technical expertise, instead leveraging AI tools and cybercrime-as-a-service offerings to conduct intrusions and monetize stolen information. DumpSec’s activity is most strongly associated with data theft and publication or sale of stolen data rather than ransomware deployment. The group publicly claimed multiple breaches against French targets and appears to have pursued both financial gain and visibility. Some public victim-impact claims attributed to DumpSec, particularly in the healthcare sector, were assessed as exaggerated or doubtful, but authorities nonetheless treated the group as a priority target because of the scale of disruption and data exposure linked to its operations. The group has been described as operating in the broader francophone underground ecosystem that intensified targeting of French entities in late 2025 and early 2026. In analyses of actors posting alleged leaks about French victims, DumpSec was identified as focusing exclusively on French targets during the observed period. French law enforcement later announced the arrest of seven suspects linked to DumpSec in multiple locations across France. An alias reported as associated with leadership of the group is Christopher Lead.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Identified as a notable actor in the surge, publishing exclusively posts targeting French entities and assessed as originating from France.
One of the most active francophone attackers in the observed France-focused leak-claim ecosystem; attributed as French and exclusively focused on French targets during the period.
Cybercriminal gang previously tied to arrests and described as causing significant damage, reportedly using AI tools and cybercrime-as-a-service.
Cybercriminal group active since at least November 2025, claiming attacks against French organizations to steal and sell leaked data while also seeking notoriety through public communications and media exposure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.