Reverse email, phone number, username or name lookup - Predicta Search
Predicta
Search
Back to blog
osint
threat-intelligence
cybercrime

DumpSec: unsophisticated but not low-impact

Predicta Lab

August 10, 2026 · 13 min read

On June 11, 2026, French authorities announced the arrest of seven individuals suspected of being involved with Dumpsec, a group of cybercriminals linked to large-scale data theft operations.

Dumpsec’s proclaimed leader, who went by “Christopher”, gave an interview in March 2026, presenting the group as a structured operation focused on accessing sensitive databases, extracting information, and publishing or selling stolen data. French authorities presented the group as composed of several young individuals aged 15 to 22, based in France.

Since late 2025, the group became visible by advertising stolen datasets on cybercriminal forums, and targeting organizations across multiple sectors, such as: Colis Privé, l’Assemblée Nationale, Assuréa and several French sport federations.

In this investigation, we use Flare, a cyber threat intelligence platform, to follow Dumpsec’s traces across several cybercriminal platforms and analyze how the group operated and evolved. By combining publicly available information, cybercriminal activity, and behavioral indicators, we aim to understand how Dumpsec built its presence, how its ecosystem developed, and how its own online activity contributed to making the group visible, and, ultimately, to its downfall.

Investigation methodology: Using Flare to map a Threat Actor

The first challenge when investigating a cybercriminal group is to understand that its name rarely tells the full story. A single actor may use multiple identities, while a single identity may sometimes represent multiple individuals. Hence, to investigate Dumpsec, we started from a simple selector:

“Dumpsec”

This query returns mentions of the keyword “Dumpsec” across different platforms. It helped us identify the group’s presence beyond their own publications, including references in Telegram channels and mentions by other threat actors such as “Angel_Batista”, whose post hinted at a possible rivalry within the ecosystem, a thread we return to later in this investigation.

Then, to investigate mentions of Dumpsec as an actor rather than just a keyword, we used the following query:

author_name:”Dumpsec”

It allowed us to map Dumpsec’s activity by identifying where the group published its content and what information was disclosed in each post. We found the group active on BreachForums, DarkForums and PwnForums. Access to these publications let us collect actor profiles, identify aliases, and compile a list of organizations targeted in the group’s posts.

Also, Flare’s AI-assisted analysis complemented the manual investigation by aggregating information scattered across multiple forum’s posts. Rather than reviewing each publication individually, the platform automatically summarized recurring behaviors, highlighted potential associations between actors, and generated a consolidated profile of Dumpsec’s activity.

For example, after analyzing more than 31 posts across 10 BreachForums threads, Flare identified recurring references to the group’s financial motivation, highlighted interactions with several accounts (HexDex, marak, czx) and repeated references to an individual named Christopher, suggesting these entities deserved further investigation. Thus, these automated summaries provided useful investigative leads that analysts could then verify and expand upon manually.

The goal with these queries, manual and AI-assisted alike, was not only to find information, but build a broader picture of Dumpsec’s activity by identifying the platforms it used, the identities it adopted, the organizations it targeted, and the relationships it maintained within cybercriminal communities.

Building the Dumpsec timeline

In order to build a timeline of Dumpsec activity, we had to determine whether older references to the name “Dumpsec” were connected to the group observed from late 2025 onward.

Flare returned an early mention of the username “Dumpsec” dating back to September 29, 2019, from a post on Hack Forums.

We were unable to establish a confirmed connection between this historical account and the Dumpsec group investigated in 2026. Flare allowed us to recover the metadata associated with this post, although the original publication is no longer accessible. The available information indicates that it was a Python GUI development question, suggesting a learning-oriented discussion. This observation is not sufficient to infer the user’s intentions at the time, but it reflects why historical usernames should not automatically be attributed to a threat actor without corroborating evidence.

A second, separate case reinforces this same caution. Flare identified a lowercase “dumpsec” account active on the CrdPro forum between July 2024 and July 2025, posting 19 times across 10 threads. Unlike the French group, this account was focused on credit card fraud and carding, discussing card dumps and marketplaces such as Rescator, with no apparent connection to the data-theft operation this investigation covers. Taken together, these two cases illustrate a recurring challenge in threat intelligence: usernames are not unique identifiers, and an alias may be reused by unrelated individuals over time, making context and correlation essential before any attribution is made.

We found a likelier trace of Dumpsec’s early activity on BreachForums on December 27th, 2025. In that post, they were selling a Mondial Relay and Colis Privé database compromised in November 2025.

After that, we accessed the posts advertising Dumpsec’s datasets with Flare in order to understand the group’s evolution. The table below lists only Dumpsec’s publications where pricing information was publicly displayed. In many cases, the actor seemed to negotiate privately, meaning that the actual price of the sale may be different from what was first announced.

As shown above, the value of datasets was not directly proportional to their size. Some smaller collections were advertised at higher prices because of the type of information they contained. This implies that Dumpsec treated stolen information as a commercial asset, where exploitability and sensitivity mattered more than volume alone, a point we return to in the section on Dumpsec’s business model.

Timeline

Mapping the actor’s network

Flare’s entity correlation feature turned out to be extremely useful to connect different elements regarding Dumpsec’s activity, namely:

  • Underground accounts
  • Related usernames
  • Communication identifiers
  • Victim references

This type of analysis matters because threat actors rarely expose their entire operation in one place. Instead, Flare allows analysts to connect fragments of information across multiple platforms. Dumpsec did not rely on a single marketplace but adapted its presence as the cybercriminal ecosystem around it shifted.

At first, the group’s activity was observed on BreachForums, but Flare also revealed activity on DarkForums starting April 6, 2026. This shift occurred during a period of major disruption within cybercriminal communities: following the takedown of BreachForums in late 2025, the ecosystem became increasingly fragmented, with multiple forums competing to attract former users and sellers.

Flare later identified Dumpsec’s activity on PwnForums, another cybercriminal platform, as well. While the exact reason for this transition cannot be confirmed, this movement illustrates a common pattern in cybercriminal ecosystems: threat actors migrate between platforms as forums emerge, disappear, or lose credibility. This volatility is not only driven by external disruption, however, takedowns and law enforcement actions are only a part of the picture. Rivalries between actors, account takeovers and doxxing attempts also reshape the underground landscape.

By monitoring the cybercriminal ecosystem as a whole, rather than focusing only on the most well-known forums, Flare enables analysts to maintain visibility into actor’s activity, even when posts or entire platforms become inaccessible.

A data-centric business model

Dumpsec’s targeting strategy appears broad rather than focused on a single industry. The observed victims were mainly French organizations, with activity spanning multiple sectors:

The diversity of victims suggests that Dumpsec was not driven by a particular industry or ideology. Instead, the group’s publications indicate a pragmatic approach centered on acquiring datasets with resale value: databases containing long-lived personal information that can be monetized through fraud, phishing, identity theft, or resale to other cybercriminals.

This pattern becomes clearer when the sector breakdown above is read alongside the pricing table in the previous section. Some of Dumpsec’s highest-value listings, such as Assuréa, priced at 20,000€ for 150 GB of insurance data, came from sectors handling personal information: financial identifiers, IBANs, and administrative records tied to a person’s identity over years rather than days. By contrast, the Carvivo dataset, despite containing over 3.2 million email addresses and 5 million license plate numbers, was priced comparably lower at 5,000€, indicating that email/plate pairs, while still valuable, carry less durable exploitation potential than financial and insurance records. Notably, not every high-sensitivity dataset was priced publicly: the CROUS export, which included sensitive student PII, was advertised without a public price, likely reflecting private negotiation rather than an indication of lower value.

This reinforces the idea that Dumpsec treated stolen data less like a volume commodity and more like a differentiated product line, priced according to how exploitable and durable the underlying information was. Even if the absence of a public price for some sensitive datasets limits how far this comparison can be pushed with confidence.

Modus Operandi

Beyond how it priced and framed its data for sale, Dumpsec’s operations also followed a fairly repeatable pattern, even if not every step can be verified to the same degree.

The starting point, how the group actually got into a victim’s systems, is the weakest link in the chain. Across their posts, the threat actor claimed to have obtained administrative access, VPN credentials or webmail portals from organizations such as Cegedim or French sports federations. However, nothing in the available material corroborates this information independently. These are the group’s own claims, not a confirmed intrusion method.

What comes after is better documented. Taken together, Dumpsec’s posts point to a consistent sequence: Compromise → Collection → Extraction → Proof of access → Underground sale.

Forum posts typically included:

  • the estimated size of the dataset;
  • the number of records;
  • a description of the exposed information;
  • screenshots or other proof-of-access elements;
  • excerpts from the dataset or database structure;
  • pricing information or instructions to negotiate privately.

These elements served two purposes: proving access and increasing the perceived value of the dataset.

During its later PwnForums period, the group also began directing buyers to a dedicated onion-hosted escrow service, built into the PwnForums platform itself, to facilitate transactions between sellers and buyers, alongside its continued use of Session messenger for direct communication.

DumpsecV2: A continuity claim?

An interesting finding was the appearance of DumpsecV2 on Darkforums.

On April 12, 2026, the account explained that the original Dumpsec profile had become inaccessible after the group lost the account’s password following an infrastructure refresh.

We had to determine whether there was genuine continuity between Dumpsec and DumpsecV2, rather than a separate actor claiming the name. Although the link between the two cannot be independently confirmed with certainty, the following indicators suggest they are probably the same group:

  • same naming convention;
  • similar targeting patterns, with a continued focus on French organizations;
  • consistent dataset advertisement style following the same Compromise → Collection → Extraction → Proof of access → Underground sale structure described earlier;
  • matching Session messenger identifier, the same identifier (051a9f9a…5362e) appears in both the January 23 BreachForums post advertising the French Volley Federation breach and the May 4 PwnForums post advertising the Groupe CGA breach, linking the two accounts to the same underlying communication channel.

Beyond these structural similarities, the tone and phrasing across Dumpsec and DumpsecV2 posts also felt broadly consistent to us during the investigation, though this observation remains impressionistic rather than the product of a formal stylometric analysis, and should be weighted accordingly.

Taken together, these indicators make DumpsecV2 a probable continuation of the original Dumpsec persona rather than a distinct actor.

Flare also allowed us to quickly identify DumpsecV2 activity across multiple underground platforms, including DarkForums and PwnForums.

Building a cybercriminal brand: reputation and exposure

Technical indicators alone are not enough to understand how underground groups operate.

Underground marketplaces rely heavily on reputation. Sellers need to demonstrate credibility by consistently advertising datasets, responding to potential buyers, and maintaining a recognizable identity over time. In these communities, a well-established account becomes a valuable asset, and losing one is a real operational setback.

Beyond losing a username, threat actors lose their reputation points, previous sales history, and the trust built with other users over time. The appearance of DumpsecV2, claiming that the original account had become inaccessible after an infrastructure refresh, illustrates the importance of maintaining that reputation and rebuilding continuity when an established identity is lost.

Through its forum presence, the group regularly published breach claims, shared samples, interacted with other users, and publicly defended its reputation and its members.

One notable example: two posts referring to “Christopher” (referenced once as “Christopher Lead” in a forum post) as the group’s leader:

Reputation in this ecosystem is also actively contested. Public disputes between rival actors are common, and Dumpsec was no exception: DarkForums activity linked to the group’s ecosystem shows public friction with other named actors, including disputes involving “HuntSec” and “RevenSec”. In one notable case, “Angel_Batista” published a hostile post targeting a separate individual, a French ethical hacker, while also referencing connections between them, HexDex, and Dumpsec, illustrating how accusations, personal disputes, and claims of insider knowledge circulate publicly within this community, sometimes escalating well beyond commercial rivalry. These dynamics are a reminder that an actor’s public reputation is shaped as much by their rivals’ claims as by their own.

Flare identified several recurring names connected to Dumpsec’s activity. We therefore looked at some of them individually, though these relationships provide insight into the surrounding ecosystem rather than confirmation of formal membership.

A BreachForums post related to a dataset attributed to Dumpsec mentioned HexDex.

HexDex appears to have been part of the same cybercriminal ecosystem. According to French officials, he is also a young French individual involved in multiple alleged intrusions against French organizations, including sport-related entities. He was also arrested earlier in 2026.

Another account observed in connection with Dumpsec activity was marak. The sentence in Russian names marak as a friend but does not provide enough evidence to determine the nature of the relationship with certainty.

There is not enough available information to determine whether HexDex or marak played a technical role in Dumpsec’s cyberattacks or collaborated on operations on multiple occasions. However, these leads represent the first step in drawing the web of interactions between different threat actors in this ecosystem.

MITRE ATT&CK Mapping

Conclusion: Is Dumpsec a sophisticated actor?

From its first activity in December 2025 to its last known post in June 2026, Dumpsec ran a data theft operation in which sensitive information, rather than any advanced technical capability, was the group’s primary asset. No custom malware or exploitation technique was advertised, and the claimed method of initial access was not independently verified beyond the group’s own claims.

What stands out instead is the operational and commercial strength of the group. Dumpsec maintained a coherent presence across three cybercriminal forums. It priced stolen datasets by exploitability and durability, not by volume. And when it lost access to its original account, it rebuilt its persona as DumpsecV2 rather than disappearing. Its public disputes and reputation management, both within the community and beyond it through Christopher’s interview, reflect a clear understanding that credibility is what sustains a seller in this ecosystem.

However, the group’s members have been arrested barely six months after Dumpsec’s first confirmed activity, with French authorities identifying and apprehending seven individuals. This may indicate a gap between the group’s commercial discipline and the measures it took to protect its own identity and traces, though the specific investigative methods used by French authorities are not known from the available material.

A technically unsophisticated actor, in other word, is not necessarily a low-impact one: Dumpsec’s ability to advertise and monetize stolen data depended less on breaching defenses and finding zero-days than on understanding and operating within the commercial logic of the underground marketplaces it used.

This investigation also highlights how threat intelligence relies on connecting fragmented traces. Through Flare, we were able to reconstruct parts of Dumpsec’s activity, identify recurring behaviors, and trace its evolution from Dumpsec to DumpsecV2.

The June 2026 arrests mark a real disruption to Dumpsec’s operations, but cybercriminal ecosystems are resilient. Arrests remove individuals, however, they do not necessarily remove the demand, infrastructure, or reputation systems that made a group like Dumpsec possible in the first place. As the group itself put it: “Dumpsec will never stop”.

Written by Predicta Lab

Don't miss our future newsletters !

Get the latest OSINT news, monthly recaps and product updates in your inbox.

More articles from Predicta Lab

background shape