Rex Mundi
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Rex Mundi is a hacker collective known primarily by that alias, with open‑source references indicating a possible base in France. The group first appeared in public reports around 2014 and has since been linked to a series of data‑theft extortion incidents across Western Europe. Their self‑described motivation is financial gain, and they consistently state that they will delete stolen data only after a ransom is paid.
The actors have targeted a range of sectors including financial institutions, employment agencies, hosting providers, and fast‑food chains, focusing on organizations in Belgium, France, and Switzerland. They exploit what they describe as mediocre IT security or poorly designed web applications, using the perceived weakness as leverage for extortion. Their strategic objective is monetary profit through the threat of releasing personally identifiable information unless a payment is made, and they have repeatedly followed through on publishing data when demands are not met.
Typical tactics involve gaining access to victim servers via web‑application flaws, exfiltrating customer or applicant databases containing names, addresses, email addresses and sometimes user‑generated passwords, and then providing partial data samples as proof of compromise. The group announces breaches and ransom demands on Twitter accounts associated with the handle @rexmundi15, posts banners on compromised websites, and threatens further attacks or public leaks if payment is not received. No specific malware families or custom tooling are mentioned in the available sources; their approach relies on exploiting existing vulnerabilities and using straightforward data‑theft and extortion methods.
Representative campaigns include the 2015 breach of a Belgian loan company where 24,000 financial records were taken and a ransom demanded, the 2015 intrusion into a French employment agency that exposed applicant email addresses and passwords, the 2015 attack on Geneva’s Banque Cantonale de Geneve resulting in the release of 30,000 bank customer records after a €10,000 ransom was refused, the 2014 compromise of Domino’s Pizza systems in Belgium and France affecting over 650,000 customer records with a €30,000 extortion demand, and the 2014 extortion attempt against Belgian hosting firm AlfaNet seeking €15,000 under threat of data leakage and website attacks.
Public attribution does not link Rex Mundi to any state sponsor or larger criminal consortium; the group is presented as an independent financially motivated actor operating out of Europe. All known activities are consistent with a pattern of web‑application exploitation, data theft, and extortion for profit, without evidence of espionage, disruption, or ideological aims.
Incidents
Attributed incidents are available to members.
6 incidents