ctipilot.ch

Cybernox

actor · actor:cybernox

Hacktivist handle credited by Cyberattaque.org with publishing personal dossiers on French national and European political figures on 2026-07-25 in protest at the EU "Chat Control" communications-scanning file. Sources differ on scope: ZATAZ puts the number of targeted figures at 24, while Cyberattaque.org describes a second group as well and states that no total is specified. ZATAZ, reporting the same operation without naming the handle, describes the actor as previously having published around ten leaks concerning French companies and assesses the dossiers as recomposed from earlier unrelated breaches rather than any fresh intrusion.

Coverage timeline
1
first 2026-07-27 → last 2026-07-27
Peak priority
notable
1 notable
Sources cited
2
2 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
2
pinned v19.1 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

2 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1589Gather Victim Identity Information×1

Adversaries may gather information about the victim's identity that can be used during targeting. Information about identities may include a variety of details, including personal data (ex: employee names, email addresses, security question responses, etc.) as well as sensitive details such as credentials or multi-factor authentication (MFA) configurations.

Evidence: 2026-07-27/cybernox-chat-control-doxing-french-eu-officials · ATT&CK page ↗

T1589.002Gather Victim Identity Information: Email Addresses×1

Adversaries may gather email addresses that can be used during targeting. Even if internal instances exist, organizations may have public-facing email infrastructure and addresses for employees.

Evidence: 2026-07-27/cybernox-chat-control-doxing-french-eu-officials · ATT&CK page ↗

Story timeline

  1. 2026-07-27Chat Control backlash turns operational: a hacktivist compiles targeting dossiers on French and EU officials out of old breach data, not a new intrusion
    active-threatsOfficials doxxed over the EU Chat Control file — dossiers assembled from years of unrelated breach data

Where this entity is cited

  • active-threats1

Source distribution

  • cyberattaque.org1 (50%)
  • zataz.com1 (50%)

explore in graph

Entries about Cybernox (1)

2026-07-27 · view entry permalink →

NOTABLENATOB2

Chat Control backlash turns operational: a hacktivist compiles targeting dossiers on French and EU officials out of old breach data, not a new intrusion

A hacktivist published personal dossiers on French national and European political figures on 25 July, presenting the release as protest against "Chat Control 1.0" — the temporary EU derogation from ePrivacy rules that permits detection of child-sexual-abuse material in private communications (ZATAZ.COM, 2026-07-26). The handle "Cybernox" comes from Cyberattaque.org, which dates the claim to 25 July (Cyberattaque.org, 2026-07-26); ZATAZ does not name the actor, describing only a hacker previously linked to around ten leaks affecting French companies. The two accounts also differ on scope, and the entry keeps both: ZATAZ puts the number of targeted figures at 24 and lists Nadine Morano, Raphaël Glucksmann, Bernard Guetta, Nathalie Loiseau, Pascal Canfin and François-Xavier Bellamy among them, while Cyberattaque.org describes a second group of officials the actor classified as having voted differently and states that "Le nombre total de personnes présentes dans les fichiers n'est pas non plus précisé" — the total number of people in the files is not specified either. ZATAZ records the contents as "des photographies, des adresses personnelles, des numéros de téléphone, des courriels, des dates de naissance et plusieurs identifiants administratifs" — photographs, home addresses, phone numbers, emails, dates of birth and several administrative identifiers — with banking details in some records (ZATAZ.COM, 2026-07-26). Cyberattaque.org adds that French social-security numbers (NIR) appear in the set, and notes that the two-group split reflects only the actor's own labelling of how each official voted rather than any verified voting record (Cyberattaque.org, 2026-07-26).

The defining fact is what did not happen. ZATAZ is explicit that "Cette action ne révèle donc pas une intrusion unique contre le Parlement, elle illustre l'exploitation politique de données déjà compromises et leur recomposition en dossier de pression" — the operation reveals no single intrusion against Parliament, but rather the political exploitation of already-compromised data recomposed into a pressure dossier (ZATAZ.COM, 2026-07-26). Cyberattaque.org reaches the same conclusion by a different route, noting that the exact origin of the dataset is not established and that the records vary from administrative-looking data to customer files, commercial databases and loyalty-programme entries — heterogeneity that points to aggregation across sources rather than extraction from one system, with no technical evidence offered that any organisation was directly compromised (Cyberattaque.org, 2026-07-26). ZATAZ frames the compounding effect precisely: an old address, a still-active number and an administrative document leaked in three separate incidents combine into one exploitable profile, and the risks it names for the targets are spearphishing, identity theft, banking fraud and coordinated harassment (ZATAZ.COM, 2026-07-26).

Cette action ne révèle donc pas une intrusion unique contre le Parlement, elle illustre l’exploitation politique de données déjà compromises et leur recomposition en dossier de pression.

Le dossier rassemble des photographies, des adresses personnelles, des numéros de téléphone, des courriels, des dates de naissance et plusieurs identifiants administratifs. Certaines fiches contiennent aussi des coordonnées bancaires.

ZATAZ.COM 2026-07-26

Une fuite de données à motivation politique a été revendiquée le 25 juillet 2026 par le hacker Cybernox.

Cyberattaque.org 2026-07-26
threat27 Jul 04:33Zmulti-sourceOpen finding ↗