-
A threat actor allegedly published an EFC database and offered the data for free online.
-
The alleged leak may contain records linked to about 49,000 students and 60,683 PDF files.
-
The data reportedly includes personal details, training records, certificates, invoices, and banking information.

A threat actor has reportedly published a database allegedly linked to École Française de Comptabilité, or EFC. The institution is a French organisation that provides distance learning and training services. Dark Web Intelligence, known as @DailyDarkWeb on X, first reported the alleged leak.
The threat actor reportedly claimed to have obtained an EFC database and released it for free. The post also showed sample records that appeared to contain student and training information.
It reportedly included a download link and some sample data to support the claim. However, the available information did not initially confirm the authenticity of the database.
Details of the Alleged Data Leak
Cyber Breaches later reported a larger alleged incident involving EFC Formation. According to the report, a threat actor known as ChimeraZ claimed responsibility for the leak. The actor allegedly published a 1.3 GB archive containing information linked to about 49,000 students. Cyber Breaches reported that the actor released the archive on May 14, 2026.
The same report also described another collection that allegedly contained 60,683 PDF documents. The second collection reportedly measured about 41 GB in size and included administrative records. The actor allegedly offered that larger collection for sale. The reported student data allegedly includes names, addresses, birth dates, and enrolment numbers.
The records may also contain details about students’ training programmes and course information. Other files reportedly include certificates, signed forms, invoices, and training records. The exposure of student records is a growing concern; hackers have claimed 58 million Indonesian students’ data for sale on the dark web.
Some documents allegedly contain banking details, including RIB and IBAN information. Brinztech also reported an alleged 41 GB collection connected to EFC Formation. The report said the collection contained 60,683 PDF files linked to the organisation.
Those files reportedly included academic records, financial documents, invoices, certificates, and administrative information. The reports did not establish how the alleged attackers obtained the information. They also did not independently confirm the full contents of every file in the collection.
Potential Risks for Students and Other Individuals
If the reported data proves genuine, affected people could face several security risks. Criminals could use personal details to create convincing phishing messages and scams. They could also use student information to impersonate schools, training centres, or other trusted organisations.
The alleged banking records could create additional risks for people whose financial details appear in the files. Attackers could combine personal and financial information to make targeted fraud attempts more believable. The alleged exposure could also affect the privacy of students and other people linked to EFC Formation.
The reported data may contain enough information to build detailed profiles of individuals. That information could then help criminals target victims with personalised messages or impersonation attempts.
The incident also raises concerns about the security of organisations that store large amounts of personal information. Educational and training organisations often hold records that include names, addresses, birth dates, and financial details. A single exposure can therefore affect many people at the same time.
What We Know About the Alleged Breach
The reported EFC incident appears to be part of wider claims involving French education and training organisations. Cyber Breaches reported that EFC Formation was among several organisations allegedly targeted by ChimeraZ. The exact method used to access the information remains unclear based on the available reports.
There is also no public confirmation from EFC Formation confirming that the alleged datasets are genuine. The precise number of affected people also remains unclear. The initial Dark Web Intelligence report pointed to an EFC database leak. Later reports described a much larger collection involving student records and administrative documents.
The reported figures, therefore, suggest that the alleged exposure may extend beyond the database mentioned in the first report. However, the full scope of the incident remains unclear without confirmation from EFC Formation or relevant authorities.
For now, the available reports describe an alleged data exposure involving personal, academic, administrative, and financial records. People who may have been affected should remain alert for unusual emails, messages, or requests for personal information.
They should also treat unexpected messages claiming to come from EFC or related organisations with caution. The alleged incident shows how a single data exposure can potentially place many types of information at risk. Until the organisation or authorities provide more details, the exact impact of the alleged leak remains unknown.