惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
Martin Fowler
Martin Fowler
博客园_首页
量子位
T
Tailwind CSS Blog
博客园 - Franky
G
Google Developers Blog
D
DataBreaches.Net
Vercel News
Vercel News
B
Blog
Recent Announcements
Recent Announcements
S
SegmentFault 最新的问题
M
MIT News - Artificial intelligence
爱范儿
爱范儿
博客园 - 【当耐特】
The Cloudflare Blog
H
Help Net Security
云风的 BLOG
云风的 BLOG
P
Proofpoint News Feed
C
Check Point Blog
有赞技术团队
有赞技术团队
Microsoft Security Blog
Microsoft Security Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

GRAHAM CLULEY

Former AT&T store worker jailed after moonlighting as a SIM-swap gang's inside man 'Anne Hathaway' admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars Smashing Security podcast #484: How websites are tracking you with silence CRPx0 ransomware: what you need to know The US military just turned off ad tracking on its phones. Maybe you should too How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts Smashing Security podcast #483: This AI helps thieves steal your iPhone Revolut scam steals £180,000 from Jersey residents in just four weeks Shai-Hulud hackers: two men charged over TeamPCP's global supply chain crime spree that hit OpenAI, and thousands more US Navy tells sailors and their families: scrub your social media, enemies are watching Smashing Security podcast #482: This hacker leaked GTA 6 - and launched their own cryptocurrency Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials Gunra ransomware: what you need to know Smashing Security podcast #481: Never say this to a robot dog Prison for data analyst who tried to extort $2.5 million from his employer An "invisible" car? Researcher uses machine learning to hide vehicles from Flock cameras Smashing Security podcast #480: This is the AI service you should never sign up to Meta's Ray-Bans are being banned from pubs, restaurants, and theatres Beware cut-price AI services that read your every word Apple's bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Fake IRS letters target cryptocurrency holders The $5 million threat: AI Is supercharging phishing attacks North Korea's elite hackers turned on their own government — and got caught Smashing Security podcast #478: This job interview could destroy your company OpenAI's AI "goes rogue" and hacks Hugging Face: what you need to know Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker Ukraine warns fake CAPTCHAs are being used to make you hack yourself Google's Gemini lets strangers send messages from your locked Android phone
French police arrest 21-year-old "HexDex" hacker over 100...
Graham CLULEY · 2026-04-28 · via GRAHAM CLULEY

A 21-year-old man suspected of conducting approximately 100 data breaches since late 2025 - including a hack of the French Ministry of National Education that exposed records on almost a quarter of a million employees — has been arrested at his home in western France.

According to French prosecutors, the man was reportedly preparing to dump yet another collection of stolen data online at the time of his arrest on 20 April, and has admitted to using the pseudonym "HexDex" online.

The police investigation began on 19 December last year, when the Paris prosecutor's cybercrime unit received around 100 reports of data exfiltration, all apparently linked to the same perpetrator.

The man has since been formally charged with six offences, four of which carry the 'organised gang' aggravator under French law, and has been remanded in custody pending trial.

In an interview given before his arrest, HexDex reportedly described his motivation as purely financial."

HexDex's alleged victims reportedly include:

  • The French Ministry of National Education - where he is said to have compromised Compas, the trainee teacher management system, exposing names, home addresses, phone numbers, and absence records for around 243,000 employees.
  • The SIA, France's national firearms registry.
  • The e-campus platform used to train France's national police force.
  • The trade unions CFDT and FO.
  • Paris's Philharmonie concert hall.
  • Numerous French sports federations: sailing, athletics, motor sports, gymnastics, skiing, rugby league, aikido, university sport, mountain and climbing, American football, hiking, aeronautics, canoeing and kayaking, disability sports, and savate.
  • French food banks.
  • The hotel chains Logis Hôtels France and Brit Hotel.

Stolen data is said to have been republished on the cybercriminal marketplaces BreachForums and DarkForums, where his account is now displaying a message saying that it "had been seized."

Although HexDex has been linked to many data breaches, the authorities in France have been at pains to point out that he is not believed to be responsible for the recent breach of the ANTS portal, which may have exposed data on up to 12 million account holders.

If French police have indeed captured the true culprit, what's striking is that the breaches were not the work of a state-sponsored gang or slick ransomware group. Sometimes it can just be one young man, working from home, methodically exploring which organisations have not secured their systems properly.

The volume of breaches (roughly four claimed per week, for months on end) illustrates the depressing reality that even in 2026 we still have many web-facing systems with little or no authentication, unpatched vulnerabilities, and default passwords waiting to be guessed. Organisations would be wise to wake up to the importance of better security systems with multi-factor authentication (MFA), keeping networks and apps patched, strong access controls, and a tested incident response plan.

For every HexDex who eventually gets a knock on the door from the police, there are sadly plenty more still beavering away. The best way to prevent your organisation from being the next one targeted by hackers is to make yourself less attractive than the next organisation along.