CTIPilot

AplaGroup

actor · actor:aplagroup single-source

Forum handle behind a 3 June 2026 data-leak posting against SDIS d'Indre-et-Loire, claiming 2,637 public-service agent records and 54 records linked to private structures; part of the recurring campaign of data-theft claims against French departmental fire-and-rescue services (ZATAZ, 2026-07-26).

Coverage timeline
1
first 2026-08-31 → last 2026-08-31
Peak priority
notable
1 notable
Sources cited
3
2 hosts
Sections touched
1
active-threats
Co-occurring entities
3
see Co-occurring entities below
ATT&CK techniques
2
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

2 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-31/france-sdis-fire-rescue-data-leak-campaign · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-31/france-sdis-fire-rescue-data-leak-campaign · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-31/france-sdis-fire-rescue-data-leak-campaign · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-31/france-sdis-fire-rescue-data-leak-campaign · ATT&CK page ↗

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-08-31/france-sdis-fire-rescue-data-leak-campaign · ATT&CK page ↗

Story timeline

  1. 2026-08-31A recurring wave of data-leak claims against French departmental fire-and-rescue services (SDIS) hits seven more units, with the first board-level victim confirmation
    active-threatsSDIS du Gard's own board confirms the theft a criminal forum had already been claiming for weeks

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

attributed activity

Where this entity is cited

  • active-threats1

Source distribution

  • zataz.com2 (67%)
  • objectifgard.com1 (33%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about AplaGroup (1)

2026-08-31 · view entry permalink →

NOTABLENATOB2

A recurring wave of data-leak claims against French departmental fire-and-rescue services (SDIS) hits seven more units, with the first board-level victim confirmation

Over the last weekend of August 2026 a criminal actor published fresh data-leak claims against seven more French Services départementaux d'incendie et de secours (Somme, Essonne, Bas-Rhin, Bouches-du-Rhône, Gard, Vosges and Moselle) extending a campaign ZATAZ first documented in late July 2026 against five other SDIS (Aisne, Alpes-de-Haute-Provence, Landes, Marne, Alpes-Maritimes), where postings were attributed to three separate criminal-forum handles: ChimeraZ, Cybernox and AplaGroup (ZATAZ.COM, 2026-08-30). Of the August wave, Objectif Gard names only ChimeraZ, tying the same handle to five of the seven units (Gard, Bouches-du-Rhône, Moselle, Bas-Rhin and Vosges); no source names an actor for the Somme or Essonne claims, or ties Cybernox or AplaGroup to this wave. This is not merely a criminal claim: contacted directly on 30 August, the president of SDIS du Gard's governing board confirmed the cyberattack and theft of personal data on personnel, including copies of identity documents and bank details, with the full scope and intrusion method still under investigation (Objectif Gard, 2026-08-30).

No common intrusion vector has been established across the incidents in this campaign. The one case with a stated mechanism is from the July wave: SDIS de l'Aisne, where a claimed administrator-level access credential was posted in cleartext by the actor; ZATAZ notes its current validity cannot be established from the post alone, since access can be disabled or changed after disclosure, but the posting itself is a more critical indicator than a plain directory extraction (ZATAZ.COM, 2026-07-26). The July wave's cumulative claims, spanning the Landes, Marne (2,167 people), Alpes-Maritimes (2,325 people), Alpes-de-Haute-Provence and Aisne SDIS, plus separate claims against SDIS d'Indre-et-Loire (2,637 public-service agents plus 54 individuals linked to private structures) and the Pompiers.fr / Fédération nationale des sapeurs-pompiers de France membership platform (ZATAZ.COM, 2026-07-26), totalled at least 166,376 exposed individuals, with a potential total exceeding 932,376 depending on the volumes claimed; ZATAZ is explicit that this estimate is a straight sum of announced record counts and does not mean each line was technically verified or maps to a distinct person (ZATAZ.COM, 2026-08-30). Each publication in the campaign otherwise appears to be a distinct claim rather than evidence of one coordinated technical compromise.

SDIS du Gard was indeed the victim of a cyberattack and data theft. Contacted this Sunday 30 August by Objectif Gard, Alexandre Pissas, chairman of SDIS 30's board, confirms the computer attack and the theft of personal data concerning personnel.

Among the stolen information are said to be particularly sensitive data, notably copies of identity documents and bank details.

Objectif Gard 2026-08-30

this data can help map personnel, roles, technical structures, hierarchical relationships and digital infrastructure of the French rescue services

ZATAZ.COM
threat31 Aug 05:00Zsingle-sourceOpen finding ↗