L’Égypte ciblée par une vague de fuites massives
A large-scale data leak targeting Egyptian organizations is being reported, with claims of millions of records being sold or offered for sale on underground forums. The leaks encompass data from Amenli (an Egyptian insurance brokerage), six universities, and the Egyptian Football Federation, including identities, passwords, financial information, academic records, and passport details. The incident highlights a growing trend of sector-specific data breaches being correlated to create a more comprehensive and exploitable intelligence picture.
A significant data leak targeting Egyptian organizations is currently under report. Multiple sources claim that a number of cybercriminals have been selling or offering access to databases belonging to Egyptian entities, including Amenli, a platform for Egyptian insurance brokerage, six public universities, and the Egyptian Football Federation. The initial reports emerged on underground forums starting in July 2026 and have continued through August 2026.
Amenli’s database, reportedly containing 13 million records, includes names, phone numbers, email addresses, national identification numbers, login attempts, IP addresses, internal employee conversations, and payment information. The six universities – Benha, Helwan, Cairo, Kafr El Sheikh, South Valley, and Sadat City – are facing a massive breach, with claims of 7,761,608 records being exposed. These records include full names, email addresses, passwords stored in plain text, national identification numbers, birthdates, religion, gender, phone numbers, professions, employers, and vaccination status.
Furthermore, the Egyptian Football Federation’s database, encompassing 350,000 players, is also under threat. The data includes photographs, identification documents, military forms, contracts, diplomas, and birth certificates. The fields published cover complete identity, place and date of birth, nationality, national identification number, passport, origin and destination teams, transfer dates, and administrative references.
The incident underscores a broader trend of sector-specific data breaches being combined to create a more valuable intelligence picture. The data, when analyzed together, can be used to build detailed profiles of individuals and organizations, facilitating identity theft, targeted phishing attacks, and fraudulent access attempts. The initial reports indicated a 48-hour period for discussion before the data was disseminated. The incident highlights the increasing sophistication of cybercriminals and the growing risk of data exploitation in Egypt.
