Congo : un pirate revendique 110 000 données e-Solde
A hacker is claiming to possess 110,000 records linked to e-Solde, a Congolese government portal for public servants, containing sensitive data like identities, contacts, and salary information. The hacker, known for previous data sales, has previously claimed to have compromised the chassez discount website and boasts a history of selling databases from various countries and sectors. This represents a significant risk due to the potential for identity theft, phishing, and social engineering attacks against Congolese public servants, and highlights a broader trend of data brokers targeting government systems worldwide.
A hacker is claiming to hold 110,000 records associated with e-Solde, a Congolese government portal used by public servants. These records include sensitive information such as identities, contact details, and salary data. The hacker, who has previously announced data sales, made this claim on a dark web forum, offering to sell the data for a private transaction. This follows a previous announcement attributed to the same account regarding two million records from the French website chassez discount, where he claimed to have ‘original files and images’ for verification.
E-Solde is a key component of the Congolese government’s information system reform, designed to provide public servants with online access to documents related to their salaries and benefits. It succeeds the e-bulletin system and aims to streamline processes such as verifying new recruits, tracking deductions, and providing access to related documents, including those concerning payments and banking arrangements.
The sensitivity of a compromise targeting e-Solde is high, as a combined database of identity, contact, administrative status, and salary information could facilitate attempts at impersonation, targeted phishing, and social engineering attacks against public servants. The hacker’s activity extends beyond just e-Solde and chassez discount, with claims of fifty other malicious operations, including the sale and distribution of databases, client files, professional contacts, and compromised access.
Targets span multiple continents and diverse sectors, including the Philippines (universitykart.com), Bulgaria (maniakino.com and tickets.ndk.bg), India (shreetransport.co), Spain (evolveyourenglish.com), Argentina (toque.com.ar), and Brazil (clubesubaru.com.br and epstopik.lk). The hacker’s activity has been particularly active since February 2025, with a surge in activity between April and August 2026. These examples illustrate a broader trend of data brokers operating as intermediaries in the illicit trade of stolen data, targeting government systems worldwide.
