DumpSec is a French or francophone cybercriminal group that emerged in late 2025 and became known for intrusions and data-leak claims affecting French organizations. French authorities linked seven suspects to the group and described them as minors or very young adults. Investigators assessed that the group did not rely on advanced bespoke tradecraft, instead leveraging AI-assisted tooling and cybercrime-as-a-service resources to conduct damaging operations at scale. The group’s activity centered on French targets and included attacks or claimed attacks against local-government service platforms, major private-sector companies, and healthcare-related organizations. Authorities counted dozens of targeted organizations and more than 1,500 downstream victims. DumpSec appears to have pursued both monetization and notoriety: stolen data was allegedly used for sale, while public claims, interviews, and underground-forum visibility were used to build reputation. Reporting on the broader francophone underground ecosystem identified DumpSec among the actors focused almost exclusively on French victims during the late-2025 to early-2026 surge in data-leak postings. Operationally, DumpSec is associated with unauthorized access to victim environments and theft of data for publication or sale. The group’s public behavior indicates a strong emphasis on visibility, self-promotion, and reputational gain in addition to financial motives. Some of its victim-impact claims, particularly in the healthcare sector, were assessed as exaggerated or doubtful, but investigators still treated the group as a priority because of the real harm caused. An individual identified as leading the group used the alias Christopher Lead. DumpSec is best characterized as a financially motivated, reputation-driven cybercriminal actor rather than a state-backed or ideologically driven operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
One of the most active francophone attackers in the observed France-focused leak-claim ecosystem; attributed as French and exclusively focused on French targets during the period.
Cybercriminal gang previously tied to arrests and described as causing significant damage, reportedly using AI tools and cybercrime-as-a-service.
Cybercriminal group active since at least November 2025, claiming attacks against French organizations to steal and sell leaked data while also seeking notoriety through public communications and media exposure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.