AI Hack : une fuite chez Darsa AI ?
A French security news outlet, ZATAZ, has reported a potential data breach at Darsa AI, a company specializing in AI security solutions. A hacker claims to have stolen 90-100GB of data, including source code, databases, emails, internal documents, and even videos from workplaces. The breach appears to have been achieved through a combination of reused passwords and internal access, potentially facilitated by a misconfigured Microsoft account lacking two-factor authentication. The incident highlights a broader campaign targeting AI-related companies, with Darsa AI standing out due to the detailed information and the inclusion of AI-related source code.
A French security news outlet, ZATAZ, has reported a potential data breach at Darsa AI, a company specializing in AI security solutions. A hacker claims to have stolen 90-100GB of data, including source code, databases, emails, internal documents, and even videos from workplaces. The breach appears to have been achieved through a combination of reused passwords and internal access, potentially facilitated by a misconfigured Microsoft account lacking two-factor authentication.
According to the report, the hacker claims to have gained access to a Microsoft account used by support staff, allowing them to access Outlook, Teams, and OneDrive – all without two-factor authentication. This access enabled them to consult internal documents, professional exchanges, sensitive technical information, and files containing employee photographs and recordings from work environments.
Furthermore, the hacker revealed a PostgreSQL backup of 300MB, which, when converted, generated 112 CSV files containing names, email addresses, phone numbers, Argon2-protected passwords, and authentication tokens. The lack of effective encryption for these passwords renders them useless to the attackers. The hacker also cited a publicly exposed Django interface with debugging enabled, leading to the disclosure of internal information and administrative addresses, and a confidential file path.
The incident is part of a wider campaign attributed to the same hacker, with publications dating back to mid-July 2026 detailing the exfiltration of multiple databases linked to AI-related companies. Suitable AI and KomikoAI are specifically mentioned in the report. Other targets include Inseyab, BridgeStorage, Navoy, Määrdekeskus, Deliware, Zoomaru and Mupol.
While the presence of these names in publications doesn't definitively prove a successful intrusion, the rapid succession of publications and the detailed information provided in the Darsa AI case suggest a coordinated effort. The report suggests a possible motivation – a request from competitors – though this remains unconfirmed. The sheer volume of data and the inclusion of AI-related source code make this incident particularly concerning.
