leak Credible Côte d'Ivoire (CI) government

ANADER Côte d'Ivoire Database Dump Leaked on DarkForums

ANADER (Agence Nationale d'Appui au Développement Rural)

📅 13 December 2025
CompanyANADER (Agence Nationale d'Appui au Développement Rural)
CountryCôte d'Ivoire (CI)
Sectorgovernment
Breach date2025-12-13
People affected500,000
Data typesusernames, password hashes, emails, contacts, roles

Overview

On 13 December 2025, a DarkForums user using the handle AHLUL SAHARA published a database dump of ANADER, the Agence Nationale d'Appui au Développement Rural of Côte d'Ivoire, whose website is anader.ci. The archive, 11.4 MB, contains the agency's user accounts, internal contacts and regional mapping.

Screenshot of the DarkForums thread

What was published

The post describes a raw database export in SQL (UTF-8) and JSON formats, built on Symfony and Doctrine ORM. The dump includes:

  • users table with credentials, roles, salts and password hashes (PBKDF2-HMAC, Base64-encoded, random 44 to 55 character salts)
  • contacts table with internal contact details
  • zones table with regional mapping
  • Emails, names and canonical usernames

Database dump excerpt

One sample account shown in the post belongs to the agency's DGA (Director General) profile with the role ROLE_SUPER_ADMIN, alongside staff accounts with salted password hashes.

Risks for affected individuals

  • PBKDF2-HMAC hashes resist casual cracking but remain exposed to offline brute force if passwords are weak.
  • A ROLE_SUPER_ADMIN account in the dump signals a potential path to full administrative access.
  • Staff names, emails and roles enable targeted phishing against a government agency.

What remains unknown

  • The total number of accounts and contacts in the dump.
  • Whether the passwords were ever validated against the plaintext.
  • The extent of any wider access to ANADER systems.

What affected people should do

ANADER staff and contractors should reset their passwords immediately, review account activity, and verify that no unauthorized administrative changes were made. The agency should audit the exposed accounts and rotate all credentials.

Sources

  • https://darkforums.ru/Thread-DATABASE-LEAK-ANADER-COTE-D-IVOIRE