84City is a threat actor alias associated with alleged data-leak activity targeting French higher-education institutions. The actor has been observed claiming breaches of PPA Business School and ESGI (École Supérieure de Génie Informatique), and advertising purported SQL database dumps containing large volumes of student and education-related personal data. Reported victim data types include identity and contact information, educational status and program details, and in one case school directory login identifiers. Access to the purported datasets was described as gated behind forum points, indicating monetized or reputation-based distribution within a cybercriminal forum environment. The observed activity is consistent with opportunistic data theft and exfiltration followed by public leak-posting or sale-oriented exposure. The known targeting centers on the French education sector, particularly private higher-education institutions. If authentic, the leaked information would support downstream phishing, fraud, impersonation, and broader social-engineering operations. Available reporting does not provide verified attribution to a nation state, confirmed intrusion details, or corroborated evidence of ransomware deployment, encryption, or disruptive operations. The breach claims associated with this alias remain unverified in the available information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Posted an allegedly stolen SQL dump attributed to PPA Business School containing nearly 294,000 records of prospects, applicants, students, and alumni; the claim is described as unverified.
Posted an allegedly stolen SQL dump attributed to ESGI containing student enrollment records; this is presented as a data-leak post and the claim is unverified.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.