← Blog

CNAM France Claim: 882K Student Records Offered for Sale

Share on X

Unverified claim: A forum seller using the handle Syrv4x advertised a dataset tied to the Conservatoire National des Arts et Métiers (CNAM) — the French public institution for lifelong learning, professional training, and research — offering 882,918 records in a 289 MB file, with birth details and internal student identifiers. Dark Web Informer documented the listing on October 2, 2026. At indexing time BreachHistory found no CNAM confirmation, no French CNIL enforcement notice tied to this sale, and no independent verification of the file. This is not Moldova’s CNAM health insurer — readers searching “CNAM breach” must separate France’s Conservatoire from Eastern European insurance brands that share the acronym.

Canonical record: https://breachhistory.com/cnam-france/cnam-france-forum2026 (/cnam-france/cnam-france-forum2026). BreachHistory catalogs 882,918 records affected (unverified) from the actor’s stated count — clearly labeled as unverified in prose until CNAM or CNIL attests otherwise.

What Syrv4x claimed on the forum

Dark Web Informer’s October 2, 2026 alert summarizes a sale post attributed to Syrv4x. The actor describes a CNAM dataset with:

  • 882,918 records and a 289 MB file size
  • Fields including internal and external identifiers, surnames, usual names, given names, normalized-name fields, dates of birth, birth departments, birth communes, owning entities, and record-creation dates
  • A 1,500-line sample and pricing on a “make an offer” basis
  • Telegram contact @Syrv4x visible in screenshots reviewed by Dark Web Informer

The listing also advertises aggregate statistics — for example 882,917 surname values with 266,029 unique surnames, and 882,927 internal student ID values with 773,306 unique IDs. Those figures come from the seller’s marketing math, not from CNAM or a regulator. Dark Web Informer explicitly states it has not independently verified authenticity, source, size, record count, sample contents, or current availability.

What the post does not include: an acquisition method, proof of live CNAM database access, malware hashes, or CNAM acknowledgment. A structured CSV of French learners is plausible in the abstract; plausibility is not verification.

Timeline

  1. October 2, 2026 (~3:25 AM in listing metadata) — Syrv4x sale post appears with CNAM branding and field list, per Dark Web Informer’s captured screenshots.
  2. October 2, 2026 (evening) — Dark Web Informer publishes its unverified alert with IOC table (actor handle, Telegram, organization domain cnam.fr as named victim context).
  3. October 5, 2026 — BreachHistory indexes the claim with unverified labeling and actor-reported count 882,918. No CNAM press release corroborating theft was located at indexing.

What we still do not know

  • Whether the file is genuine CNAM data — sellers reuse old breach dumps, synthesize rows, or mislabel institutions.
  • Compromise path if real — SQL misconfiguration, stolen admin credentials, backup tape, or insider export is unstated.
  • Recency — record-creation dates in the field list might span years; the listing does not prove a 2026 intrusion.
  • Full vs sample — buyers may receive truncated or stale copies even when counts look large.

CNAM France — which institution this is

The Conservatoire National des Arts et Métiers is a French public higher-education and training institution with research missions — not the national health insurance fund often abbreviated CNAM in other countries. Confusing the Conservatoire with Moldova’s Compania Națională de Asigurări în Medicină or casual “CNAM” insurance references has already polluted social search threads in prior European breach news.

CNAM (Conservatoire) serves adult learners, apprentices, and researchers across a decentralized network. Student and alumni registries naturally hold stable identifiers, legal names, and birth metadata — exactly the fields Syrv4x highlights. That makes the CNAM data breach keyword valuable for SEO and dangerous for accuracy: every paragraph here refers to the French Conservatoire unless explicitly noted otherwise.

Why 882,918 records in 289 MB is plausible — and why that does not verify the sale

Structured identity rows compress efficiently. Hundreds of thousands of records can fit in a few hundred megabytes when fields are mostly text and dates, not scanned documents. Conversely, a seller can lie about counts while showing a 1,500-line sample that looks realistic.

BreachHistory stores 882,918 as the best available figure from the actor listing while labeling it unverified in catalog prose and this blog. If CNAM later publishes a smaller confirmed census, the canonical row should be updated — not because forum marketers deserve benefit of the doubt, but because victims and regulators own the final number.

Field-by-field stakes for learners and alumni

Dark Web Informer’s table of advertised columns maps to concrete fraud scenarios if the dataset is authentic:

Identifiers

Internal and external student IDs let attackers correlate rows across years and campuses. Unique internal IDs (~773k unique of ~883k claimed) suggest repeat enrollments or multiple programs per person — useful for profiling, not just single-shot phishing.

Names

Surnames, given names, and “usual names” (nom d’usage) support French-language spear phishing that mirrors official CNAM enrollment mail. Normalized-name fields may help attackers deduplicate married-name changes.

Birth department and commune

French birth locality fields are sensitive in combination with DOB and full name — they anchor identity checks used by banks and some government workflows. They also help criminals guess INSEE-style validation questions when other leaks supply missing digits.

Owning entity and creation dates

Campus or regional entity names turn generic spam into messages citing a learner’s actual site (“Your CNAM Paris enrollment must be confirmed”). Creation dates hint at cohort year for social-engineering timing around exam periods.

What was not claimed — and what CNAM has not said

The Dark Web Informer article does not assert passwords, grades, payment cards, or research intellectual property in the advertised field list. Absence in a forum screenshot is not a CNAM guarantee those categories are safe.

CNAM (Conservatoire) had not issued a public confirmation matching Syrv4x’s sale at BreachHistory indexing on October 5, 2026. Check cnam.fr and official CNAM social accounts before treating Telegram screenshots as institutional fact.

CNIL — France’s data protection authority — had not been tied in indexed sources to a reprimand or press line specifically validating this October forum post at indexing time.

How the data might have leaked — speculative paths only

Dark Web Informer maps an inferred MITRE technique (T1213.006 — data from information repositories: databases) because the listing looks like structured query output. That is analyst labeling of the claim, not forensics from CNAM’s SOC.

Common paths for similar education-sector dumps worldwide include:

  • Over-exposed staging database with weak credentials
  • Compromised integrator account syncing student information systems
  • Insider export sold as “fresh” data years after initial theft
  • Reuse of an older incident repackaged under a 2026 post date

CNAM defenders — if investigating — will know which hypothesis fits. Outsiders should not stamp “SQL injection” on the headline.

Who is at risk if the claim proves true

Current CNAM learners. Phishing about tuition, exam registration, or apprenticeship paperwork.

Alumni and former trainees. Career-long retention means adults who studied a decade ago may still appear in registries.

Staff referenced as owning entities. Messages impersonating regional administrators.

Family members. Less common in the field list, but secondary scams often target relatives when DOB + name leaks.

Until CNAM confirms, the widest at-risk group is anyone who believes the dump is verified and clicks actor-linked Telegram offers — those buyers become fraud victims themselves.

Phishing scenarios tied to CNAM France

  • “Confirm your CNAM inscription before cutoff.” Links to cloned cnam.fr login pages.
  • SMS in French citing birth commune — locality detail borrowed from a real row feels authoritative.
  • Fake CNIL or CNAM refund forms harvesting banking details unrelated to the original leak.
  • Scholarship or apprenticeship grants requiring “verification fees.”

France education and forum-sale context in 2026

France’s education sector has seen both verified regulator-tracked incidents and unverified actor marketing. BreachHistory catalogs an unverified ZeroBytes claim against Education Nationale pupil data — different agency, similar playbook: name a recognizable ministry or school brand, publish huge counts, wait for press amplification.

Verified university incidents elsewhere in Europe show what confirmation looks like. Denmark’s DTU DTUBasen IAM breach shipped an official English notice, CPR exposure detail, and regulator reporting — none of which exists yet for Syrv4x’s CNAM sale post.

Consumer travel breaches such as Wakacje.pl passport exposure and Japan’s Times Car 6.6 million account confirmation illustrate how national ID cultures shape post-breach advice. French readers should watch CNAM and CNIL channels, rotate passwords reused on CNAM portals, and treat forum “samples” as toxic waste — downloading them can be illegal regardless of authenticity.

Media parallels like the Japan Times Eclipse unverified listing show how recognizable brands attract leak-site or forum noise without same-day corporate confirmation.

What you should do

  1. Do not buy or download the alleged dataset — possession can violate French computer abuse and privacy law even when sellers claim “research.”
  2. Verify CNAM communications only through cnam.fr and known official email domains; ignore Telegram sellers.
  3. Rotate passwords if you reused a CNAM portal password on consumer email or banking sites.
  4. Enable MFA on personal email and banking where available.
  5. Watch for French-language phishing referencing your birth department or internal student ID — report to CNAM through official channels if received.
  6. Monitor credit and identity services if CNAM later confirms sensitive national identifiers beyond what the forum listed.
  7. Journalists: distinguish Conservatoire CNAM from unrelated CNAM acronyms in headlines; label Syrv4x material unverified.
  8. Researchers: do not republish the 1,500-line sample — it may contain living individuals’ data.

Regulatory and institutional posture

Under GDPR, a confirmed personal-data breach at a French public institution would trigger internal notification workflows and likely CNIL contact within statutory timelines. None of that public paper trail was indexed for this forum sale on October 5, 2026.

If CNAM confirms unauthorized export, expect French-language notices to learners, description of affected fields narrower than forum marketing, and guidance on fraud hotlines. Until then, “882,918 records” lives in the same bucket as actor math — useful for threat intelligence, not for personal panic.

Technical notes for CNAM defenders and integrators

  • Audit export jobs and DB roles tied to student information systems — forum listings often follow bulk SELECT patterns.
  • Alert on anomalous downloads approaching hundreds of megabytes from training registries.
  • Review third-party SaaS connectors with standing API keys to CNAM identity stores.
  • Preserve logs if investigating Syrv4x claims — law enforcement may request them if sales continue.
  • Prepare French and English holding statements; forum posts sometimes precede journalist calls by hours.

Was I affected?

There is no legitimate public search tool tied to Syrv4x’s post. If you studied or train through CNAM (Conservatoire), the honest answer on October 5, 2026 is: unverified claim — wait for CNAM. Bookmark the canonical breach page and revisit after institutional statements.

If CNAM denies the dataset or CNIL publishes findings, update your personal risk calculus accordingly. If CNAM confirms, expect field lists and remediation steps that may differ from forum screenshots.

Canonical record and sources

BreachHistory indexes this row as an unverified forum sale claim against a named French public institution with actor-stated count 882,918 (unverified).

Independent verification may never arrive — some forum sales are fraud. The indexing value is early warning for CNAM security teams and clear public labeling so learners do not confuse Conservatoire CNAM with unrelated health insurers or treat actor counts as government-confirmed fact.

Acronym confusion — a reader guide

Search engines collapse distinct institutions. “CNAM breach 2026” may surface this Conservatoire forum claim, Moldovan insurance news, or unrelated clinical networks. Before sharing, check whether the article names Conservatoire National des Arts et Métiers, France, and student registries — not health claims processing.

International reporters drafting English headlines should spell out “CNAM (Conservatoire), France” once per piece to reduce harm to unrelated CNAM-branded organizations.

Sample lines and researcher ethics

Syrv4x advertised a 1,500-line sample. Security vendors sometimes acquire samples under controlled conditions; journalists and curious students should not. French privacy law and GDPR apply to processing personal data even when rows appear on criminal forums. Dark Web Informer withheld live student identifiers in its public IOC table — follow that example.

Telegram commerce and buyer risk

Forum sellers who route buyers to @Syrv4x on Telegram monetize attention. Even if a buyer receives a file, it may be poisoned with malware or partially fabricated. Law-enforcement stings also target buyers. The safe consumer action is zero engagement.

CNAM’s public mission and data minimization expectations

As a public training institution, CNAM processes learner data under GDPR principles including purpose limitation and retention schedules. A confirmed exfiltration would raise questions about export controls on registries, not just perimeter firewalls. None of those institutional responses were public at indexing — only Syrv4x’s marketing.

Cross-border learners

CNAM’s adult-learning mission includes professionals who may also hold accounts in other EU countries. If confirmed, notification might need French and English (and possibly other language) guidance for alumni abroad. Unverified status means diaspora learners should not assume compromise but should still rotate reused passwords as basic hygiene.

Threat intelligence value without sensationalism

Indexing forum sales early helps CNAM CISOs hunt for matching IOCs and prepares comms teams for journalist queries. It does not require amplifying the seller’s record count as fact. BreachHistory’s unverified label is the compromise: document the claim, refuse to launder it into certainty.

Relation to EU sectoral NIS2 expectations

Public entities and large education providers across the EU face heightened incident-reporting expectations under NIS2 implementations. A confirmed CNAM breach would intersect with national transposition timelines and CNIL cooperation — details beyond what a Telegram seller supplied. Forum posts are not substitute regulatory filings.

Password and portal hygiene for CNAM users

If you maintain an active CNAM learner account, enable strong unique passwords and MFA if the portal supports it — sensible even when no breach is confirmed. Phishing that cites real birth communes works best against people reusing credentials across sites.

French learners reading BreachHistory should remember that 882,918 unverified records does not mean 882,918 people received CNAM email notices — it means one seller said so. Official CNAM messaging, if it comes, will define the affected population in legal terms, not forum arithmetic.

French learners reading BreachHistory should remember that 882,918 unverified records does not mean 882,918 people received CNAM email notices — it means one seller said so. Official CNAM messaging, if it comes, will define the affected population in legal terms, not forum arithmetic.

French learners reading BreachHistory should remember that 882,918 unverified records does not mean 882,918 people received CNAM email notices — it means one seller said so. Official CNAM messaging, if it comes, will define the affected population in legal terms, not forum arithmetic.