Data stolen in February 2026 from IFAPME has been republished on a dark web forum, and this time anyone can download it for free. IFAPME (Institut wallon de formation en alternance et des indépendants et petites et moyennes entreprises) is Wallonia's public body for apprenticeships, self-employed workers and SME training. Breach tracker FrenchBreaches spotted the free release on October 4, 2026. Every source cites the same figures: more than 700,000 people and more than 85,000 IBANs. Those figures come from the threat actor's own claims. None of the sources shows IFAPME confirming them independently. According to RTBF, IFAPME's management says the intrusion started when two users handed over their login credentials after a phishing email. All eight sources available for this brief are press or tracker reports. No regulator filing, CERT advisory, or direct statement from IFAPME was available. The organisation's comments below are as reported by RTBF and Cybernews.
What Happened
- February 2026: initial breach. IFAPME's interim administrator general, Sandrine Villette, told RTBF that "unauthorised access was detected on an IFAPME IT application" in February. Around the same time, a threat actor claimed the theft on a cybercrime forum and offered the database for sale. FrenchBreaches, Cybernews and All About Security all say early access to the data required payment.
- October 4, 2026: free republication. FrenchBreaches reports that the same dataset reappeared on a dark web forum with no fee. Belgian outlets RTBF, RTL and ITdaily, plus the German outlet All About Security, picked up the story from that report on October 5 and 6.
- IFAPME's position. According to Cybernews and All About Security, IFAPME says this is the February breach resurfacing, not a new incident. RTBF reports that IFAPME has revoked the compromised users' access, isolated the affected database, notified the Centre for Cybersecurity Belgium (CCB) and the Data Protection Authority, and emailed everyone potentially affected. RTBF also says the attacker did not try to extort IFAPME.
- Accounts differ on the current status. One RTBF article describes the attacker as trying to resell the data in early October. A companion RTBF piece and every other source describe a free release. Both are possible: the dataset may have been offered for sale in some places and given away in others. The weight of reporting points to free distribution now.
- Threat actor identity is unconfirmed. Brinztech is the only source that names the actor, using the handle "Mica". No other source repeats that attribution, so treat it as unverified.
What Was Taken
According to the threat actor's claims, as relayed by FrenchBreaches, RTBF, Cybernews and All About Security, the dataset contains:
- First and last names
- Postal addresses and email addresses
- Telephone numbers
- Dates of birth
- Belgian national register numbers
- IBANs and other banking information (more than 85,000 IBANs)
- Administrative data linked to beneficiaries
Volume: Every source uses "more than 700,000 people". RTBF headlines describe them as "Wallons" (Walloon residents). Brinztech's write-up refers more vaguely to "thousands of students, instructional staff, and associated entrepreneurs". Brinztech also calls the IBANs "active". No other source makes that claim and it has not been independently verified. No source reports an independent count of the leaked files, and IFAPME has not publicly confirmed the total.
Sensitivity: FrenchBreaches singles out the national register number as the most worrying field. It is a lifelong identifier and cannot be rotated like a password or card number. FrenchBreaches also notes that an IBAN alone does not let anyone make payments from an account. Combined with a verified identity, though, it makes fraud and social engineering far more convincing.
Why It Matters
- Making the data free widens the threat. A paid dump reaches a small number of motivated buyers. A free one reaches every low-skill scammer on the forum. FrenchBreaches, RTBF and Cybernews all say the free release significantly raises the exposure risk.
- This is a complete kit for impersonation. With name, address, date of birth, national ID number and IBAN together, a scammer can pass as a bank adviser, a government agency or IFAPME itself. RTL quotes CCB director Miguel De Bruycker advising people not to trust a caller just because they know accurate personal details: "C'est mieux de raccrocher" ("It's better to hang up"). He also said the threat is changing fast, especially with AI-assisted attacks.
- The victims skew toward small businesses. IFAPME serves apprentices, self-employed workers and entrepreneurs. For many of them, the personal IBAN may also be their business account, so invoice fraud and fake-supplier payment requests are a realistic follow-on risk.
- Public training bodies are soft targets. As Brinztech notes, vocational and continuing-education networks hold large, interlinked records on rotating groups of learners, often in applications without enterprise-grade identity controls.
- There is no sign yet of actual fraud. FrenchBreaches cautions that the leak does not prove any fraud has happened. The risk comes from what kind of data was exposed.
The Attack Technique
According to IFAPME's management, as quoted by RTBF, the initial access was credential phishing. "Two users unfortunately transferred their authentication data following an email phishing attack." The attacker then used those credentials to reach an IFAPME application and the database behind it. IFAPME has not said what the phishing lure looked like, whether multi-factor authentication was in place, or how long the attacker had access before detection.
The pattern is familiar: harvest valid credentials, log in to a web-facing application, then bulk-export the backing database. Two compromised accounts were apparently enough to pull hundreds of thousands of records. That suggests those accounts had broad read access and that nothing caught or limited an unusually large export in time to stop it.
What Organizations Should Do
- Require phishing-resistant MFA on every application that touches personal data. That means FIDO2 keys or passkeys, especially for admin and back-office accounts. Stolen passwords alone should never be enough to get into a database of 700,000 records.
- Apply least privilege and limit bulk access. Ordinary user accounts should not be able to query or export an entire beneficiary database. Add row limits, rate limits and approval steps for bulk exports.
- Watch for unusual data access. Alert on large query volumes, exports at odd hours, and logins from new devices or locations to business applications, not just email.
- Minimise and segregate sensitive fields. Store national register numbers and IBANs separately from contact data, encrypt them at the field level, and delete them when they are no longer needed.
- Prepare people for follow-on fraud. Warn customers, learners and staff that callers or emails quoting accurate personal data are not proof of legitimacy. Publish an official verification channel. Banks should flag affected IBANs for extra checks on mandate changes and payment-redirection requests.
- Monitor dark web forums after a breach. As this case shows, a dataset that first appears for sale can later be given away for free. Keep tracking leaked data, and send a fresh notification when its availability changes.
Sources: IFAPME data leak exposes 700K people for free on dark web Cybernews | Fuite de données à l'IFAPME : plus de 700 000 personnes ... | L’IFAPME victime d’hameçonnage, au moins 700.000 données consultées... | Piratage à l'IFAPME : les données personnelles de 700.000 Wallons v... | Fuite de données IFAPME : 700.000 Belges exposés | Gegevens van 700.000 mensen gratis op het dark web na hack bij IFAP... | IFAPME-Datenleck: Gestohlene Daten von über 700.000 Personen kosten... | Walloon Public Training Institute IFAPME Suffers Major Data Breach...