Breach3d
breach3d is a threat actor moniker associated with claims of responsibility for a 2026 data breach affecting France Titres / Agence nationale des titres sécurisés (ANTS), a French government agency under the Ministry of the Interior that manages official identity and registration documents. On April 16, 2026, breach3d was reported to have claimed the attack on hacker forums and to have offered allegedly stolen ANTS data for sale. The actor claimed to possess between 18 million and 19 million records. Reported claimed data fields included login IDs, names, email addresses, dates of birth, unique account identifiers, and in some cases postal addresses, places of birth, phone numbers, gender, civil status, professional status, and government-verification status. Supporting content also names EvilDump and ExtaseHunters as collaborators in the alleged ANTS breach, with one report stating EvilDump made the sale post and credited ExtaseHunters and Breach3d as collaborators. The content characterizes the activity as sale of stolen data on hacker forums/open web with pricing via direct message and acceptance of escrow or middleman services. ATT&CK mappings mentioned in the content for the alleged intrusion and follow-on activity are T1190 (Exploit Public-Facing Application), T1213 (Data from Information Repositories), T1567 (Exfiltration Over Web Service), and potential downstream abuse via T1078 (Valid Accounts) and T1657 (Financial Theft). The record-count claims and full scope of the theft were not publicly confirmed by ANTS in the cited reporting.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
Where they target
Geographies tied to known operations.
- 🇫🇷 France
Tradecraft
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed responsibility for the ANTS/France Titres data breach and offered allegedly stolen citizen data for sale on hacker forums.
Named as a collaborator in the claimed compromise of ANTS / France Titres involving alleged theft and sale of 18 million citizen identity records.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.