Saturne is a threat actor alias observed advertising and distributing alleged stolen data from organizations in Europe and Latin America. In the provided reporting, Saturne is linked to an alleged sale of data from Follow.fr, a French Ségur-certified medical software and patient-record platform used by specialist doctors and surgeons, and to a claimed free leak of data from Avícola El Madroño S.A., a Colombian poultry and prepared-foods company based in Bucaramanga. The Follow.fr claim was described as an unverified sale listing for 2,052,123 patient records in CSV format dated July 2026, allegedly including names, sex, dates of birth, email addresses, phone numbers, French INSEE national identification numbers, health insurance numbers, profession and label fields, and associated doctor details; the seller reportedly described it as a partial export interrupted by detection, with negotiable pricing and samples for serious buyers. The Avícola El Madroño claim was described as an unverified 860MB leak shared for free, allegedly enabled by exposed unauthenticated diagnostic and backup interfaces, enabled directory listings, an open file-upload form, and database administration panels accessible with default or weak credentials. The allegedly exposed Avícola data included accounting and payment records, names and ID numbers, customer files, user-account tables, application passwords stored as weak MD5 hashes, and database account hashes. Based on the provided content, Saturne appears to operate as a data-leak actor publishing breach claims and offering or releasing allegedly stolen datasets. No nation-state attribution is provided in the content. Known alias in the content: Saturne.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Selling an allegedly stolen database from French medical platform Follow.fr containing over 2 million patient records; the post also says this is the same alias behind other recent French and European leaks.
Posted and allegedly exfiltrated data from Avícola El Madroño, claiming access via exposed unauthenticated interfaces, enabled directory listings, open file-upload functionality, and database administration panels accessible with default or weak credentials. The post says this alias is behind other recent European and Latin American website leaks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.