La Poste Tunisienne: root access claimed on DarkForums
La Poste Tunisienne
Overview
On July 2, 2025, DarkForums user mecrobyte claimed that La Poste Tunisienne, Tunisia's national postal operator, had been breached. The post states that full root access was gained to the main mail servers, with control over financial and customer data, internal parcel tracking systems and the ability to alter or extract user information.

What was published
No data sample or download link was published in the thread. The claim lists the systems the actor says were accessed:
- Main mail servers with root access
- Financial and customer data
- Internal parcel tracking systems
- Backdoor installation for persistent access
The poster provided a TOX identifier as proof of the operation.
Risks for affected individuals
Tunisian postal customers could be at risk if customer data was extracted, including names, addresses and parcel information. Financial services linked to La Poste Tunisienne accounts could be targeted if payment data was accessed.
What remains unknown
- La Poste Tunisienne has not publicly commented
- No data was released, so the scope of any exfiltration is unverified
- The claim could not be independently confirmed
What affected people should do
Tunisian postal users should watch for suspicious messages referencing their postal or financial accounts and monitor statements for unauthorized activity. Changing passwords on La Poste Tunisienne online services is recommended.
Sources
- https://darkforums.ru/Thread-Full-Server-Acces-We-Hacked-The-Tunisian-Poste