Egidio
Case file Β· August 24, 2026

NETIM: a French registrar targeted by a new extortion group

The DYSPHOR1A group, presenting itself as recent, claims an intrusion at NETIM, a French domain registrar and hosting provider: server configurations, billing data, PayPal and Stripe information. Not confirmed, no encryption observed.

⚠️ Claimed, not confirmed. No public confirmation from NETIM was found at the time of writing. The pattern observed β€” publishing a victim list, threatening to sell the data β€” is that of a data-extortion group, not a classic ransomware operation with system encryption.

What's claimed

IP + code
IP addresses and source code claimed as exfiltrated.
DYSPHOR1A's claim, not confirmed.
Servers
Server configurations and infrastructure data.
DYSPHOR1A's claim.
PayPal Β· Stripe
Information linked to clients' electronic payment methods, and billing data.
DYSPHOR1A's claim.
0
Server encryption or classic malware observed β€” the pattern remains the threat of publication.
ZATAZ.

Timeline

CLAIMED
Week of August 17–23, 2026
The DYSPHOR1A group claims an intrusion at NETIM: IP addresses, source code, server configurations, billing data, customer personal data, PayPal and Stripe information, infrastructure details.
CONTEXT
2026
DYSPHOR1A presents itself as a recent group, associated with a community called "Normal Hunters." Its method relies on financial pressure: a storefront listing victims, monetizing certain databases, removing content upon payment.

🏒A hosting provider, so a business risk

NETIM isn't a consumer service: it's a domain registrar and hosting provider whose clients are mostly businesses and freelancers. A claim touching their billing and payment information shifts the main risk from the individual to the client business β€” wire fraud, impersonation of the client's own professional identity toward its own contacts.

What it changes for you

If you're a NETIM customer for a domain name or hosting, stay alert to any communication asking you to change your bank details or resend a payment, even if it cites a real invoice. See From Leak to Scam.

πŸ”’ Always verify by an independent channel (phone, not the email received) any change of payment details, even seemingly from a regular provider.

Frequently asked questions

Is the NETIM leak confirmed?

Not to our knowledge at the time of writing.

What is DYSPHOR1A?

A data-extortion group presenting itself as recent, with no server encryption observed to date.

Why do PayPal and Stripe change the nature of the risk?

Because NETIM's clients are mostly businesses: the risk shifts toward professional fraud, not just personal identity theft.

πŸ“Œ Last checked: August 24, 2026. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio β€” The Threat Laboratory, "NETIM: a French registrar targeted by a new extortion group," egidio.app/en/laboratoire/netim-dysphor1a-hosting-breach/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.