INPI Registry Files With 27 Million Director Records Published
A forum actor posting as fuie has published data attributed to INPI, the French institute that administers industrial property and the national business register. The actor states they reached a file transfer service on an INPI data domain using an administrator account, found more than 170 GB available and downloaded what they could. The release is given as 27,348,474 records, 16.47 GB compressed and 165.42 GB expanded, described as covering full names of directors and representatives including birth names, month and year of birth, postal code, municipality and country of residence, professional roles, and the company name, identifier and legal form each person is attached to. A transfer log is offered as proof. The claim is unverified.
▣Post details
!What the post claims
- 27,348,474 records
- 165.42 GB uncompressed
- 16.47 GB compressed
- More than 170 GB seen on the server
- Administrator account used
- File transfer service reached
- Directors and representatives named
- Birth names and usage names
- Month and year of birth
- Postal codes
- Municipalities
- Country of residence
- Professional roles
- Company names
- Company identifiers
- Legal forms
- Registry formality archives
- Transfer log offered as proof
◱Screenshot
☷Mapped techniques
Mapped from the actor's own account. Claimed, not confirmed.
- Initial access T1078 Valid accounts Stated The actor describes signing in to a file transfer service with an administrator account rather than exploiting a flaw. How that credential was obtained is not addressed.
- Collection T1213 Data from information repositories Stated Bulk registry archives were listed and retrieved, with more visible on the server than was taken.
- Exfiltration T1048 Exfiltration over alternative protocol Stated The proof image is a client transfer log showing multi gigabyte archives pulled down over the same file transfer channel used for access.
⚠Potential impact
Much of the French business register is public by design, so company names, identifiers and legal forms are not the story. The value sits in the personal layer that is normally restricted: birth names, dates of birth and residential locality tied to named company officers. Those are exactly the details used to verify identity by telephone and to reset accounts, and a birth name is not something anyone can change. At this scale the set effectively covers the country's company directors and representatives, which makes it both an identity resource and a ranked target list for business fraud, since each person arrives attached to their role and their company.
iStatus Unverified
The proof offered is a transfer log rather than the data, though the file names, multi gigabyte sizes and dated naming pattern are consistent with how bulk registry archives are actually published. The important gap is the credential: the actor claims an administrator account and says nothing about where it came from, which leaves open whether this was a leaked login, a reused password or an account that should never have had that reach. The visible sample is a company record of the kind already published openly, so it demonstrates little about the restricted personal fields the post advertises. Dark Web Informer has not retrieved the files and is not linking them, and INPI has not publicly addressed the claim.
Dark Web Informer // Threat Intelligence