Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
underground-data-leakmass-credential-exposurefinancial-sector-threat

HexDex Lists Stolen Customer and Operational Data From French Retailers

Updated 3mo agoFirst seen Mar 23, 20262 sources

Threat actor HexDex has claimed breaches at two French e-commerce companies and is offering the allegedly stolen data for sale. One listing targets Airsoft-Entrepot, where the actor says it obtained more than 10 database files covering 2013 to 2026, including roughly 383,000 customer profiles, 328,000 email addresses, 243,000 phone numbers, and 333,000 full address records. The exposed material reportedly goes beyond customer PII to include orders, invoices, supplier data, delivery history, accounting records, B2B orders, and warehouse or inventory information, suggesting compromise of both customer-facing and back-office systems.

A second listing targets Allopneus, a major French online tire retailer, with HexDex claiming to hold data spanning 2014 to 2026 for 453,299 customers across 739,316 records, including 513,089 phone numbers and 453,299 email addresses. The actor reportedly published proof links, sample records, and 1,000-line excerpts for both datasets while soliciting offers through underground channels. If authentic, the disclosures would expose large volumes of customer contact data and purchase-related information, while the Airsoft-Entrepot cache could also reveal sensitive supplier, financial, and logistics details that increase fraud, phishing, and business intelligence risks.

Share:
HexDex Lists Stolen Customer and Operational Data From French Retailers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Mar 23, 20263mo ago

HexDex allegedly breaches Airsoft-Entrepot data spanning 2013–2026

HexDex claimed to be selling multiple stolen databases from French retailer Airsoft-Entrepot, allegedly exposing extensive customer, order, invoice, supplier, delivery, accounting, B2B, and inventory records. The listing said the customer dataset included 383,000 unique customer profiles, 328,000 email addresses, 243,000 phone numbers, and 333,000 full address records.

HexDex allegedly breaches Allopneus customer data spanning 2014–2026

Threat actor HexDex claimed to have stolen a large dataset from French online tire retailer Allopneus, allegedly containing 453,299 unique customers and 739,316 total records. The exposed data reportedly included customer contact details and likely related delivery, vehicle, and purchase or service history.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

3 LINKEDOpen in app
Threat actors
1 linked
Organizations
2 linked
Airsoft-EntrepotAllopneus
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.