Threat Intelligence

Dark Web Posts Claim French Data Leak, University Breach and Cheap Access to a US Manufacturer

SOCRadar · 5 Oct 2026
Key Takeaway Protect remote access such as VPN and RDP with multi-factor authentication, and change email and SMTP credentials promptly if you suspect they have been exposed.

SOCRadar's Dark Web Team has flagged several new underground posts. One claims to leak more than 10 million French residential records, allegedly extracted using a tool called IQUALIF. The sample reportedly includes names, addresses, phone numbers, housing type, ethnicity and marketing fields. If genuine, the data could fuel phishing, smishing, fraud and wider social engineering against people in France.

Another post claims a breach of IUT Paris Seine, part of Université Paris Cité. The threat actor says it found a critical flaw in the institution's web infrastructure and took about 6.8GB of data, along with references to 30 million logs, server information and server access. The claim is unverified, but exposed logs and access details could lead to credential abuse, follow-on intrusions and exposure of student or institutional data.

An initial access broker is also auctioning access to a US manufacturing company with roughly $16 million in revenue. The seller offers VPN and RDP access to an environment with 138 Active Directory hosts and domain user rights. Bidding starts at $1,800, with a buy-it-now price of $2,200. If valid, such access could be used for ransomware, data theft or lateral movement. A separate post advertises a dump of about 19 million SMTP credentials, with a sample shared through an external file-hosting link.

dark web initial access broker data leak credential dump phishing

Summarised by CISO AI from SOCRadar, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.