-
A threat actor claims to have leaked data tied to Kafiil, a freelance platform popular in the Arab world.
-
The alleged dataset reportedly holds over 300,000 user records, including names, ratings, and profile details.
-
No independent source has confirmed the breach, and the claim remains unverified.

A threat actor has posted what they claim is stolen data from Kafiil, an Arabic-language freelance marketplace. The claim surfaced on September 30, 2026. It was shared by the Dark Web Intelligence account on X. According to the post, the actor says they obtained a dataset with more than 300,000 records linked to Kafiil users.
However, no independent cybersecurity outlet or mainstream news source has confirmed the claim. Treat it as unverified. Kafiil works like a freelance marketplace. It connects clients with service providers, mostly across Arab-speaking countries. The platform remains active. Its website is up, listings are live, and user activity continues as normal.
Hacker Claims Dataset Holds Freelancer Profile Records
According to the Dark Web Intelligence post, the alleged dataset contains a wide range of user profile details. The records reportedly include usernames, full names, profile titles, and professional descriptions. They also reportedly contain identity-verification indicators, online-status data, ratings, profile-completion percentages, and links to profile media.
A separate report that picked up the same claim described a similar list of data types. That report also noted the breach had not been independently verified at the time of writing.
One key point stands out here. Most of the data described in the listing looks like profile information. On Kafiil, much of that kind of data is visible to the public. Anyone browsing the site can see a freelancer’s name, rating, and profile title without logging in.
That raises a real question. Did the actor actually break into Kafiil’s private systems? Or did they scrape data that was already publicly visible? The listing alone does not answer that. No technical evidence, such as private database fields, internal timestamps, or system identifiers, has been made public to support the claim of an actual intrusion.
What Makes this Claim Hard to Confirm
Underground forum listings are not proof of a data breach. Cybersecurity researchers know this well. Confirming a leak requires more than a post and a sample. Investigators seek private data they could not have obtained through any other means.. They check database structures, internal fields, and technical markers that point to a real system compromise.
None of that evidence has surfaced publicly in this case. Searches for independent coverage of the alleged Kafiil breach returned no credible reporting from established cybersecurity outlets. The only indexed coverage found was a feed that reproduced the same Dark Web Intelligence claim without separately confirming it, as seen on topic.fit.
Kafiil has also not issued any public statement about a breach. The platform continues to operate normally. Active service listings, including those in technical categories like AI development, remain visible on the site.
This does not mean the claim is false. It means the claim is unproven. Threat actors sometimes post real stolen data on underground forums. Other times, they recycle old data, scrape public sources, or combine both to make a listing look more serious than it is. Until researchers examine the dataset and confirm its origin, the public cannot know which is true here.
Still, if the data turns out to be genuine and privately sourced, the impact could be real. Freelancers on Kafiil share personal details as part of how the platform works. Exposed profile data, even if it seems harmless on its own, can give attackers enough to craft convincing phishing messages.
Cybercriminals have also used compromised fintech platforms in other cases to move stolen money, as reported in our story cybercriminals exploit French Fintech platforms to launder stolen funds. A fake message that addresses someone by their correct name, mentions their professional title, and references their rating can fool a lot of people.
Social engineering attacks often start exactly this way. Attackers use small pieces of real information to appear trustworthy. That lowers a target’s guard before the real attack begins.
Kafiil users should stay cautious. Watch for unexpected messages claiming to be from Kafiil or from clients on the platform. Be careful with links in emails or direct messages, especially ones asking you to log in or reset a password. Kafiil also has an active Telegram channel where platform updates are shared.
For now, the breach claim remains exactly that: a claim. No confirmed compromise, no verified dataset, and no public response from Kafiil. Users should monitor the situation and stay alert while investigators look closer.