news.mlab.sh
Back to the feed
threat-intel

Fuite revendiquée au Rassemblement national ?

High
Summary

A pirate claims to have compromised the website of the French far-right party, Rassemblement National (formerly Front National), and is offering a recent SQL dump for sale. The dump, allegedly containing 95 tables, includes details about WordPress installations, Gravity Forms extensions, and technical information like MariaDB versions and custom prefixes. While the pirate provides technical details, there’s no independent verification of the breach or the existence of the data, and the Rassemblement National has confirmed they were hacked. The article explores the pirate's history, including previous data sales targeting other French organizations, and discusses the motivations behind using multiple pseudonyms. The claim is currently being treated as a sales pitch rather than a confirmed data breach.

A pirate claims to have compromised the website of the Rassemblement National, a French far-right political party, and is offering a recent SQL dump for sale. The claim, made on a hacker forum on July 20, 2026, alleges that the pirate has successfully accessed and extracted a database from the party’s website, rassemblementnational.fr. The dump is described as containing 95 tables and includes details about a WordPress installation running on MariaDB 11.8.8 under Debian, a custom table prefix, and associated credentials. The pirate also mentions a Gravity Forms extension, used for creating and managing forms, with additional tables related to it.

However, despite the technical details provided, there’s no independent verification of the breach. The Rassemblement National has confirmed they were hacked, but deny that any personal data was exfiltrated. The article highlights the pirate’s history, revealing that he has previously offered data sales targeting other French organizations, including EFAB, KeepCool, Mille et Une Listes, and more. He uses multiple pseudonyms to avoid identification and potentially circumvent bans on forums.

The pirate’s activity is characterized by a rapid succession of publications, with announcements for ESGI and PPA Business School appearing on July 14th and 15th, respectively. The article details the methods used by pirates to establish multiple identities, including using different pseudonyms for various activities – selling data, claiming intrusions, and negotiating. It emphasizes that the pirate’s actions are primarily a sales pitch, not a confirmed data breach, and that the value of the dump hinges on the authenticity of the data and the potential for exploitation. A formal complaint is expected to be filed by the Rassemblement National.

Currently, the claim is being treated as a sales pitch, not a confirmed data breach. The article stresses that the pirate’s actions do not demonstrate a sustained access to the server, nor do they reveal any exploitable personal data. The focus is now on verifying the existence of the data and identifying the infrastructure used in the alleged breach.

Read the full article at ZATAZ