French Ministry Staff Directory and Inspector Records Published Free
A forum actor posting as mondial, crediting one collaborator, has published two datasets attributed to developpement-durable.gouv.fr, the domain of France's Ministry for Ecological Transition. The first is a staff directory of 8,166 accounts, described as carrying 8,166 unique email addresses, 5,278 landlines, 3,642 mobile numbers, 4,849 staff reference numbers and 942 units or directorates, with directory logins, organisational paths and office addresses. The second holds 14,656 records for certified controllers, including names, dates of birth, approval and internal reference numbers, employing organisations and certification dates. The actor attributes access to an API misconfiguration and an access control flaw in a separate tool. The claim is unverified.
▣Post details
!What the post claims
- Two datasets published
- 14,656 controller records
- 8,166 staff accounts
- 8,166 unique email addresses
- 5,278 landline numbers
- 3,642 mobile numbers
- 4,849 staff reference numbers
- 942 units and directorates
- Directory logins and identifiers
- Organisational unit paths
- Office street addresses
- Names and salutations
- Account verification flags
- Controller dates of birth
- Approval numbers
- Employing organisations
- Certification and notification dates
- Active status flags
◱Screenshot
☷Mapped techniques
Mapped from the actor's own account. Claimed, not confirmed.
- Initial access T1190 Exploit public facing application Stated Two weaknesses are named by class: a misconfigured interface on an authentication host, and a missing authorisation check in a separate application. Neither is described in detail.
- Discovery T1087.002 Domain account discovery Inferred The staff dataset carries directory attributes including organisational unit paths and distinguished names, indicating an enumeration of the identity directory rather than a website export.
- Collection T1213 Data from information repositories Stated Two separate systems were drawn from, one holding staff identities and one holding the register of certified controllers.
- Exfiltration T1567 Exfiltration over web service Inferred Distribution runs through forum hosting behind a reply wall. The route out of the environment is not described.
⚠Potential impact
There are no passwords here, so the risk is impersonation rather than account takeover. A directory listing every member of staff with their login, reference number, unit and desk phone is an organisational chart of a ministry, and it is the groundwork for internal style phishing that names the right person in the right directorate. The controller register is the sharper half: those are named individuals whose approval carries regulatory weight, published alongside their dates of birth and approval numbers, which supports impersonation of an inspector as well as fraud against the people themselves.
iStatus Unverified
The post is more specific than most about how the data was reached, naming two classes of weakness rather than simply asserting access, and the per field counts are the work of someone who has parsed the files rather than guessed at them. What is published is still two sample rows, which is not enough to establish scale or authenticity. The collaborator credited here also appears in a separate French claim posted the same day, which is worth tracking. Dark Web Informer has not retrieved the files and is not linking them, and the ministry has not publicly addressed the claim.
Dark Web Informer // Threat Intelligence