Skip to content

FNIM Sites Defaced and Databases Published After a Single Server Compromise

Breach Report France Mutual Insurance Published Free

FNIM Sites Defaced and Databases Published After a Single Server Compromise

Three forum actors, led by one posting as yiranet, claim to have compromised the infrastructure of the Fédération Nationale Indépendante des Mutuelles, the French federation representing small and medium sized mutual insurers. The post states they obtained remote code execution on a server hosting several websites and defaced four of them, including the federation's main site, two billing subdomains and an associated organisation's site, offering public archive snapshots as evidence. A fifth site on the same server was not defaced because their access was removed first, though they say its data was taken anyway. Full SQL databases are published free through two file hosts. No record count or field list is given. The claim is unverified.

Sites defacedFour
Sites affectedFive
DistributionFree
ActorsThree

Post details

TargetFNIM
CountryFrance
SectorMutual insurance
ListingFree download
VolumeNot stated
Stated sourceCode execution on a server
Observed
Actoryiranet, with two others

!What the post claims

  • Remote code execution obtained
  • One server, several websites
  • Four sites defaced
  • Federation main site defaced
  • Two billing subdomains defaced
  • Associated body's site defaced
  • A fifth site on the same host
  • Access removed before defacing it
  • Data taken from it regardless
  • Full SQL databases published
  • Two file hosts used
  • Archive snapshots given as proof
  • Three actors credited
  • No record count given
  • No field list given
  • No sample data published
  • No price, released free
  • Contact addresses given

Screenshot

Forum post publishing FNIM databases and defacement claims, observed 2 September 2026.

Mapped techniques

Mapped from the actors' own account. Claimed, not confirmed.

  • Initial access T1190 Exploit public facing application Stated Code execution is claimed against a web server hosting several sites. No vulnerability or product is named.
  • Persistence T1505.003 Web shell Stated The actors refer to their shell being removed before they could deface the last site, which indicates an interactive foothold was maintained on the host.
  • Collection T1213 Data from information repositories Stated Complete SQL databases for the hosted sites are described as taken and are published in full.
  • Impact T1491.002 External defacement Stated Four public sites were altered, with archive snapshots cited so the change can be checked after the fact.
  • Exfiltration T1567 Exfiltration over web service Inferred Distribution runs through two public file hosts linked from the post.

Potential impact

Mutuelles are health insurers, so any member data held by the federation or its associated bodies falls into a sensitive category, though nothing published so far demonstrates what the databases actually contain. The billing subdomains are the part to look at first, since invoicing systems tie named organisations to payment records and bank details. The single host is the structural problem: five sites belonging to more than one organisation sat on one server, so a single foothold reached all of them, and each affected body has to assess its own exposure separately.

iStatus Unverified

The defacement element is unusually checkable, because public archive snapshots preserve what those pages looked like at a given moment, so that part of the claim can be tested independently rather than taken on trust. The database claim has none of that support: no record count, no schema, no sample and no description of contents beyond the word "everything". Dark Web Informer has not retrieved the files and is not linking them, nor the contact addresses, and FNIM has not publicly addressed the claim.

Dark Web Informer // Threat Intelligence

Latest