ctipilot.ch
← Back to the live brief
NOTABLENATOB2threat

Chat Control backlash turns operational: a hacktivist compiles targeting dossiers on French and EU officials out of old breach data, not a new intrusion

discovered 2026-07-27 04:33 UTCrun 2026-07-27T0409Z-intel2 sourcesmulti-source

A hacktivist published personal dossiers on French national and European political figures on 25 July, presenting the release as protest against "Chat Control 1.0" — the temporary EU derogation from ePrivacy rules that permits detection of child-sexual-abuse material in private communications (ZATAZ.COM, 2026-07-26). The handle "Cybernox" comes from Cyberattaque.org, which dates the claim to 25 July (Cyberattaque.org, 2026-07-26); ZATAZ does not name the actor, describing only a hacker previously linked to around ten leaks affecting French companies. The two accounts also differ on scope, and the entry keeps both: ZATAZ puts the number of targeted figures at 24 and lists Nadine Morano, Raphaël Glucksmann, Bernard Guetta, Nathalie Loiseau, Pascal Canfin and François-Xavier Bellamy among them, while Cyberattaque.org describes a second group of officials the actor classified as having voted differently and states that "Le nombre total de personnes présentes dans les fichiers n'est pas non plus précisé" — the total number of people in the files is not specified either. ZATAZ records the contents as "des photographies, des adresses personnelles, des numéros de téléphone, des courriels, des dates de naissance et plusieurs identifiants administratifs" — photographs, home addresses, phone numbers, emails, dates of birth and several administrative identifiers — with banking details in some records (ZATAZ.COM, 2026-07-26). Cyberattaque.org adds that French social-security numbers (NIR) appear in the set, and notes that the two-group split reflects only the actor's own labelling of how each official voted rather than any verified voting record (Cyberattaque.org, 2026-07-26).

The defining fact is what did not happen. ZATAZ is explicit that "Cette action ne révèle donc pas une intrusion unique contre le Parlement, elle illustre l'exploitation politique de données déjà compromises et leur recomposition en dossier de pression" — the operation reveals no single intrusion against Parliament, but rather the political exploitation of already-compromised data recomposed into a pressure dossier (ZATAZ.COM, 2026-07-26). Cyberattaque.org reaches the same conclusion by a different route, noting that the exact origin of the dataset is not established and that the records vary from administrative-looking data to customer files, commercial databases and loyalty-programme entries — heterogeneity that points to aggregation across sources rather than extraction from one system, with no technical evidence offered that any organisation was directly compromised (Cyberattaque.org, 2026-07-26). ZATAZ frames the compounding effect precisely: an old address, a still-active number and an administrative document leaked in three separate incidents combine into one exploitable profile, and the risks it names for the targets are spearphishing, identity theft, banking fraud and coordinated harassment (ZATAZ.COM, 2026-07-26).

Cette action ne révèle donc pas une intrusion unique contre le Parlement, elle illustre l’exploitation politique de données déjà compromises et leur recomposition en dossier de pression.

Le dossier rassemble des photographies, des adresses personnelles, des numéros de téléphone, des courriels, des dates de naissance et plusieurs identifiants administratifs. Certaines fiches contiennent aussi des coordonnées bancaires.

ZATAZ.COM 2026-07-26

Une fuite de données à motivation politique a été revendiquée le 25 juillet 2026 par le hacker Cybernox.

Cyberattaque.org 2026-07-26

ATT&CK mapping

2 techniques mapped from the cited reporting · MITRE ATT&CK v19.1

Reconnaissance TA0043
T1589Gather Victim Identity Information

Adversaries may gather information about the victim's identity that can be used during targeting. Information about identities may include a variety of details, including personal data (ex: employee names, email addresses, security question responses, etc.) as well as sensitive details such as credentials or multi-factor authentication (MFA) configurations.

overlap matrix · ATT&CK page ↗

T1589.002Gather Victim Identity Information: Email Addresses

Adversaries may gather email addresses that can be used during targeting. Even if internal instances exist, organizations may have public-facing email infrastructure and addresses for employees.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.