news.mlab.sh
Back to the feed
threat-intel

Une fuite d’accès IT français réapparaît sur un forum pirate

High
Summary

A previously reported threat intelligence alert regarding a Russian hacker offering access to over 200 French IT companies’ infrastructure has resurfaced on a Russian cybercrime forum. The hacker claims to possess detailed technical information about clients of a French IT provider, including Microsoft 365, Google Workspace, firewall, switch and server details, as well as IP addresses and credentials. While the seller claims to have a large amount of data, the validity of the claims and the potential impact remain uncertain, highlighting the ongoing risk of disinformation and potential exploitation by malicious actors. The alert’s reappearance underscores the value of IT service providers as entry points for cyberattacks and the importance of monitoring threat actors and recurring offers.

A previously reported threat intelligence alert from ZATAZ regarding a Russian hacker offering access to over 200 French IT companies’ infrastructure has resurfaced on a Russian cybercrime forum. The hacker claims to possess detailed technical information about clients of a French IT provider, including Microsoft 365, Google Workspace, firewall, switch and server details, as well as IP addresses and credentials. The announcement, initially flagged months ago, has been re-posted in late August 2026, with the seller now requesting interested parties to propose a price, suggesting a potential sale. The hacker initially stated that the data could be used for phishing and ransomware attacks.

According to the post, the hacker’s account, which only contains 28 messages and two reactions, appeared on the Russian forum in March 2024. The hacker claims to have recovered data encompassing ‘all the information’ related to his clients’ infrastructure. He lists several technical environments, including O365 and Gsuite.

While the seller claims to have a large amount of data, the validity of the claims remains uncertain. The hacker does not provide technical evidence, and crucial details such as password freshness, account privileges, and the presence of multi-factor authentication are not specified. The hacker also mentioned that the data could be used for phishing and ransomware attacks.

Despite the lack of concrete evidence, the hacker’s post suggests a significant risk. Access obtained through an IT provider could provide visibility into multiple client environments. The hacker emphasizes the ‘enormous possibilities’ offered by the data. The hacker’s account has since been removed from the forum, but the sale was validated.

This incident highlights a common threat intelligence challenge: monitoring threat actors and recurring offers to identify potential attacks before they materialize. The Service de veille et d’Investigation de ZATAZ’s mission is to track threat actors and recurring offers to identify potential attacks before they materialize.

Read the full article at ZATAZ