FRAP.CD User Database Leaked on DarkForums
FRAP.CD
Overview
On 12 September 2025, a DarkForums user shared a database dump from FRAP.CD, an online government-related portal in the Democratic Republic of Congo used for administrative profiles, official records and internal staff accounts. The post describes the file as a fresh private dump containing 1,136 records.

What was published
The dump includes the following columns:
usernameandpassword(hashed, in various formats)prenom,nom,postnom,sexe(names and gender)emailandphoneref_doc_designationanddoc_designation(reference documents)- Account metadata:
last_login,last_password_updated,creation_time,last_update_time,created_by,updated_by,status
The dataset covers administrators and sector staff accounts, according to the post. The presence of hashed passwords suggests the database was extracted directly from the portal's backend.
Risks for affected individuals
- Hashed passwords may be cracked offline if weak, enabling account takeover.
- Names, emails and phones linked to government portals enable targeted phishing.
- Reference document identifiers could be used to impersonate officials.
What remains unknown
- The hashing algorithm used and whether any passwords are trivially crackable.
- The number of administrative accounts among the 1,136 rows.
- Whether the portal itself was defaced or only the database copied.
What affected people should do
Government staff in DR Congo who hold FRAP.CD accounts should change their passwords immediately, enable two-factor authentication where available, and remain cautious of messages that reference their administrative identifiers.
Sources
- https://darkforums.ru/Thread-DATABASE-LEAK-FRAP-CD-%E2%80%94-1-136-LINES-Full-User-Data-Gov-Staff-Access