-
A hacker claimed they stole a 10 GB MSQL database from Location-etudiant.fr, a French student housing website.
-
The stolen database allegedly includes very sensitive information, usernames, emails, phone numbers, addresses, IP addresses, as well as encrypted passwords.
-
If the allegations are correct, this data breach could expose both students and landlords to scams of different types.
Location Etudiant, a hostel rental site for French students, is reportedly entangled in a cyber breach claim. A hacker claimed to have compromised the platform’s systems, downloaded the MySQL database, and plans to leak it online.
The database allegedly contains about 10 GB of information. No word from the organization about any data breach yet, and the claims remain unvalidated.
Details of the Hacker’s Claims
According to the hacker, the alleged breach took place on July 21, 2026. The database supposedly holds a variety of user information. From the samples he released, there are full names and email addresses, phone numbers, physical addresses, and IP addresses, among others.
The exact entry point remains unclear, but ransomware groups have been increasingly targeting VPN vulnerabilities to gain initial access to corporate networks.
The post, published on a cybercrime forum, particularly indicated that the threat actor extracted user records and other information from an SQL database. They displayed a part of the SQL database directly to show their claim is authentic.
The visible structure matches a table labeled as cms_users, holding various fields related to user accounts.
Visible fields particularly include:
- Login credentials
- Account identifiers
- Email address
- Password hashes
- Full names
- Postal addresses
- Telephone numbers
- Postal codes
- Cities
- Associated companies
- Account creation dates and validity dates
- Connection IP addresses and last connection dates
- User profile info
From the details the actor provided, this database has a lot of personal information, making it dangerous. If scammers obtain such information, it may allow them to commit acts of identity theft, phishing, among others.
Hashing of passwords is a better way to store passwords compared to storing them as plaintext. However, with weak hashing and simple passwords, hackers can still decode them and use the decoded passwords in other sites where users would have used the same password.
Who Might Be at Risk?
Location Etudiant helps students find housing by connecting students with landlords and rental properties. Also, the platform helps people find roommates. So a compromise of the platform will affect a lot of people.
Property owners who list their rentals could also face danger. Roommate seekers and housing agencies using the platform might be exposed as well.
Names, contact information, and physical addresses could give criminals enough to build believable scams. They could pretend to be landlords or university officials. They might also impersonate the housing platform itself to trick victims.
Meanwhile, the author specifically threatened to release the entire database publicly if the platform ignores his message. This looks like an extortion by data disclosure attack, making the matter even more serious, even though the post mentioned no ransom demand.
The goal here appears to be to pressure the company into compensating the actor to prevent the alleged leak from going public.
No Confirmation Yet
There’s a need to validate these claims before anyone can trust them. Threat actors often bloat the size of stolen data. Some recycle old leaked information to attract buyers. Others use fake claims to pressure companies into paying ransoms.
The attacker reportedly shared a sample of the data online. But this does not prove they hold the complete database. It also does not confirm that every record is genuine.
There is no public evidence about how the attack happened. Location Etudiant hasn’t released any statement confirming any recent breach or data theft. The timing of the breach remains unknown. It is also unclear if the platform’s systems are still at risk.
Without confirmation from Location Etudiant, the full picture remains unclear. Investigating the matter officially will reveal the full scope of the incident, if at all it actually happened.
Then the organization, under GDPR rules, will notify regulators as soon as they confirm the incident. Also, they must also tell affected users within specific timeframes.
What Users Should Do Now
Even though the breach is not confirmed, experts suggest being careful. Users of Location Etudiant should think about changing their passwords, especially those who use the same password in other places.
Enable multi-factor authentication and thus increase security and make it difficult for criminals to enter your accounts.
What’s most important here is to be careful about emails and calls from unknown parties that pretend to be known companies. Scammers could pose as company reps and contact users about housing or rentals. Do not disclose any of your personal information, and do not pay money to anyone asking for payment without first verifying their identity.
It is also wise to monitor bank accounts and online services so you can spot unusual activities early. For now, this incident remains what it is, an unverified claim, so treat it as such. Every part must wait for more information before drawing conclusions.
More details will likely come out soon. Affected users might learn how many people were impacted. They could also find out what security measures to take. Until then, users should stay alert. Watch for official updates from the platform and guard your personal info with every measure possible.