France Cyber Threat Outlook: Dark Web, Ransomware, and Hacktivism Trends

France Cyber Threat Outlook: Dark Web, Ransomware, and Hacktivism Trends
CloudSEK telemetry shows a sustained surge in France-targeted data leaks, credential dumps, ransomware advisories, and hacktivist activity, with dark-web volume rising more than 4x over two years and driven mainly by infostealer logs and credential resale. The report also links this underground activity to rising CNIL enforcement, major breaches at Free Mobile/Free and France Travail, and ongoing disruption campaigns by NoName057(16). #CNIL #FreeMobile #FranceTravail #NoName05716

Keypoints

  • France-related underground activity reached roughly 17,800 items across the last 24 months, spanning data leaks, credential sales, ransomware advisories, and hacktivist disruption.
  • Dark-web volume climbed from under 300 items per month in mid-2024 to more than 1,000 per month in spring 2026, peaking above 1,400 in January 2026.
  • Account credentials and credential collections were the dominant data types, indicating heavy use of infostealer logs and combolist resale.
  • Government, financial services, technology, telecommunications, and email were the most targeted sectors over the two-year period.
  • Ransomware activity was lower in volume but focused on under-resourced local government bodies, with Qilin and MedusaLocker recurring in France advisories.
  • Hacktivism was dominated by NoName057(16), which claimed DDoS attacks, access claims, and defacement tied to geopolitical motivations.
  • The report highlights tightening French regulatory pressure, including major CNIL fines against Free Mobile/Free and France Travail for security failures.

MITRE Techniques

  • [T1078 ] Valid Accounts – Credential leaks and credential collections suggest use of stolen logins for reuse and account access (‘Account Credentials and Credential Collections are the two largest categories’).
  • [T1589 ] Gather Victim Identity Information – Large PII dumps and datasets containing subscriber, patient, and job seeker data were traded (‘large structured PII dumps’, ‘24.6 million subscriber contracts’, ‘up to 43 million job seekers’).
  • [T1190 ] Exploit Public-Facing Application – The Classic-Days.fr breach was linked to an exposed Apache directory listing and prior SQL injection attempts (‘an exposed Apache directory listing was discovered; evidence of SQL injection attempts against the same site dates back to 2024’).
  • [T1059 ] Command and Scripting Interpreter – SQL injection attempts indicate use of scripted input to interact with the target application (‘SQL injection attempts’).
  • [T1486 ] Data Encrypted for Impact – Ransomware groups such as Qilin and MedusaLocker conducted extortion campaigns against municipalities (‘ransomware victim advisories’, ‘claimed an attack on the municipal administration’).
  • [T1489 ] Service Stop – DDoS campaigns were used to disrupt availability of French organizations and ministries (‘claimed DDoS attacks against French drone manufacturers’, ‘coordinated DDoS on government ministries’).
  • [T1531 ] Account Access Removal – Hacktivist and criminal activity included access claims and takeover of systems like CCTV and video surveillance (‘claimed unauthorized access to the CCTV system’).
  • [T1189 ] Drive-by Compromise – Infostealer-driven credential harvesting and resale imply mass compromise at scale through commodity infection chains (‘infostealer logs being harvested at scale’).

Indicators of Compromise

  • [File names / datasets ] leaked or sold datasets – Classic-Days.fr 11GB database, 489K French “documents” leak, and 2 million French PII records for sale
  • [Organizations / victims ] targeted entities – Free Mobile, Free, France Travail, Cegedim Santé, and Thiverval-Grignon municipality
  • [Threat actors / handles ] named actors in posts – Saturne, 587306, Immanuel_Kant, HiddenHq, and NoName057(16)
  • [Ransomware groups ] advisory sources – Qilin, MedusaLocker, and LockBit
  • [Platforms / channels ] distribution and hosting – Mega, Telegram, and dark web forums/marketplaces
  • [Infrastructure / web indicators ] web compromise context – exposed Apache directory listing, Salesforce-linked dataset, and CCTV/video surveillance systems


Read more: https://www.cloudsek.com/blog/france-dark-web-ransomware-hacktivism-report