Skip to content

French Ministry Staff Directory and Inspector Records Published Free

Breach Report France Central Government Published Free

French Ministry Staff Directory and Inspector Records Published Free

A forum actor posting as mondial, crediting one collaborator, has published two datasets attributed to developpement-durable.gouv.fr, the domain of France's Ministry for Ecological Transition. The first is a staff directory of 8,166 accounts, described as carrying 8,166 unique email addresses, 5,278 landlines, 3,642 mobile numbers, 4,849 staff reference numbers and 942 units or directorates, with directory logins, organisational paths and office addresses. The second holds 14,656 records for certified controllers, including names, dates of birth, approval and internal reference numbers, employing organisations and certification dates. The actor attributes access to an API misconfiguration and an access control flaw in a separate tool. The claim is unverified.

Controller records14,656
Staff accounts8,166
Units listed942
Actormondial

Post details

Targetdeveloppement-durable.gouv.fr
CountryFrance
SectorCentral government
ListingFree, reply to unlock
VolumeTwo datasets
Stated sourceAPI and access control flaws
Observed
Actormondial, with one other

!What the post claims

  • Two datasets published
  • 14,656 controller records
  • 8,166 staff accounts
  • 8,166 unique email addresses
  • 5,278 landline numbers
  • 3,642 mobile numbers
  • 4,849 staff reference numbers
  • 942 units and directorates
  • Directory logins and identifiers
  • Organisational unit paths
  • Office street addresses
  • Names and salutations
  • Account verification flags
  • Controller dates of birth
  • Approval numbers
  • Employing organisations
  • Certification and notification dates
  • Active status flags

Screenshot

Forum post publishing ministry directory and controller data, observed 2 September 2026.

Mapped techniques

Mapped from the actor's own account. Claimed, not confirmed.

  • Initial access T1190 Exploit public facing application Stated Two weaknesses are named by class: a misconfigured interface on an authentication host, and a missing authorisation check in a separate application. Neither is described in detail.
  • Discovery T1087.002 Domain account discovery Inferred The staff dataset carries directory attributes including organisational unit paths and distinguished names, indicating an enumeration of the identity directory rather than a website export.
  • Collection T1213 Data from information repositories Stated Two separate systems were drawn from, one holding staff identities and one holding the register of certified controllers.
  • Exfiltration T1567 Exfiltration over web service Inferred Distribution runs through forum hosting behind a reply wall. The route out of the environment is not described.

Potential impact

There are no passwords here, so the risk is impersonation rather than account takeover. A directory listing every member of staff with their login, reference number, unit and desk phone is an organisational chart of a ministry, and it is the groundwork for internal style phishing that names the right person in the right directorate. The controller register is the sharper half: those are named individuals whose approval carries regulatory weight, published alongside their dates of birth and approval numbers, which supports impersonation of an inspector as well as fraud against the people themselves.

iStatus Unverified

The post is more specific than most about how the data was reached, naming two classes of weakness rather than simply asserting access, and the per field counts are the work of someone who has parsed the files rather than guessed at them. What is published is still two sample rows, which is not enough to establish scale or authenticity. The collaborator credited here also appears in a separate French claim posted the same day, which is worth tracking. Dark Web Informer has not retrieved the files and is not linking them, and the ministry has not publicly addressed the claim.

Dark Web Informer // Threat Intelligence

Latest