Skip to content

Docurba User Tables Shared, Exposing French Planning Officials and Admin Flags

Breach Report France Government Platform Shared Free

Docurba User Tables Shared, Exposing French Planning Officials and Admin Flags

A forum user posting as 0xSec has published what they describe as the user tables of docurba.beta.gouv.fr, a French state platform used by local authorities, consulting firms and government services to develop urban planning documents such as PLUs and SCoTs. The release is three spreadsheets totalling 5,152 rows, covering names, work email addresses, telephone numbers, job titles and the authority each person belongs to, together with administrator and staff flags, verification status and login state. The actor states they could have taken the rest of the data but chose not to, describing it as worthless. The files are unlocked for a nominal forum fee. The claim is unverified.

Rows5,152
FilesThree
Further accessClaimed
Actor0xSec

Post details

Targetdocurba.beta.gouv.fr
CountryFrance
SectorGovernment platform
ListingNominal forum fee
Volume5,152 rows
FormatXLSX, three files
Observed
Actor0xSec

!What the post claims

  • 5,152 rows in three files
  • XLSX format
  • First and last names
  • Work email addresses
  • Telephone numbers
  • Job titles
  • Secondary job titles
  • Department and region
  • Authority identifiers
  • SIREN numbers
  • INSEE codes
  • Administrator flags
  • Staff flags
  • Verification status
  • First login indicator
  • Marketing opt in status
  • CRM sync field
  • Wider access claimed

Screenshot

Forum post publishing Docurba user tables, observed 25 August 2026.

Mapped techniques

Mapped from the actor's own account. Claimed, not confirmed.

  • Collection T1213 Data from information repositories Stated The actor says they selected the user tables and left the rest, which implies query level access rather than a single dump taken blind.
  • Exfiltration T1567 Exfiltration over web service Inferred Distribution is through forum hosting behind a points wall. The route out of the environment is not described.

Potential impact

Five thousand rows with no passwords looks minor, and as a privacy incident it largely is. As a targeting list it is considerably more useful than its size suggests. Every row names a working official, gives their job title, their direct line, their work address and the authority they sit in, and the export helpfully marks which of them hold administrator or staff privileges on a government platform. That is the shortlist a phishing operation would otherwise have to assemble by hand, and it arrives pre sorted by seniority and by region. The context raises the value further, because PLUs and SCoTs govern what can be built where, decisions with direct financial consequences for developers and landowners, so the people in this file are worth impersonating as well as worth compromising. The line that deserves the most attention is the actor's own: they say the remaining data was left behind by choice. If that is true, the access was broader than what has been published, and the planning documents themselves remain within reach.

iStatus Unverified

The column lists are the most persuasive element. They include internal relational naming across three joined tables and operational fields such as verification state, first login and a CRM sync marker, which is the kind of detail that comes from looking at a real schema rather than from imagining one. Set against that, no intrusion method, date or access route is given, and the claim of wider access is both unverifiable and self serving, since dismissing the unpublished data as worthless conveniently explains why none of it was shown. The account is established, with a long history and a paid rank. The nominal points fee is a distribution mechanic rather than a price, and does not indicate the data is being sold. Dark Web Informer has not retrieved the files and is not linking them. Neither the platform team nor any French authority has publicly addressed the claim.

Dark Web Informer // Threat Intelligence

Latest