> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# French Ministry Staff Directory and Inspector Records Published Free
- URL: https://darkwebinformer.com/french-ministry-staff-directory-and-inspector-records-published-free/
- Published: 2026-09-02T16:26:10.000Z
- Updated: 2026-09-02T16:26:10.000Z
- Author: Dark Web Informer
- Tags: Data Breaches

Breach Report France Central Government Published Free 

## French Ministry Staff Directory and Inspector Records Published Free

A forum actor posting as **mondial**, crediting one collaborator, has published two datasets attributed to **developpement-durable.gouv.fr**, the domain of France's **Ministry for Ecological Transition**. The first is a staff directory of **8,166 accounts**, described as carrying **8,166 unique email addresses, 5,278 landlines, 3,642 mobile numbers, 4,849 staff reference numbers and 942 units or directorates**, with directory logins, organisational paths and office addresses. The second holds **14,656 records for certified controllers**, including names, dates of birth, approval and internal reference numbers, employing organisations and certification dates. The actor attributes access to **an API misconfiguration and an access control flaw** in a separate tool. The claim is **unverified**.

Severity HIGH 

[ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) 

Controller records14,656

Staff accounts8,166

Units listed942

Actormondial

### ▣Post details

Targetdeveloppement-durable.gouv.fr

CountryFrance

SectorCentral government

ListingFree, reply to unlock

VolumeTwo datasets

Stated sourceAPI and access control flaws

ObservedSep 2, 2026

Actormondial, with one other

### !What the post claims

- Two datasets published
- 14,656 controller records
- 8,166 staff accounts
- 8,166 unique email addresses
- 5,278 landline numbers
- 3,642 mobile numbers
- 4,849 staff reference numbers
- 942 units and directorates
- Directory logins and identifiers
- Organisational unit paths
- Office street addresses
- Names and salutations
- Account verification flags
- Controller dates of birth
- Approval numbers
- Employing organisations
- Certification and notification dates
- Active status flags

### ◱Screenshot

[ ![Forum post publishing staff directory and controller records attributed to a French ministry domain, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/2873957298635982763549872635698762359687239875.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/2873957298635982763549872635698762359687239875.png) 

Forum post publishing ministry directory and controller data, observed 2 September 2026.

### ☷Mapped techniques

Mapped from the actor's own account. Claimed, not confirmed.

- Initial access [T1190](https://attack.mitre.org/techniques/T1190/) Exploit public facing application Stated Two weaknesses are named by class: a misconfigured interface on an authentication host, and a missing authorisation check in a separate application. Neither is described in detail.
- Discovery [T1087.002](https://attack.mitre.org/techniques/T1087/002/) Domain account discovery Inferred The staff dataset carries directory attributes including organisational unit paths and distinguished names, indicating an enumeration of the identity directory rather than a website export.
- Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Stated Two separate systems were drawn from, one holding staff identities and one holding the register of certified controllers.
- Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Distribution runs through forum hosting behind a reply wall. The route out of the environment is not described.

### ⚠Potential impact

There are no passwords here, so the risk is **impersonation rather than account takeover**. A directory listing every member of staff with their login, reference number, unit and desk phone is **an organisational chart of a ministry**, and it is the groundwork for internal style phishing that names the right person in the right directorate. The controller register is the sharper half: those are **named individuals whose approval carries regulatory weight**, published alongside their dates of birth and approval numbers, which supports impersonation of an inspector as well as fraud against the people themselves.

### iStatus Unverified

The post is **more specific than most about how the data was reached**, naming two classes of weakness rather than simply asserting access, and the **per field counts** are the work of someone who has parsed the files rather than guessed at them. What is published is still **two sample rows**, which is not enough to establish scale or authenticity. The collaborator credited here also appears in a separate French claim posted the same day, which is worth tracking. Dark Web Informer has **not retrieved the files and is not linking them**, and the ministry has not publicly addressed the claim.

Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=developpement-durable-2026-09-02&utm%5Fcontent=threat-feed) and search there for this alert.

[View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=developpement-durable-2026-09-02&utm%5Fcontent=pricing-button) 

[Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=developpement-durable-2026-09-02&utm%5Fcontent=footer) // Threat Intelligence