> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# AFTT and FRBTT Breach Claim Includes 66,852 Subscribers and Plaintext Admin Passwords
- URL: https://darkwebinformer.com/aftt-and-frbtt-breach-claim-includes-66-852-subscribers-and-plaintext-admin-passwords/
- Published: 2026-09-15T16:59:12.000Z
- Updated: 2026-09-15T16:59:12.000Z
- Author: Dark Web Informer
- Tags: Data Breaches

Breach Report Belgium Member & Credential Data 1.69 GB 

## AFTT and FRBTT Breach Claim Includes 66,852 Subscribers and Plaintext Admin Passwords

A forum actor posting as **Venus1337** is selling what they claim is data belonging to **AFTT, Aile Francophone de Tennis de Table, and FRBTT, Fédération Royale Belge de Tennis de Table**. The actor claims the exposed material includes **66,852 subscriber records, 2,080 fine records, 17,441 user records and credentials for 87 club administrator accounts**. According to the post, the compromise began with a **remote code execution vulnerability in an insecure file-upload mechanism**, after which the actor says they deployed a web shell, accessed SQL databases and found database credentials hardcoded in a file named **secret.php**. The actor further claims that multiple club-administrator passwords were stored in plaintext inside the CPHAdmin database and that approximately **1.69 GB** of data was extracted. The claim is **unverified**.

Severity CRITICAL 

Sponsored

[ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) 

Subscribers66,852

Users17,441

Fines2,080

Club admins87

### ▣Post details

TargetsAFTT & FRBTT

CountryBelgium

SectorSports / membership organizations

ListingDatabase sale

Data volumeApprox. 1.69 GB

Claimed breach dateSep 14, 2026

ObservedSep 15, 2026

ActorVenus1337

### !What the post claims

- 66,852 subscriber records
- 17,441 user records
- 2,080 fine records
- 87 club administrator accounts
- Plaintext club-admin passwords
- Approximately 1.69 GB of data
- Affiliation or membership numbers
- Names and first names
- Player class information
- Club names
- Club and division information
- Match categories and codes
- Sanction numbers and reasons
- Fine amounts
- User identifiers and usernames
- Email addresses
- Last-visit timestamps
- RCE through insecure file upload
- Web shell deployed after initial access
- Access to SQL databases
- Hardcoded database credentials in secret.php

### ◱Screenshots

[ ![Forum post claiming a breach of AFTT and FRBTT involving member data and administrator credentials, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/5327896237659827634986723598762539876.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/5327896237659827634986723598762539876.png) [ ![Forum post showing alleged AFTT and FRBTT member, fine and user database samples, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/5327896237659827634986723598762539877.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/5327896237659827634986723598762539877.png) 

Forum post claiming compromise of AFTT and FRBTT systems and the theft of member, user, fine and administrator data, observed 15 September 2026.

### ☷Mapped techniques

The techniques below are based on methods explicitly described by the actor in the forum listing. Dark Web Informer has not independently verified the intrusion chain.

- Initial Access [T1190](https://attack.mitre.org/techniques/T1190/) Exploit Public-Facing Application Claimed The actor claims a critical remote code execution vulnerability in an insecure file-upload mechanism was used to gain unauthorized access to the web server.
- Persistence [T1505.003](https://attack.mitre.org/techniques/T1505/003/) Web Shell Claimed The actor states that a web shell was deployed after exploiting the file-upload weakness.
- Credential Access [T1552.001](https://attack.mitre.org/techniques/T1552/001/) Credentials In Files Claimed The listing says SQL database credentials were hardcoded in a configuration file named secret.php.
- Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from Information Repositories Claimed The actor claims access to SQL databases containing subscriber, user, fine and administrator records and says the databases were dumped in full.

### ⚠Potential impact

If authentic, the compromise could expose members, players and club personnel to **phishing, impersonation and credential-based attacks**. The most significant risk comes from the actor's claim that administrator passwords were stored in plaintext, which could allow those credentials to be reused against related systems if administrators used the same passwords elsewhere. Membership records, club affiliations, email addresses and account identifiers also provide useful context for targeted social engineering. A functioning web shell or unresolved file-upload vulnerability would further increase the risk of **continued unauthorized access, database manipulation or follow-on compromise**.

### iStatus Unverified

The forum post provides a detailed intrusion narrative, claimed record counts and visible samples from files named **adherents.jsonl, amendes.jsonl and users.jsonl**. It also claims that database credentials were hardcoded and that club-administrator passwords were stored in plaintext. However, Dark Web Informer has **not independently verified the vulnerability, the alleged web-shell access, the completeness of the 1.69 GB dump or the authenticity of the claimed administrator credentials**.

Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=aftt-frbtt-2026-09-15&utm%5Fcontent=threat-feed) and search there for this alert.

[View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=aftt-frbtt-2026-09-15&utm%5Fcontent=pricing-button) 

[Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=aftt-frbtt-2026-09-15&utm%5Fcontent=footer) // Threat Intelligence