惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
Last Week in AI
Last Week in AI
T
Tailwind CSS Blog
WordPress大学
WordPress大学
B
Blog RSS Feed
T
The Blog of Author Tim Ferriss
F
Fortinet All Blogs
aimingoo的专栏
aimingoo的专栏
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
C
Check Point Blog
P
Proofpoint News Feed
H
Help Net Security
月光博客
月光博客
博客园_首页
Stack Overflow Blog
Stack Overflow Blog
博客园 - 三生石上(FineUI控件)
Martin Fowler
Martin Fowler
Recent Announcements
Recent Announcements
人人都是产品经理
人人都是产品经理
U
Unit 42
美团技术团队
I
InfoQ
A
About on SuperTechFans

Consumer Insights

The ransomware negotiator who was working for the other side After years on the run, alleged Ryuk ransomware operator pleads guilty INTERPOL crackdown shows scammers shifting to social media Meta lets strangers remix your public Instagram photos with AI—here’s how to opt out Invited to a "job interview" with Netflix or OpenAI? Beware! Your Google password could be at risk Two arrested over credit card phishing - as the Netherlands is named Europe's worst for payment fraud India pauses WhatsApp username feature over security concerns Alleged teen ransomware hustler faces US charges after arrest in Finland WhatsApp usernames explained: how to reserve yours and stay safe Scammers race to cash in on Venezuelan earthquake disaster USB drives carrying China-linked malware infected Japanese military networks for nearly a year WhatsApp tests new safety prompt before you chat with strangers Social media is worth celebrating. It's also worth protecting. Polish police dismantle SIM-swap gang accused of crypto theft Operation Endgame deals fresh blow to StealC and Amadey malware networks Hacker hijacks Brazil's national alert system, sending "misanthropy" to millions of phones Cybercrime now rivals traditional crime across parts of Asia Apple's Hide My Email tweak leaves privacy fans fuming Americans lost $3.5 billion to imposter scams last year — and the scams are getting harder to spot Scammers have killed the physical Steam Gift cards Crypto investment scam sends couriers to collect victims' cash, FBI warns Maine forced to take down data breach portal after fake notices filed with authorities Privacy own-goal: World Cup blunder leaks Lionel Messi's passport details Why schools remain one of cybercriminals' favourite targets WhatsApp detects new spyware activity from Israel’s NSO Group despite court order Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 Europol cracks down on illegal streaming globally Hackers didn't hack Instagram; they just asked Meta AI FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup Virtual knife, real lawsuit: Counter-Strike skin dispute ends in court
French police arrest 21-year-old "HexDex" hacker over 100...
Graham CLULEY · 2026-04-28 · via Consumer Insights

A 21-year-old man suspected of conducting approximately 100 data breaches since late 2025 - including a hack of the French Ministry of National Education that exposed records on almost a quarter of a million employees — has been arrested at his home in western France.

According to French prosecutors, the man was reportedly preparing to dump yet another collection of stolen data online at the time of his arrest on 20 April, and has admitted to using the pseudonym "HexDex" online.

The police investigation began on 19 December last year, when the Paris prosecutor's cybercrime unit received around 100 reports of data exfiltration, all apparently linked to the same perpetrator.

The man has since been formally charged with six offences, four of which carry the 'organised gang' aggravator under French law, and has been remanded in custody pending trial.

In an interview given before his arrest, HexDex reportedly described his motivation as purely financial."

HexDex's alleged victims reportedly include:

  • The French Ministry of National Education - where he is said to have compromised Compas, the trainee teacher management system, exposing names, home addresses, phone numbers, and absence records for around 243,000 employees.
  • The SIA, France's national firearms registry.
  • The e-campus platform used to train France's national police force.
  • The trade unions CFDT and FO.
  • Paris's Philharmonie concert hall.
  • Numerous French sports federations: sailing, athletics, motor sports, gymnastics, skiing, rugby league, aikido, university sport, mountain and climbing, American football, hiking, aeronautics, canoeing and kayaking, disability sports, and savate.
  • French food banks.
  • The hotel chains Logis Hôtels France and Brit Hotel.

Stolen data is said to have been republished on the cybercriminal marketplaces BreachForums and DarkForums, where his account is now displaying a message saying that it "had been seized."

Although HexDex has been linked to many data breaches, the authorities in France have been at pains to point out that he is not believed to be responsible for the recent breach of the ANTS portal, which may have exposed data on up to 12 million account holders.

If French police have indeed captured the true culprit, what's striking is that the breaches were not the work of a state-sponsored gang or slick ransomware group. Sometimes it can just be one young man, working from home, methodically exploring which organisations have not secured their systems properly.

The volume of breaches (roughly four claimed per week, for months on end) illustrates the depressing reality that even in 2026 we still have many web-facing systems with little or no authentication, unpatched vulnerabilities, and default passwords waiting to be guessed. Organisations would be wise to wake up to the importance of better security systems with multi-factor authentication (MFA), keeping networks and apps patched, strong access controls, and a tested incident response plan.

For every HexDex who eventually gets a knock on the door from the police, there are sadly plenty more still beavering away. The best way to prevent your organisation from being the next one targeted by hackers is to make yourself less attractive than the next organisation along.