Togo : une base de contrôle de police exposée ?
A data breach involving the Togolese police control has been reported, with a hacker claiming to have obtained approximately 148,882 administrative records and 90,118 identity cards. The incident raises concerns about potential misuse of the data for fraud, identity theft, and targeted operations, highlighting the value of aggregated data for threat actors. While the method of access remains unknown, the sheer volume of sensitive information involved underscores the risk.
A data breach affecting the Togolese police control has been reported on August 27, 2026, on a hacking forum. A user, identified as a close associate of the ZeroBytes hacking group, claims to have gained access to a database containing approximately 148,882 administrative records and 90,118 identity cards, along with national numbers. The incident is linked to a user account with a ‘GOD User’ rank and a reputation score of 30, suggesting an attempt to establish credibility and proximity to forum administrators.
The hacker presented three sets of data: 90,118 identity cards, a collection of ‘national numbers’ linked to a text publishing service, and a database of 148,882 records. The user’s account was created recently, with only 13 messages and three discussions at the time of publication.
Evidence presented includes links to screenshots hosted on an external service, which are intended to demonstrate access to the stolen data. The timing of the announcement on a hacking forum is significant, as it represents a claim originating from the alleged attacker. The presence of sample data and visual evidence increases the perceived credibility of the announcement, though it does not independently verify each data point. ZATAZ has confirmed the reality of the reported breach.
The large volume of data – 148,882 administrative records and 90,118 identity cards – is particularly concerning. The combination of these records, along with national numbers, creates a valuable dataset for threat actors specializing in fraud, social engineering, and targeted intelligence operations. Individual records may have limited value, but the aggregated data allows for sophisticated searches, cross-referencing, and profile selection for malicious purposes. The method used to obtain the data remains unclear, preventing attribution to a specific vulnerability or attack vector.
