What OFAC announced
Arrests were made across the country — in Lille, Marseille, Strasbourg, Poitiers, Bordeaux, and Limoges — coordinated by OFAC's Rennes branch. The investigation began back in November 2025 after an attack on a company based in Rennes, and gradually uncovered the scope of the group. Its members publicly admitted to their attacks in the media and offered the stolen data for sale on forums such as BreachForums. During house searches, investigators seized several data storage devices, which are still being analyzed, and the investigation continues. Le Monde ↗Dumpsec was not an unknown player. Already in March, the group had claimed credit on hacker forums for a data leak from the French student system Crous — a booking platform for student housing and social assistance. According to the national agency Cnous, it affected approximately 774,000 current and former students, and for around 139,000 of them the attackers also allegedly downloaded uploaded attachments, potentially including identity documents. Europe Infos ↗
Young self-taught hackers "without inhibitions"
It is precisely the profile of those detained that makes the case exceptional. "These are young French hackers who crave fame and think they're beyond reach," said Commissioner Julie Benoit, head of OFAC's cyber investigations unit, describing them. According to her, they are "minors or young adults," "often self-taught," and "completely without inhibitions." "We have a clear strategy: cross-reference, identify, neutralize," she added. Le Figaro ↗This is not an isolated case. Just recently, French police detained a twenty-year-old going by the alias HexDex, linked to roughly a hundred attacks since late 2025. Among them was a breach of the Ministry of Education's personnel system, which leaked the data of nearly 243,000 employees, mostly teachers. He too published his hauls on the cybercriminal marketplaces BreachForum and Darkforum. The Record ↗
The year France became a target
Dumpsec and HexDex fit into a series of incidents that make 2026 one of the worst years for France in terms of data breaches. In April, the state agency ANTS, which manages ID cards, passports, and immigration documents, admitted to a breach — a hacker on a forum was offering approximately 19 million records containing names, dates of birth, and contact details. TechCrunch ↗Back in December 2025, police charged a 22-year-old man with breaching the Ministry of Interior's network, where attackers gained access to court records and lists of wanted persons. The man, charged with attacking a state personal-data processing system as part of an organized group, faces up to ten years in prison — and was no stranger to prosecutors, having earlier convictions for similar offenses. The Record ↗
The Cybernews portal counted more than fifty ransomware attacks in just the beginning of 2026 alone, citing experts according to whom part of the French public administration is "operationally paralyzed." Cybernews ↗
Why it's worth following from here too
This story isn't just a French one. Marketplaces like BreachForums are global — once data leaks, it is bought and sold regardless of borders, and it often serves targeted phishing or extortion for years after the breach. The perpetrator profile too — a young self-taught hacker who hacks for community respect rather than money — knows no borders and could just as easily emerge in Slovakia or the Czech Republic. And since most of the affected entities fall under European data protection rules (GDPR), the case is also a test of how quickly the Union can detect and punish such groups.What hotinfo is watching
- The names and specific charges against the seven detainees and how many face custody.
- A link between Dumpsec and the major leaks of late 2025 and early 2026 (the interior ministry, ANTS).
- The real scale: how many of the 1,500 possible victims actually lost data.
- The response of the French regulator CNIL and any fines for the affected firms.
- EU pressure on cybercrime marketplaces such as BreachForums.







