bestdata is a data-broker style cybercriminal threat actor observed advertising the sale of a large dataset described as French FICOBA banking leads. The actor publicly claimed the dataset contained approximately 1.2 million records associated with the French banking sector and more than 15 financial institutions. The advertised data was described as including extensive identity, contact, government identifier, and banking-account information, creating significant risk of identity theft, financial fraud, account impersonation, and targeted social engineering. The activity attributed to bestdata is consistent with financially motivated illicit data trafficking rather than espionage or disruptive operations. High-confidence observed behavior is limited to the claimed sale of stolen or otherwise illicitly obtained financial and personal data. Based on the available facts, the actor’s demonstrated capability is centered on exfiltration and monetization of sensitive data. The targeting reflected in the advertised dataset aligns with the French financial sector, particularly banking institutions and account-holder data associated with France’s bank-account registry ecosystem. No high-confidence attribution to a nation state, formal intrusion set, or broader criminal syndicate is currently available. No corroborated sub-groups or widely used alternate aliases are currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.