ONEFEP Student Database with Plaintext Passwords Leaked
National Office for Distance Education and Training of Algeria (ONEFEP)
Overview
On 29 March 2026, a DarkForums user published what is described as the breached database of the National Office for Distance Education and Training of Algeria (ONEFEP). The post includes a SQL dump sample with student records and states that passwords were stored in plaintext.

What was published
The post lists the following exposed fields:
- Students' full names
- Usernames
- Passwords in plaintext
- IP addresses of users
- Academic email addresses
- Birth dates and registration dates

The sample row shows a student registered on 16 March 2026 with username, plaintext password, IP address, name, birth date and birthplace. The data appears to come from the cbt_user table of the distance education platform.
Risks for affected individuals
- Plaintext passwords allow immediate account takeover of the distance learning platform.
- Reused passwords put other online accounts at risk.
- Birth dates, names and emails enable identity fraud and targeted phishing.
What remains unknown
- The total number of student records in the dump.
- Whether the breach is limited to the
cbt_usertable. - Whether ONEFEP has notified affected students.
What affected people should do
Students of ONEFEP should change their platform password immediately and every other account where the same password was used, enable two-factor authentication where available, and be alert to phishing referencing their academic records.
Sources
- https://darkforums.ru/Thread-DATABASE-National-Office-for-Distance-Education-and-Training-of-Algerian