# IQUALIF French Residential Data Leak, IUT Paris Seine Breach, 19M SMTP Credential Dump and Apache Struts CVE-2017-5638 Access Sale

> SOCRadar's Dark Web Team reported several alleged underground posts: a 10M+ record French residential database claimed to be extracted with the IQUALIF tool, an alleged breach of IUT Paris Seine, an alleged 19M SMTP credential dump, an alleged VPN/RDP initial-access auction for a U.S. manufacturer, and a sale of server access reportedly obtained via Apache Struts CVE-2017-5638. All claims are unverified threat-actor assertions.

- **Published:** 2026-10-05T00:00:00Z
- **Last reviewed:** 2026-10-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2930
- **ID:** TL-2026-2930
- **Severity:** HIGH
- **Category:** DATA_BREACH
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 9 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2017-5638

## Description

On 2026-10-05 SOCRadar's Dark Web Team (via the SOCRadar blog and a malware.news mirror) reported a cluster of alleged underground forum posts. None of the claims has been independently verified, and the source material names no threat actors or forums.

1) IQUALIF French residential leak: a post claims a database of more than 10 million French residential records, allegedly extracted using the IQUALIF tool and offered for download. Reported fields include names, postal codes, cities, addresses, gender, phone/mobile numbers, fax, housing type, average age, ethnicity and marketing fields. SOCRadar assesses the dataset could support targeted phishing, smishing, fraud and large-scale social engineering.

2) IUT Paris Seine breach: an alleged compromise of IUT Paris Seine (Universite Paris Cite), with a claimed 6.8GB of data and references to 30 million logs. Exposed material is described as server information, access credentials and logs, creating risk of credential abuse, follow-on intrusion and exposure of student or institutional data.

3) U.S. manufacturing initial-access auction: access to a U.S. manufacturing company (~$16M revenue) is offered via VPN and RDP, with 138 Active Directory hosts, domain user rights and Windows Defender present. Pricing is a $1,800 starting bid, $100 increments and a $2,200 buy-it-now. SOCRadar notes potential misuse for ransomware, data theft and privilege escalation.

4) 19M SMTP credential dump: a listing titled '19M SMTPs MIX' offering 19 million SMTP credentials, usable for phishing, spam, malware delivery, business email compromise and domain-reputation abuse.

5) Apache Struts CVE-2017-5638 access sale: access to four compromised servers (one reportedly linked to a Canadian university) is offered, with the seller claiming remote command execution, administrative control and persistence. CVE-2017-5638 (Struts S2-045) is a Jakarta Multipart parser flaw in which a crafted Content-Type header (containing an OGNL payload such as '#cmd=') yields remote code execution; CVSS v3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), CWE-755. It affects Struts 2.3.5-2.3.31 and 2.5-2.5.10, fixed in 2.3.32 and 2.5.10.1, and is in the CISA KEV catalog (added 2021-11-03).

Caveats: the SOCRadar page returned HTTP 403 to direct fetch, so details come from the malware.news mirror and search summaries. Publication/post dates of the individual forum posts, actor handles, forums and IOC network indicators are not available. The threat-level CVSS is left null because the 9.8 score belongs to the CVE only; severity HIGH is analyst-assigned from claimed scale and the exploitation-linked access sale.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1133 External Remote Services
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1021.001 Remote Desktop Protocol
- T1650 Acquire Access
- T1586.002 Email Accounts
- T1589.001 Credentials

## Sources

- [IQUALIF Leak, IUT Breach, SMTP Dump and Struts Exploit (SOCRadar)](https://socradar.io/blog/iqualif-iut-smtp-struts-dark-web-posts/)
- [IQUALIF France Leak, IUT Paris Seine Breach, US IAB Auction, SMTP Credential Dump, and Apache Struts Exploit Sale (malware.news mirror)](https://malware.news/t/iqualif-france-leak-iut-paris-seine-breach-us-iab-auction-smtp-credential-dump-and-apache-struts-exploit-sale/126128)
- [NVD - CVE-2017-5638](https://nvd.nist.gov/vuln/detail/CVE-2017-5638)
- [Apache Struts S2-045 Security Bulletin](https://cwiki.apache.org/confluence/display/WW/S2-045)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [CWE-755: Improper Handling of Exceptional Conditions](https://cwe.mitre.org/data/definitions/755.html)
- [MITRE ATT&CK T1190 Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190/)
- [MITRE ATT&CK T1650 Acquire Access](https://attack.mitre.org/techniques/T1650/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2930
