84City is a threat actor alias associated with alleged data-leak activity targeting French private higher-education institutions. Publicly observed activity under this name consists of posts advertising purported SQL database dumps attributed to schools including PPA Business School and ESGI (École Supérieure de Génie Informatique). The claims center on student and education-related records, including personal, contact, and enrollment information, and in one case reportedly school directory login identifiers. The observed operations appear financially or reputationally motivated and align with opportunistic leak-forum behavior rather than a clearly established espionage or destructive campaign. The actor’s known activity involves claiming unauthorized access to institutional databases and offering the resulting data through gated forum mechanisms. Reported victimology is concentrated in the French education sector, particularly private schools and higher-education organizations. If authentic, the exposed datasets would create significant downstream risk for identity fraud, targeted phishing, social engineering, privacy harms, and impersonation of students, applicants, alumni, and other individuals connected to the institutions. At present, attribution beyond the alias 84City is not available. There is no high-confidence public evidence linking this actor to a specific nation state, intrusion set, malware family, or broader named cluster. The observed reporting is limited to unverified breach claims and leak-post activity, so conclusions about technical tradecraft, initial access methods, persistence mechanisms, tooling, or operational sophistication cannot be made with confidence. No additional confirmed aliases or sub-groups are currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Posted an allegedly stolen SQL dump attributed to PPA Business School containing nearly 294,000 records of prospects, applicants, students, and alumni; the claim is described as unverified.
Posted an allegedly stolen SQL dump attributed to ESGI containing student enrollment records; this is presented as a data-leak post and the claim is unverified.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.