HommedeLombre
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor is known by the alias HommedeLombre. Public sources associate this alias with an individual located in France. The actor identifies himself as a hacktivist and claims affiliation with a hacker forum. He states that his actions are intended as a protest against rising gas prices. In his statements he also expresses support for French workers and patriots.
On 23 August 2023 HommedeLombre disclosed a customer database belonging to Engie’s monespaceprime service. The database was managed by an external provider, which the actor identified as the actual target of the intrusion. The exposed data included names, email addresses, phone numbers and city information for approximately 110,000 Engie customers. The actor said he did not release home addresses or financial details, citing ethical reasons. Engie confirmed the breach on 30 August, filed a complaint and began cooperating with law‑enforcement authorities. No payment card numbers, bank account information or passwords were compromised in the leak.
The intrusion was carried out by exploiting a vulnerability in the external provider’s system or software; no specific malware families or tools are mentioned in the reporting. Because the description focuses on the flaw exploitation, there is no publicly available information about the actor’s typical malware usage, tooling style or post‑exploitation techniques. Attribution to any state sponsor, criminal consortium or larger hacking group has not been established in open sources. The Engie incident remains the only publicly documented operation linked to the HommedeLombre alias, making it the representative example of the actor’s activity to date.
Incidents
Attributed incidents are available to members.
1 incident