Threat reportData BreachTL-2026-2930

IQUALIF French Residential Data Leak, IUT Paris Seine Breach, 19M SMTP Credential Dump and Apache Struts CVE-2017-5638 Access Sale

highACTIVE

IQUALIF French Residential Data Leak, IUT Paris Seine (TL-2026-2930), also tracked as IQUALIF leak, is a high-severity data breach, first published 2026-10-05. It has no confirmed attribution, affects Apache Software Foundation Apache Struts 2, references 1 CVE (CVE-2017-5638), maps to 8 MITRE ATT&CK techniques (T1021.001, T1059, T1078), and is covered by 9 detection rules and 9 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
1Referenced vulnerabilities
Techniques
8MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
9Indicators of compromise

Key facts for TL-2026-2930

Threat ID
TL-2026-2930
Also known as
IQUALIF leak, 19M SMTPs MIX, S2-045
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
consumer, education, manufacturing, telecoms
Target regions
france, united states of america, canada
Detection rules
9
Indicators of compromise
9

Malware and tooling in IQUALIF French Residential Data Leak, IUT Paris Seine

Malware and tooling: French residential dataset (10M+ records), IQUALIF

How IQUALIF French Residential Data Leak, IUT Paris Seine works

SOCRadar's Dark Web Team reported several alleged underground posts: a 10M+ record French residential database claimed to be extracted with the IQUALIF tool, an alleged breach of IUT Paris Seine, an alleged 19M SMTP credential dump, an alleged VPN/RDP initial-access auction for a U.S. manufacturer, and a sale of server access reportedly obtained via Apache Struts CVE-2017-5638. All claims are unverified threat-actor assertions.

On 2026-10-05 SOCRadar's Dark Web Team (via the SOCRadar blog and a malware.news mirror) reported a cluster of alleged underground forum posts. None of the claims has been independently verified, and the source material names no threat actors or forums.

1) IQUALIF French residential leak: a post claims a database of more than 10 million French residential records, allegedly extracted using the IQUALIF tool and offered for download. Reported fields include names, postal codes, cities, addresses, gender, phone/mobile numbers, fax, housing type, average age, ethnicity and marketing fields. SOCRadar assesses the dataset could support targeted phishing, smishing, fraud and large-scale social engineering.

2) IUT Paris Seine breach: an alleged compromise of IUT Paris Seine (Universite Paris Cite), with a claimed 6.8GB of data and references to 30 million logs. Exposed material is described as server information, access credentials and logs, creating risk of credential abuse, follow-on intrusion and exposure of student or institutional data.

3) U.S. manufacturing initial-access auction: access to a U.S. manufacturing company (~$16M revenue) is offered via VPN and RDP, with 138 Active Directory hosts, domain user rights and Windows Defender present. Pricing is a $1,800 starting bid, $100 increments and a $2,200 buy-it-now. SOCRadar notes potential misuse for ransomware, data theft and privilege escalation.

4) 19M SMTP credential dump: a listing titled '19M SMTPs MIX' offering 19 million SMTP credentials, usable for phishing, spam, malware delivery, business email compromise and domain-reputation abuse.

5) Apache Struts CVE-2017-5638 access sale: access to four compromised servers (one reportedly linked to a Canadian university) is offered, with the seller claiming remote command execution, administrative control and persistence. CVE-2017-5638 (Struts S2-045) is a Jakarta Multipart parser flaw in which a crafted Content-Type header (containing an OGNL payload such as '#cmd=') yields remote code execution; CVSS v3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), CWE-755. It affects Struts 2.3.5-2.3.31 and 2.5-2.5.10, fixed in 2.3.32 and 2.5.10.1, and is in the CISA KEV catalog (added 2021-11-03).

Caveats: the SOCRadar page returned HTTP 403 to direct fetch, so details come from the malware.news mirror and search summaries. Publication/post dates of the individual forum posts, actor handles, forums and IOC network indicators are not available. The threat-level CVSS is left null because the 9.8 score belongs to the CVE only; severity HIGH is analyst-assigned from claimed scale and the exploitation-linked access sale.

MITRE ATT&CK techniques used in TL-2026-2930

Lateral Movement

T1021.001 Remote Desktop Protocol

Execution

T1059 Command and Scripting Interpreter

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application

Resource Development

T1586.002 Email Accounts; T1650 Acquire Access

Reconnaissance

T1589.001 Credentials

Affected products and versions in IQUALIF French Residential Data Leak, IUT Paris Seine

  • Apache Software Foundation — Apache Struts 2
    Vulnerable versions: 2.3.5 - 2.3.31; 2.5 - 2.5.10
    Fixed in: 2.3.32; 2.5.10.1
  • Universite Paris Cite — IUT Paris Seine (alleged breach victim)

Remediation for IQUALIF French Residential Data Leak, IUT Paris Seine

Patches

  • Upgrade Apache Struts to 2.3.32 or 2.5.10.1 or later (S2-045)

Immediate actions

  • Inventory and patch any Apache Struts 2 instance below 2.3.32 / 2.5.10.1; hunt for Content-Type headers containing OGNL expressions such as '#cmd='
  • Review externally exposed VPN and RDP gateways for anomalous logons, enforce MFA and rotate domain credentials
  • Force credential resets and review mail-relay logs for any SMTP accounts that may appear in the claimed dump
  • For IUT Paris Seine / Universite Paris Cite: rotate server and service credentials and review access logs for the claimed exposure

Workarounds

  • Deploy a Servlet filter that validates and rejects suspicious Content-Type headers
  • For Struts 2.5.8-2.5.10, remove the File Upload Interceptor from the default stack

Longer-term hardening

  • Monitor dark-web sources for organization domains, credentials and access listings
  • Maintain software inventory/SBOM to find legacy Struts deployments
  • Alert on outbound SMTP volume anomalies and enforce SPF/DKIM/DMARC
  • Warn French residents/customers about phishing and smishing built on leaked personal data

CVEs associated with IQUALIF French Residential Data Leak, IUT Paris Seine

CVE-2017-5638

Weaknesses (CWE) in IQUALIF French Residential Data Leak, IUT Paris Seine

CWE-755

Timeline of IQUALIF French Residential Data Leak, IUT Paris Seine

  • NVD records CVE-2017-5638 as actively exploited in the wild as of March 2017, with public Exploit-DB and Metasploit modules.
  • Apache publishes Struts S2-045 (CVE-2017-5638): Jakarta Multipart parser RCE via crafted Content-Type header; fixed in Struts 2.3.32 and 2.5.10.1.
  • CISA adds CVE-2017-5638 to the Known Exploited Vulnerabilities catalog (remediation due 2022-05-03).
  • CISA KEV remediation due date for CVE-2017-5638 for federal agencies.
  • SOCRadar also reports a U.S. manufacturer VPN/RDP access auction ($1,800 start, $2,200 buy-it-now, 138 AD hosts) and a sale of four servers allegedly compromised via CVE-2017-5638, one linked to a Canadian university.
  • SOCRadar Dark Web Team reports alleged posts: IQUALIF-extracted 10M+ French residential database, IUT Paris Seine breach (6.8GB, 30M logs referenced), and a '19M SMTPs MIX' SMTP credential dump. Individual post dates are not stated.

Sources cited for IQUALIF French Residential Data Leak, IUT Paris Seine

Detection coverage for TL-2026-2930

As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2930 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
9 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats