> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# mutreasury Allegedly Breached: Admin Credentials and API Keys Exposed From the Egyptian University Payment Gateway Covering 28+ Universities, Sold With a Zero-Day Vulnerability
- URL: https://darkwebinformer.com/mutreasury-allegedly-breached-admin-credentials-and-api-keys-exposed-from-the-egyptian-university-payment-gateway-covering-28-universities-sold-with-a-zero-day-vulnerability/
- Published: 2026-05-14T15:02:53.000Z
- Updated: 2026-05-14T15:02:53.000Z
- Author: Dark Web Informer
- Tags: Data Breaches

Breach Report · Egypt

# mutreasury Allegedly Breached: Admin Credentials and API Keys Exposed From the Egyptian University Payment Gateway Covering 28+ Universities, Sold With a Zero-Day Vulnerability

A threat actor is selling a database from mutreasury, the centralized payment gateway connecting more than 28 Egyptian universities for tuition, application fees, and other student payments. The dump contains administrative credentials, ERP integration API tokens, and the full transaction ledger linking student PII to fee payments through Fawry, e-Finance, and Khales. The seller is also marketing an unauthenticated-access zero-day vulnerability used to dump the data, which they say allows full persistence and real-time data extraction from the remaining 24+ universities not yet included in the public preview. The current public leak covers 4 major university targets as a proof of concept, with the complete dataset covering 28+ Egyptian universities connected to the same centralized infrastructure.

Post details

Actor(s)INT3X (with credits to quellostanco, CrowStealer, @bigF)

SectorEducation / Government / Payment Gateway

TypeData Sale + Zero-Day Vulnerability Sale

FormatCSV (multiple tables)

Records28+ Egyptian universities (4 included in public preview)

CountryEgypt 

Date14/05/2026

Compromised data

sysusers.csv Identity & Access

- ID, f1 through f14, isAdmin flag, isLocal flag, item\_type
- Administrative credentials, internal employee data, access levels
- Encrypted and plaintext authentication strings
- Job titles and workplace affiliations

erpapis.csv Integration Layer

- scope\_id, account\_id, connectType
- erp\_api\_url, erp\_api\_token, erp\_api\_profile, erp\_company\_name
- Live API tokens and endpoint URLs bridging the payment gateway with internal university ERP systems
- Direct server-to-server communication credentials

efinance\_service.csv Financial Routing

- id, sender\_id, foundation\_id, fees, type, is\_active
- sender\_name, service\_url, service\_code, service\_name
- sender\_password, settlement\_code, confirmation\_url, settlement\_amount
- payment\_gateway\_url, sender\_request\_number, sender\_user\_identifier
- confirmation\_redirect\_url
- Logic and credentials for connecting to national payment providers (e-Finance and Khales)
- Settlement codes, service passwords, and redirect flows

paymentgetway.csv Transaction Master

- UnivId, user\_id, order\_id, FacultyId, SessionId, CustomerId
- UniqueInvoiceId, item, Email, Mobile, RefNum, Service, Merchant
- UnivName, Result, Status, feesName, fawryFees
- notifyurl, PaidAmount, ConfirmedAt, ConfirmedBy, ConfirmedIP
- EnquiryDate, FacultyName, CustomerCode, CustomerName
- triedConfirm, PaymentMethod, description, SuccessIndicator
- Primary ledger for all student payments, logs PII, transaction status, reference numbers (Fawry/Bank), and total amounts across various university faculties

paymentgetwaydetails.csv Transaction Details

- feeId, UniqueInvoiceId, item, Amount, feeName
- Granular breakdown of fees associated with each UniqueInvoiceId
- Payment nature specified (Application fees, Tuition, etc.)

Zero-Day Vulnerability For Sale

- Unauthenticated access exploit
- Allows full persistence on the gateway
- Enables real-time data extraction from the remaining 24+ Egyptian universities not in the public preview

Screenshots

[ ![Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/823768598273648972365897263598723589761.png) 01 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/823768598273648972365897263598723589761.png) [ ![Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/823768598273648972365897263598723589762.png) 02 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/823768598273648972365897263598723589762.png) [ ![Screenshot 3](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/823768598273648972365897263598723589763.png) 03 ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/05/823768598273648972365897263598723589763.png) 

Want the non-blurred screenshots? Subscribe and check out the threat feed section. [darkwebinformer.com/pricing](https://darkwebinformer.com/pricing/)