Skip to content
RegionEurope

LowII Cyber Warfare & Critical Infrastructure4 October 2026, Sunday

Stolen data on 700,000 Belgians from IFAPME now circulating free

Personal data on about 700,000 people stolen from IFAPME, the Walloon vocational training network, in a February 2026 cyberattack has been freely downloadable on a dark web forum since 4 October. The leak includes more than 85,000 bank account numbers (IBANs).

Location: CHARLEROI

According to VRT, the data includes names, addresses, email addresses, phone numbers and dates of birth, as well as Belgian national register numbers. ITdaily reports that IFAPME was attacked in February 2026 and that the stolen data was put up for sale on the dark web at the time. FrenchBreaches, which tracks data breaches, said the files have been circulating for anyone to download since 4 October. The sources do not name the group behind the attack or say whether a ransom was demanded; this could not be verified.

According to FrenchBreaches, the risk comes from identity and banking details being combined for the same individuals. An IBAN alone does not authorise payments, but paired with personal details it makes fake invoices and phishing attacks convincing. Because the national register number is a permanent identifier that cannot be changed, the impact of the leak could last for years.

The constraint lies in the data moving from sale to free distribution. Data offered for sale reaches a limited number of buyers; data released for free ends up with every fraudster. A public training network in Wallonia is back in the news eight months on. That shows the damage from a breach grows not on the day of the attack but each time the data changes hands.

Talay assessment

Bottom line

The free release of data stolen in February widens the damage from a limited pool of buyers to anyone. With national register numbers and IBANs circulating together, the risk of targeted fraud in Wallonia is rising. The most likely course is a wave of phishing in the coming weeks that exploits the IFAPME name or victims' bank details.

Likely effects

  • Fraud in BelgiumNegativeWeeks

    Identity and banking details circulating together make fake invoices and phishing messages personalised and convincing.

  • Public sector accountabilityUncertain1–6 months

    Data from a public training network that can circulate for years may increase supervisory and enforcement pressure under EU data protection rules.

  • A lesson for TürkiyeUncertain6 months+

    Data leaked from Turkish public and educational institutions carries the same risk if it is re-released for free; permanent identity numbers are the weakest link.

Possibilities, ranked

  1. 1
    Phishing wave55%

    Targeted phishing and fake invoice attempts using the leaked data and posing as IFAPME or banks are reported.

    Watch: Phishing alerts linked to IFAPME from Belgium's Centre for Cybersecurity

  2. 2
    Silent circulation30%

    The data keeps circulating but no large-scale fraud is reported, and the issue drops off the agenda.

    Watch: No reports of IFAPME-linked fraud in Wallonia in October–November

  3. 3
    Regulatory sanction15%

    Belgium's data protection authority announces an investigation into or sanction against IFAPME.

    Watch: A ruling on IFAPME by the Belgian Data Protection Authority

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • People whose data leaked▼ ≈700,000
  • Bank account numbers leaked▼ 85,000+

Sources

  1. VRT NWS — Cyberaanval IFAPME Wallonië
  2. ITdaily — Data of 700,000 people leaked for free on dark web after IFAPME hack, including bank details