Cyber & AI intelligence
Wasteland.
Briefs indexed3022
Issues31
Published Mondays07:30 CT
▣ Breach IFAPME-DATA-LEAK 2026-10-06

IFAPME: Phishing-Fueled Breach Data of 700,000 People Released Free on Dark Web

"Data stolen in February 2026 from IFAPME has been republished on a dark web forum, and this time anyone can download it for free. IFAPME (Institut wallon de formation en alternance et des indépendants et petites et…"

Data stolen in February 2026 from IFAPME has been republished on a dark web forum, and this time anyone can download it for free. IFAPME (Institut wallon de formation en alternance et des indépendants et petites et moyennes entreprises) is Wallonia's public body for apprenticeships, self-employed workers and SME training. Breach tracker FrenchBreaches spotted the free release on October 4, 2026. Every source cites the same figures: more than 700,000 people and more than 85,000 IBANs. Those figures come from the threat actor's own claims. None of the sources shows IFAPME confirming them independently. According to RTBF, IFAPME's management says the intrusion started when two users handed over their login credentials after a phishing email. All eight sources available for this brief are press or tracker reports. No regulator filing, CERT advisory, or direct statement from IFAPME was available. The organisation's comments below are as reported by RTBF and Cybernews.

What Happened

What Was Taken

According to the threat actor's claims, as relayed by FrenchBreaches, RTBF, Cybernews and All About Security, the dataset contains:

Volume: Every source uses "more than 700,000 people". RTBF headlines describe them as "Wallons" (Walloon residents). Brinztech's write-up refers more vaguely to "thousands of students, instructional staff, and associated entrepreneurs". Brinztech also calls the IBANs "active". No other source makes that claim and it has not been independently verified. No source reports an independent count of the leaked files, and IFAPME has not publicly confirmed the total.

Sensitivity: FrenchBreaches singles out the national register number as the most worrying field. It is a lifelong identifier and cannot be rotated like a password or card number. FrenchBreaches also notes that an IBAN alone does not let anyone make payments from an account. Combined with a verified identity, though, it makes fraud and social engineering far more convincing.

Why It Matters

The Attack Technique

According to IFAPME's management, as quoted by RTBF, the initial access was credential phishing. "Two users unfortunately transferred their authentication data following an email phishing attack." The attacker then used those credentials to reach an IFAPME application and the database behind it. IFAPME has not said what the phishing lure looked like, whether multi-factor authentication was in place, or how long the attacker had access before detection.

The pattern is familiar: harvest valid credentials, log in to a web-facing application, then bulk-export the backing database. Two compromised accounts were apparently enough to pull hundreds of thousands of records. That suggests those accounts had broad read access and that nothing caught or limited an unusually large export in time to stop it.

What Organizations Should Do

  1. Require phishing-resistant MFA on every application that touches personal data. That means FIDO2 keys or passkeys, especially for admin and back-office accounts. Stolen passwords alone should never be enough to get into a database of 700,000 records.
  2. Apply least privilege and limit bulk access. Ordinary user accounts should not be able to query or export an entire beneficiary database. Add row limits, rate limits and approval steps for bulk exports.
  3. Watch for unusual data access. Alert on large query volumes, exports at odd hours, and logins from new devices or locations to business applications, not just email.
  4. Minimise and segregate sensitive fields. Store national register numbers and IBANs separately from contact data, encrypt them at the field level, and delete them when they are no longer needed.
  5. Prepare people for follow-on fraud. Warn customers, learners and staff that callers or emails quoting accurate personal data are not proof of legitimacy. Publish an official verification channel. Banks should flag affected IBANs for extra checks on mandate changes and payment-redirection requests.
  6. Monitor dark web forums after a breach. As this case shows, a dataset that first appears for sale can later be given away for free. Keep tracking leaked data, and send a fresh notification when its availability changes.

Sources: IFAPME data leak exposes 700K people for free on dark web Cybernews | Fuite de données à l'IFAPME : plus de 700 000 personnes ... | L’IFAPME victime d’hameçonnage, au moins 700.000 données consultées... | Piratage à l'IFAPME : les données personnelles de 700.000 Wallons v... | Fuite de données IFAPME : 700.000 Belges exposés | Gegevens van 700.000 mensen gratis op het dark web na hack bij IFAP... | IFAPME-Datenleck: Gestohlene Daten von über 700.000 Personen kosten... | Walloon Public Training Institute IFAPME Suffers Major Data Breach...