730 Million Stolen Records: Police Take Down Reacher, the Pirate Search Engine Run by 3 Teens
The French anti-cybercrime office (OFAC) has arrested three suspected administrators of a “lookup.” Behind that term is a pirate search engine that compiles and resells personal data taken from breaches and cyberattacks. The site, first called Reacher, was renamed Stryx at the beginning of the summer.
This article will also interest you: X (Twitter) Scam: This Fake Email Can Hack Your Account
According to the authorities, it made it possible to find a person from a phone number, an IBAN, a name, or even a license plate.
What is known about the operation
On Tuesday, October 6, OFAC arrested three suspects. All of them are 17 years old and were previously unknown to the justice system.
They are suspected of:
- receiving data obtained through fraudulent extraction;
- fraudulent possession of data;
- fraudulent transmission of data;
- acting as part of an organized group.
The penalties can reach up to ten years in prison. Their trial is scheduled for January 2027.
This case is not isolated. In June, France had already arrested seven young hackers after more than 1,500 cyberattacks committed on French territory.
Reacher/Stryx: a lookup that claimed 730 million records
Created in March 2026, Stryx displayed striking figures:
| Item | Claimed figure |
|---|---|
| Indexed data rows | 730 million |
| Queries made | More than 3 million |
| Access | Free or subscription |
| Paid features | Extra credits |
| Search criteria | Name, phone, IBAN, license plate |
The process was simple: the user entered a piece of information, and the site returned everything it knew about the person concerned. The model recalls the so-called “Google of data breaches.”
An investigation opened after a report from e-Enfance
The investigation was opened on May 15, after a report from the e-Enfance association. In the wake of the operation, the authorities collected data on the administrators, customers, and users of the service.
That information is still being analyzed. A possible consequence: Reacher users could also face legal action.
Lookup users in the authorities’ sights
The takedown of Reacher/Stryx is part of a series of actions against platforms that aggregate stolen data.
- In May, a 19-year-old was charged and placed in pretrial detention for creating and running the site C3N Backup.
- More recently, BrixHub, which claims 11 billion records, drew the attention of Anne Le Hénanff, the minister in charge of digital affairs.
- On October 5, she referred that lookup to the justice system, with the aim of having it shut down.
The authorities are therefore trying to hit the whole ecosystem: administrators, but also users and customers of these services.
Why are lookups dangerous?
A lookup does not merely index information that is already public. It compiles data taken from security breaches, sometimes highly sensitive:
- postal addresses;
- phone numbers;
- dates of birth;
- IBANs;
- social security numbers;
- license plates;
- login credentials.
That information can then be used to:
- steal an identity;
- run targeted phishing campaigns;
- commit bank fraud;
- blackmail someone;
- resell complete profiles to other cybercriminals.
FAQ: common questions about the Reacher/Stryx case
What is a lookup?
A lookup is a pirate search engine that compiles personal data taken from breaches and hacks, then makes it searchable, often for free or through a subscription.
Who was arrested in the Reacher/Stryx case?
Three suspected administrators, aged 17, were arrested by OFAC on October 6. They were previously unknown to the justice system.
What sentences do they face?
They face up to ten years in prison for receiving fraudulently extracted data, and for fraudulent possession and transmission of data as part of an organized group. Their trial is scheduled for January 2027.
Can users of the site be prosecuted?
The investigation collected data on the administrators, customers, and users. Their situation is still being analyzed, which means they could also face prosecution.
What should you do if your data appears on a lookup?
Paying to have it removed is not recommended. It is better to report the site to the relevant authorities, change your passwords, turn on two-factor authentication, and watch your bank accounts.
What to remember
- OFAC arrested three suspected administrators of Reacher, renamed Stryx.
- The suspects are 17-year-old minors, previously unknown to the justice system.
- The site claimed 730 million indexed data rows and more than 3 million queries.
- It made it possible to search for a person by name, phone number, IBAN, or license plate.
- The investigation was opened on May 15 after a report from e-Enfance.
- Data on administrators, customers, and users was collected.
- Other platforms such as C3N Backup and BrixHub are also in the authorities’ sights.
The authorities’ message is clear: lookups are not harmless services. Administrators and users alike expose themselves to criminal prosecution.