socradar.io 5 Oct 2026, 07:39 UTC

Dark Web Claims Expose 10 Million French Records and More

CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Status Unknown

SOCRADAR’S Dark Web Team report highlights a cluster of fresh underground posts alleging a mix of data leaks and access to compromised infrastructures. The most prominent claim is an IQUALIF-based leak of more than 10 million French residential records, with the sample reportedly containing names, addresses, postal codes, gender, phone numbers, housing type, age, ethnicity, and marketing fields.

Also alleged is a breach of IUT Paris Seine (part of Université Paris Cité), with about 6.8GB of data and 30 million logs referenced, though verification remains pending. A separate post advertises access to a U.S.-based manufacturing company via an initial access broker, claiming 138 Active Directory hosts, domain user rights, Windows Defender protection, and a starting bid of $1,800 rising to a buy-it-now of $2,200.

In addition, the report notes a claim of a “19M SMTPs MIX” credential dump, described as containing roughly 19 million SMTP credentials with a sample link provided, which could enable abuse of mail infrastructure for phishing, spam, or business email compromise if authentic.

Finally, a post markets a tool to exploit CVE-2017-5638 in Apache Struts and claims access to four compromised servers, including one linked to a Canadian university, with details on claimed remote commands, administrative control, and persistence. The article emphasises that all items are unverified at this stage; if validated, the potential impacts include credential abuse, targeted phishing, ransomware deployment, data exfiltration, and lateral movement.

View full article

Article by CyberSIXT