Mistral denies a second breach; the code on sale looks like May's leak
A seller claims a fresh theft of Mistral's full source code; the company denies a new breach, and samples overlap the May leak.
Original event 2026-09-22
Mistral denies being hacked again, saying its investigation found no evidence of new unauthorized access.
On September 16, an account using the handle "mrwho" posted on an English-language cybercrime forum offering what it called Mistral's full source code, priced in Monero only. Mistral responded that it had "found no evidence to support this claim," but has not stated whether the listed code is genuine.
FrenchBreaches compared the 339-file tree the account shared and found at least four repository names that also appear in TeamPCP's May leak samples. No customer data has surfaced in analyzed samples, and nobody has shown files created after May 12. Deciding whether a second breach happened requires commits or still-valid credentials dated after May, which no one has verified.
The seller's account was created in September with four posts, so it could be a scam or a resale of the May dump.