Threat reportData BreachTL-2026-2930
IQUALIF French Residential Data Leak, IUT Paris Seine Breach, 19M SMTP Credential Dump and Apache Struts CVE-2017-5638 Access Sale
IQUALIF French Residential Data Leak, IUT Paris Seine (TL-2026-2930), also tracked as IQUALIF leak, is a high-severity data breach, first published 2026-10-05. It has no confirmed attribution, affects Apache Software Foundation Apache Struts 2, references 1 CVE (CVE-2017-5638), maps to 8 MITRE ATT&CK techniques (T1021.001, T1059, T1078), and is covered by 9 detection rules and 9 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 8MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 9Indicators of compromise
Key facts for TL-2026-2930
- Threat ID
- TL-2026-2930
- Also known as
- IQUALIF leak, 19M SMTPs MIX, S2-045
- Severity
- HIGH
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- consumer, education, manufacturing, telecoms
- Target regions
- france, united states of america, canada
- Detection rules
- 9
- Indicators of compromise
- 9
Malware and tooling in IQUALIF French Residential Data Leak, IUT Paris Seine
Malware and tooling: French residential dataset (10M+ records), IQUALIF
How IQUALIF French Residential Data Leak, IUT Paris Seine works
SOCRadar's Dark Web Team reported several alleged underground posts: a 10M+ record French residential database claimed to be extracted with the IQUALIF tool, an alleged breach of IUT Paris Seine, an alleged 19M SMTP credential dump, an alleged VPN/RDP initial-access auction for a U.S. manufacturer, and a sale of server access reportedly obtained via Apache Struts CVE-2017-5638. All claims are unverified threat-actor assertions.
On 2026-10-05 SOCRadar's Dark Web Team (via the SOCRadar blog and a malware.news mirror) reported a cluster of alleged underground forum posts. None of the claims has been independently verified, and the source material names no threat actors or forums.
1) IQUALIF French residential leak: a post claims a database of more than 10 million French residential records, allegedly extracted using the IQUALIF tool and offered for download. Reported fields include names, postal codes, cities, addresses, gender, phone/mobile numbers, fax, housing type, average age, ethnicity and marketing fields. SOCRadar assesses the dataset could support targeted phishing, smishing, fraud and large-scale social engineering.
2) IUT Paris Seine breach: an alleged compromise of IUT Paris Seine (Universite Paris Cite), with a claimed 6.8GB of data and references to 30 million logs. Exposed material is described as server information, access credentials and logs, creating risk of credential abuse, follow-on intrusion and exposure of student or institutional data.
3) U.S. manufacturing initial-access auction: access to a U.S. manufacturing company (~$16M revenue) is offered via VPN and RDP, with 138 Active Directory hosts, domain user rights and Windows Defender present. Pricing is a $1,800 starting bid, $100 increments and a $2,200 buy-it-now. SOCRadar notes potential misuse for ransomware, data theft and privilege escalation.
4) 19M SMTP credential dump: a listing titled '19M SMTPs MIX' offering 19 million SMTP credentials, usable for phishing, spam, malware delivery, business email compromise and domain-reputation abuse.
5) Apache Struts CVE-2017-5638 access sale: access to four compromised servers (one reportedly linked to a Canadian university) is offered, with the seller claiming remote command execution, administrative control and persistence. CVE-2017-5638 (Struts S2-045) is a Jakarta Multipart parser flaw in which a crafted Content-Type header (containing an OGNL payload such as '#cmd=') yields remote code execution; CVSS v3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), CWE-755. It affects Struts 2.3.5-2.3.31 and 2.5-2.5.10, fixed in 2.3.32 and 2.5.10.1, and is in the CISA KEV catalog (added 2021-11-03).
Caveats: the SOCRadar page returned HTTP 403 to direct fetch, so details come from the malware.news mirror and search summaries. Publication/post dates of the individual forum posts, actor handles, forums and IOC network indicators are not available. The threat-level CVSS is left null because the 9.8 score belongs to the CVE only; severity HIGH is analyst-assigned from claimed scale and the exploitation-linked access sale.
MITRE ATT&CK techniques used in TL-2026-2930
Lateral Movement
T1021.001 Remote Desktop Protocol
Execution
T1059 Command and Scripting Interpreter
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
Resource Development
T1586.002 Email Accounts; T1650 Acquire Access
Reconnaissance
Affected products and versions in IQUALIF French Residential Data Leak, IUT Paris Seine
- Apache Software Foundation — Apache Struts 2
Vulnerable versions: 2.3.5 - 2.3.31; 2.5 - 2.5.10
Fixed in: 2.3.32; 2.5.10.1 - Universite Paris Cite — IUT Paris Seine (alleged breach victim)
Remediation for IQUALIF French Residential Data Leak, IUT Paris Seine
Patches
- Upgrade Apache Struts to 2.3.32 or 2.5.10.1 or later (S2-045)
Immediate actions
- Inventory and patch any Apache Struts 2 instance below 2.3.32 / 2.5.10.1; hunt for Content-Type headers containing OGNL expressions such as '#cmd='
- Review externally exposed VPN and RDP gateways for anomalous logons, enforce MFA and rotate domain credentials
- Force credential resets and review mail-relay logs for any SMTP accounts that may appear in the claimed dump
- For IUT Paris Seine / Universite Paris Cite: rotate server and service credentials and review access logs for the claimed exposure
Workarounds
- Deploy a Servlet filter that validates and rejects suspicious Content-Type headers
- For Struts 2.5.8-2.5.10, remove the File Upload Interceptor from the default stack
Longer-term hardening
- Monitor dark-web sources for organization domains, credentials and access listings
- Maintain software inventory/SBOM to find legacy Struts deployments
- Alert on outbound SMTP volume anomalies and enforce SPF/DKIM/DMARC
- Warn French residents/customers about phishing and smishing built on leaked personal data
CVEs associated with IQUALIF French Residential Data Leak, IUT Paris Seine
Weaknesses (CWE) in IQUALIF French Residential Data Leak, IUT Paris Seine
Timeline of IQUALIF French Residential Data Leak, IUT Paris Seine
- NVD records CVE-2017-5638 as actively exploited in the wild as of March 2017, with public Exploit-DB and Metasploit modules.
- Apache publishes Struts S2-045 (CVE-2017-5638): Jakarta Multipart parser RCE via crafted Content-Type header; fixed in Struts 2.3.32 and 2.5.10.1.
- CISA adds CVE-2017-5638 to the Known Exploited Vulnerabilities catalog (remediation due 2022-05-03).
- CISA KEV remediation due date for CVE-2017-5638 for federal agencies.
- SOCRadar also reports a U.S. manufacturer VPN/RDP access auction ($1,800 start, $2,200 buy-it-now, 138 AD hosts) and a sale of four servers allegedly compromised via CVE-2017-5638, one linked to a Canadian university.
- SOCRadar Dark Web Team reports alleged posts: IQUALIF-extracted 10M+ French residential database, IUT Paris Seine breach (6.8GB, 30M logs referenced), and a '19M SMTPs MIX' SMTP credential dump. Individual post dates are not stated.
Sources cited for IQUALIF French Residential Data Leak, IUT Paris Seine
- IQUALIF Leak, IUT Breach, SMTP Dump and Struts Exploit (SOCRadar)
- IQUALIF France Leak, IUT Paris Seine Breach, US IAB Auction, SMTP Credential Dump, and Apache Struts Exploit Sale (malware.news mirror)
- NVD - CVE-2017-5638
- Apache Struts S2-045 Security Bulletin
- CISA Known Exploited Vulnerabilities Catalog
- CWE-755: Improper Handling of Exceptional Conditions
- MITRE ATT&CK T1190 Exploit Public-Facing Application
- MITRE ATT&CK T1650 Acquire Access
Detection coverage for TL-2026-2930
As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2930 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.