Skip to content

Groupe Bernard Data Published Free as the Thirteenth Leak From One Platform

Breach Report France Agriculture Published Free

Groupe Bernard Data Published Free as the Thirteenth Leak From One Platform

A forum user posting as NikolaT has published what they describe as the database of Groupe Bernard, a French group working in grain, animal nutrition and agriculture, giving a size of 22.25 GB across 330,563 files. The post presents it as the thirteenth in a running series drawn from a shared platform the actor calls BlgCloud, and announces a fourteenth against a named French company still to come. Samples cover three distinct layers: CRM records for companies, document metadata for invoices and delivery notes, and application user accounts. The data is not for sale, with download links released to anyone who replies to the thread. The claim is unverified.

Size22.25 GB
Files330,563
DistributionFree
ActorNikolaT

Post details

Targetbernard-groupe.com
CountryFrance
SectorAgriculture
ListingFree, reply to unlock
Volume22.25 GB, 330,563 files
Stated sourceShared platform
Observed
ActorNikolaT

!What the post claims

  • 22.25 GB of data
  • 330,563 files
  • Thirteenth in a series
  • Fourteenth already announced
  • Next target named
  • CRM company records
  • Registered addresses
  • Company and VAT numbers
  • Business phone numbers
  • Geographic coordinates
  • Bank account fields
  • Invoices and delivery notes
  • Work orders
  • Stored file hashes and paths
  • Application user accounts
  • Corporate email addresses
  • Password fields empty in sample
  • Access and reset timestamps

Screenshots

Forum post publishing Groupe Bernard data, observed 24 August 2026.

Mapped techniques

Mapped from the actor's own account. Claimed, not confirmed.

  • Initial access T1199 Trusted relationship Stated The data is attributed to a shared platform serving many companies rather than to the named company itself.
  • Collection T1213 Data from information repositories Stated Samples show CRM objects, document records and user tables exported together from one application.
  • Collection T1530 Data from cloud storage Inferred Document entries carry storage paths and file hashes, and the file count far exceeds what a database export alone would produce.
  • Exfiltration T1567 Exfiltration over web service Inferred Distribution is through forum hosted links. The route out of the environment is not described.

Potential impact

This is business data rather than consumer data, and the exposure runs outward from the named company rather than inward. The CRM layer describes the customers, suppliers and sites Groupe Bernard trades with, down to registered addresses, company numbers and coordinates, while the document layer is full of invoices, purchase orders and delivery notes. That pairing is the raw material for invoice fraud, because an approach that quotes a genuine order reference and a real contact at a real supplier is very hard for an accounts department to reject. The user table adds working corporate addresses and account activity dates, and although password fields are empty in the sample, knowing who has an account and when they last used it is enough to build a convincing internal lure. The more serious point is the framing: if thirteen companies have been published from one platform and a fourteenth is announced, then the platform is the incident and every other client of it should be treating this as their problem too. Because the data is free rather than sold, it will spread immediately.

iStatus Unverified

Nothing is being sold here, which removes the usual incentive to inflate, though it introduces a different one, since a numbered series builds a reputation and reputation is the currency the actor is actually collecting. The samples are the strongest element: three separate layers, with internally consistent identifiers, timestamps spanning years, storage paths and file hashes, all of which would be laborious to fabricate at this depth and are checkable against reality by anyone who downloads the set. Against that, the central claim, that this came from a shared platform rather than from the company, rests entirely on the actor's word, and the platform they name is not one with an obvious public footprint. The account is established rather than new, with a numbered series behind it. Dark Web Informer has not retrieved the files and is not linking them. Neither Groupe Bernard nor any platform provider has publicly addressed the claim.

Dark Web Informer // Threat Intelligence

Latest