Key Takeaways
The notorious BreachForums appears to have re-emerged, claiming a significant data breach targeting the French state. On December 13, 2025, a forum administrator using the alias "Indra" posted a statement intended to clarify recent confusion about the forum's status and to assert that the platform is not a law enforcement honeypot as ShinyHunters said
It’s not clear yet what this announcement means, whether it comes from a member of the previously disrupted dark net platform or just another honeypot. Meanwhile, earlier this month, RaidForums V2 came back online at the same clearnet site, raidforums[.]st, and under a new onion.
To prove its autonomy and retaliate for the arrest of their associates, the group claims to have successfully executed a French government hack, specifically targeting the Ministry of the Interior ("MININT").
Interior Minister Laurent Nuñez said in a statement shared with RTL Radio on Friday that an unnamed attacker had accessed some files during a recent cyberattack targeting its email servers.
The post details an extensive exfiltration of sensitive data, challenging official narratives that reportedly limited the incident to email server access. The threat actors allege they have accessed the "TAJ" (Criminal Records Processing) and "FPR" (Wanted Persons) databases, claiming to hold records on 16,444,373 individuals.Â
Furthermore, the statement suggests the compromise extends beyond the police files to include INTERPOL's "EASF MI" system, the DGFIP (public finances), and the CNAV (pensions).Â
This alleged MININT data compromise represents cybersecurity threats facing sovereign nations, potentially exposing millions of citizens and law enforcement data.
The administrators have issued an ultimatum to the French government, providing a one-week window to establish contact via a redacted method to "negotiate what happens to their files."Â
They offer two outcomes: the purchase and subsequent deletion of the data by the government, or the sale of the data to the cybercriminal community to verify the forum's legitimacy.Â
This incident underscores the persistent volatility of underground cyber marketplaces and the severe risks posed when these groups target national infrastructure to prove their resilience against law enforcement takedowns. The FBI Internet Crime Complaint Center (IC3) helps report related cyber criminal activity.
About 2.6GB of ‘Relief Database’ allegedly from Interpol was released on BreachForums in February, and a threat actor claimed to leak 1,000 database entries from Interpol in May.
In June, French Police disrupted BreachForums as the U.S. indicted British cyber kingpin "IntelBroker" and four other French hackers, who operated under the pseudonyms "ShinyHunters," "Hollow," "Noct," and "Depressed," were arrested.
In October, the FBI announced seizing BreachForums’ clearnet domain. Administrators ShinyHunters confirmed all database backups since 2023, including escrow records, were compromised during the seizure, but said the takedown would not impact its ongoing extortion campaign against Salesforce.Â
Meanwhile, the German government on Friday said Russian nation-state hackers were behind a 2024 hacking incident targeting air traffic control systems, as reported by German public broadcaster Deutsche Welle.