Le « deface » revient dans le commerce des données volées
A hacker is using a tactic called ‘barbouillage’ – defacing websites – as a demonstration of their ability to compromise a database and sell the stolen data. In this case, a hacker on a pirate forum is offering a massive database of the Fédération Française de Spéléologie (French Speleological Federation), containing 93,493 members’ data, including financial information and source code. The hacker is not just selling data; they are showcasing their access and control over the organization's infrastructure. This tactic highlights a growing trend of cybercriminals using visible attacks to bolster the credibility of their data sales and demonstrate deeper intrusion capabilities.
A hacker is using a tactic called ‘barbouillage’ – defacing websites – as a demonstration of their ability to compromise a database and sell the stolen data. In this case, a hacker on a pirate forum is offering a massive database of the Fédération Française de Spéléologie (French Speleological Federation), containing 93,493 members’ data, including financial information and source code. The hacker is not just selling data; they are showcasing their access and control over the organization's infrastructure.
This ‘barbouillage’ – a deliberate modification of a website’s content – is a deliberate attempt to prove their intrusion capabilities. The hacker claims to have compromised seven subdomains linked to the Federation’s ecosystem, offering access to services like payment, billing, information, download, and media. The hacker is offering a ‘Full RCE’ – Remote Code Execution – meaning they could execute commands and modify the sites accessible.
The hacker’s message follows a sales-like structure, detailing the target, listing data volumes, describing compromised content, and presenting evidence to convince potential buyers. They claim to possess the names, postal addresses, email addresses, phone numbers, dates of birth, and licenses of 93,493 individuals, along with 371 IBANs, payment details, insurance information, and club accounts. They also claim to have a table containing root users and 28 other users.
Despite the impressive claims, it’s important to note that simply ‘barbouillage’ a website doesn’t guarantee access to sensitive data. The hacker is using this visible attack to build trust and demonstrate the depth of their intrusion. This tactic reflects a convergence between two cybercriminal cultures: the vandalism of visible attacks and the clandestine commerce of stolen data.
From a threat intelligence perspective, this resurgence of ‘barbouillage’ underscores that a modified page can be both an observable incident and a signal accompanying a monetization operation. The tactic is evolving from a simple provocation to a tool for establishing reputation and supporting the value of a claimed intrusion. The hacker is essentially offering a ‘Shop Leak’ – a digital storefront for stolen data – to potential buyers.
