leak Potential Tunisia (TN) logistics

La Poste Tunisienne: full server root access claimed

La Poste Tunisienne

📅 03 July 2025 👁️ 1 views
CompanyLa Poste Tunisienne
CountryTunisia (TN)
Sectorlogistics
Breach date2025-07-03
People affected100,000
Data typesNot disclosed
<p>On 03 July 2025, mecrobyte claims to have obtained access to data belonging to <strong>La Poste Tunisienne</strong>, Tunisia on a hacking forum. The claimed data includes Firebase configuration, server access proof. Sample data was published alongside the claim, providing corroborating evidence of the breach.</p> <h2>What the source reveals</h2> <p>Weewoo Hi, DarkForums Community Weewoo I have returned to you again, and this time I will publish proof that shows the hacking of Tunisian Poste servers . You are truly fools; how could a national postal service not be secure? You are really fools, and definitely M3Cr0byte greets you And you should know that I am not Moroccan, you cowards.And soon we will publish the vulnerability Tunisian Poste FirebaseConfig : Quote: apiKey : "AIzaSyAF8ivffEax1A-wFs02YO4tC41GTyKriyQ", authDomain : "digipostbank17.firebaseapp.com", databaseURL : "https://d17-ccp.firebaseio.com", TELEGRAM USERNAME : @M3cr0byte</p> <h2>Risks</h2> <ul> <li>Unauthorised access to sensitive organisational data that could be used for follow-on attacks</li> <li>Competitive intelligence loss if proprietary business information or trade secrets were exposed</li> <li>Reputational damage and erosion of customer, citizen, or stakeholder trust in the affected organisation</li> <li>Legal liability and regulatory fines under applicable data protection frameworks</li> </ul> <h2>What remains unknown</h2> <ul> <li>the total volume of data compromised and whether it includes additional categories beyond those disclosed</li> <li>the method by which the data was obtained - whether through a direct database compromise, an insecure API, or a third-party breach</li> <li>whether the data has been sold or distributed to additional parties beyond the forum post</li> </ul> <h2>Conclusion</h2> <p>While the claim has not been independently verified, the potential exposure of data from La Poste Tunisienne warrants attention. Organisations in the logistics sector should treat this incident as a reminder to audit access controls, monitor for anomalous data exfiltration, and ensure incident response plans address data publication scenarios. Affected individuals should change passwords and remain vigilant against phishing attempts.</p>