-
A cyber thief allegedly claims to sell a new SQL database taken from France’s Rassemblement National website.
-
The advertised dump reportedly contains WordPress tables and data linked to the Gravity Forms plugin.
-
The claim remains unverified, with no public confirmation that the French political party suffered a breach.

A threat actor is allegedly offering an SQL database linked to the official website of France’s Rassemblement National. Rassemblement National ranks among France’s major political parties.
The alleged database appeared for sale on a hacking forum, according to Daily Dark Web. The Dark Web Intelligence account shared details about the alleged listing on X. The post reportedly appeared on July 20, 2026.
According to the information shared by Daily Dark Web, the database allegedly came from the party’s website. The threat actor reportedly claims the dump contains several tables from the site’s WordPress setup. The listing also allegedly includes data connected to Gravity Forms.
Gravity Forms is a WordPress plugin that helps websites collect information through online forms. Websites often use such forms to receive messages and other details from visitors.
However, no independent source has confirmed that the database is real. There is also no public confirmation that Rassemblement National suffered a security breach.
Alleged Database Details – What’s Inside
The threat actor reportedly describes the database as a fresh SQL dump. The listing allegedly contains core WordPress tables from the targeted website. The advertised data also reportedly includes information linked to Gravity Forms.
This could relate to records created when visitors submitted information through online forms. The sale of website data and access is a growing market; hackers have been offering access to thousands of Italian websites on the dark web.
The exact information inside the alleged database remains unclear. The available details do not confirm the specific personal records that the dump may contain.
The claim also does not prove how the threat actor allegedly obtained the data. No evidence has publicly confirmed that the database came directly from Rassemblement National’s website. The alleged listing, therefore, remains unverified at this time. Researchers would need to examine the data before confirming its source and authenticity.
Threat actors sometimes advertise databases using the names of well-known organizations. Some listings may contain real stolen data, while others may contain old information or false claims. For that reason, the alleged Rassemblement National database should not be treated as a confirmed breach. More evidence would be needed before reaching that conclusion.
If the database proves genuine, the possible exposure could still raise serious concerns. A compromised WordPress database may contain records connected to website users and administrators. Depending on the site’s setup, such records could include usernames, email addresses, password hashes, comments, and other stored information.
The alleged Gravity Forms records could also create additional concerns. Website forms can collect information that visitors choose to submit. The type of information exposed would depend on the forms available on the website. The available report does not confirm what those forms collected.
Possible Risks for Users
If the alleged database is genuine, attackers could use exposed information for further attacks. Email addresses, for example, could support targeted phishing attempts. Criminals could use information from online forms to create more believable messages.
They could also use exposed account details to target users or administrators. Password hashes could face attempts to recover the original passwords. Attackers may then try those passwords against other accounts when people reuse them.
The alleged data could also help attackers understand parts of the organization’s online setup. Administrative records may reveal information about accounts with higher access.
The possible risks could also depend on what information the alleged database actually contains. At present, the available information does not confirm the full scope. The incident also comes as organizations continue to face threats against their websites and stored data.
Political groups can hold information that attracts interest from different types of attackers. However, the available information does not establish any motive behind the alleged listing. It also does not confirm whether the threat actor successfully accessed the party’s systems.
Rassemblement National has not publicly confirmed that its website suffered a breach, based on the information provided. The alleged database therefore remains a claim from a threat actor. Independent researchers or the organization itself would need to verify the data.
Investigation and Next Steps
If the claim is confirmed, the organization would need to investigate how attackers gained access. Security teams could review server logs and activity linked to website administrators. They could also check application records to identify unusual access.
The investigation could help determine when the alleged access happened and what information attackers obtained. The organization may also need to review its account security. This could include changing passwords and checking whether any user sessions were affected.
Security teams would also need to determine whether personal information appeared in the alleged database. That step would help establish the possible impact on people who used the website.
For now, however, the alleged Rassemblement National SQL database remains unconfirmed. No independent verification has established that the data came from the political party’s website. The threat actor’s claim alone does not prove that a breach occurred.
Further evidence from security researchers, the political party, or other reliable sources will be needed. Until then, the reported database listing should be treated as an unverified allegation rather than a confirmed cyberattack.