← Blog

Grand Delta Habitat: 188K Records Sale Claim (Unverified)

Share on X

Unverified claim: Cybercrime forum listings attributed to actors using the handles mica and, in an earlier thread, fdp have advertised a database said to belong to Grand Delta Habitat (GDH), a French social-housing landlord headquartered in Avignon and operating at granddelta.fr. The posts claim roughly 188,010 records totaling about 272 MB, spanning operational data from approximately May 2018 through September 2026 in the earlier “fdp” analysis cited by regional press. Trade coverage and breach trackers describe tenant, maintenance, billing, and intervention workflows — not a simple email combo list. At BreachHistory indexing on 11 October 2026, Grand Delta Habitat had not confirmed a data breach; LinkedIn and press quotes describe awareness of circulating reports, ongoing verification, and a promise to notify stakeholders if exposure is confirmed. This article treats the sale as an unverified forum claim with an actor-supplied record count — not as regulator-attested or company-confirmed fact.

What the mica and fdp listings allege

According to FrenchBreaches’ alert of 11 October 2026, user mica published a cybercrime forum advertisement offering a file described as Grand Delta Habitat data. The pitch mirrors an earlier revendication under the pseudonym fdp that La Marseillaise covered on 16 September 2026: orders and interventions tied to housing units, occupants, personal contact details, suppliers, and the processing history of tenant requests.

Visible sample fields reported by FrenchBreaches include structured maintenance and billing columns such as ref, client, montantTTC, description_demande, events_history, prestations, patrimoine, and occupants_info. That schema suggests a property-management or work-order system export rather than a marketing newsletter database. Samples reference municipalities in GDH’s footprint — including Avignon, Arles, Le Pontet, Mallemort, and Pont-Saint-Esprit — with work types ranging from plumbing leak searches and electrical maintenance to equipment replacement, move-related operations, and invoiced technical services.

Undercode News summarized Dark Web Intelligence reporting on the same scale: 188,010 records, ~272 MB, with field names pointing to client details, contact persons, request descriptions, status fields, comments, occupant-related data, and billing lines (supplier names, service numbers, amounts before and after VAT). None of that proves the seller exfiltrated data from GDH production systems; it proves someone is marketing a dataset with GDH branding and plausible housing-administration shape.

188,010 records vs. 36,000 people

The headline number 188,010 is an unverified actor count of rows or events, not a census of unique tenants. Maintenance systems generate repeat entries: the same household may appear across multiple interventions, billing cycles, status updates, and supplier tickets. FrenchBreaches and La Marseillaise both caution that analysts previously estimated on the order of 36,000 locataires might be implicated when deduplicating occupants — still an analytical estimate, not a confirmed victim notification.

BreachHistory catalogs recordsAffected: 188010 with companyConfirmed: false so readers searching “Grand Delta Habitat data breach” see the scale actors advertise while the title and writeup keep the unverified label. If GDH or CNIL later publish an attested count, replace the actor figure; until then, do not treat 188k as “188k people.”

Claimed data types and what was not established

Based on samples described in open-source reporting, claimed categories include:

  • Names and surnames of tenants, occupants, and contact persons
  • Postal addresses of dwellings and residences
  • Landline and mobile phone numbers
  • Personal and professional email addresses
  • Manager or handler coordinates inside GDH workflows
  • Order and intervention references
  • Free-text descriptions of repair requests and maintenance work
  • Billing amounts, prestation details, supplier identities, and service numbers
  • Administrative status history and event timelines

Reporting reviewed for this article does not clearly establish exposure of full payment-card primary account numbers, bank account credentials, or national ID numbers as a confirmed field set. Do not assume IBANs or passwords were in the bundle unless a future verified notice says so. Even without financial identifiers, housing CRM plus intervention narrative can be high-impact PII: it ties people to precise addresses and ongoing service relationships.

Why social-housing maintenance data is sensitive

Grand Delta Habitat manages more than 42,000 logements across seven départements, with heavy concentration in Vaucluse (~30,000 units per La Marseillaise). Social landlords hold legally and socially sensitive dossiers: rent situations, accessibility needs surfaced through repair tickets, family composition hints in occupant fields, and free-text comments where staff or residents describe emergencies (leaks, heating failures, security hardware).

Attackers value that mix for targeted phishing and fake technician scams. FrenchBreaches notes a fraudster who knows a real intervention at a real address can impersonate GDH or a legitimate contractor, demand payment for “urgent” work, or schedule a bogus visit. That is more convincing than generic spam because it references authentic-sounding ticket language — exactly why unverified claims about intervention exports still belong in threat-intelligence catalogs even before confirmation.

Timeline of public reporting (all unverified until GDH confirms)

  • ~September 2026 (reported) — Forum listing under handle fdp described by FrenchBreaches; La Marseillaise (16 Sep) quotes GDH saying the subject is not confirmed, investigations continue, and teams are mobilized.
  • Claimed coverage period (actor-stated) — Data alleged to span roughly May 2018 through early September 2026 in the earlier listing analysis — actor dating, not verified by GDH.
  • 11 October 2026 — FrenchBreaches documents a fresh advertisement under mica with the same ~188,010 / 272 MB framing; Undercode News/DWI-style summaries circulate internationally.
  • 11 October 2026 (indexing) — BreachHistory row remains companyConfirmed false; no CNIL sample notice attached to this specific claim in sources used here.

Handle changes (fdp → mica) are common in forum resale chains. They do not, by themselves, prove two separate intrusions or a single persistent compromise.

How the attack might have worked — and what we cannot say

Open sources do not identify an initial-access vector: no named CVE, no confirmed stolen VPN credential, no ransomware leak site attribution. Undercode News explicitly separates a rumored $500 administrator-access upsell from the captured mica post — that access offer was not visible in the archived listing they reviewed, so treat admin-access marketing as its own unverified thread.

Plausible hypotheses investigators would test (speculative, not confirmed): misconfigured backup export, compromised third-party maintenance SaaS, over-privileged contractor account, insider abuse, or recycled data from an older incident repackaged under a new seller name. Forensics and GDH’s internal schema match would be required to elevate any hypothesis to fact.

What Grand Delta Habitat has said publicly

La Marseillaise quotes GDH in mid-September 2026: although the incident is not confirmed, the organization takes reports very seriously; verification is ongoing; protecting tenant, partner, and stakeholder data remains the priority; and GDH never asks by phone, email, or SMS for bank details, passwords, or payments. That is careful crisis language — neither denial nor admission — appropriate while logs and data-lineage checks run.

Later LinkedIn and press echoes reported in international summaries state GDH is aware of circulating reports, is verifying, and will notify affected parties if confirmed. Until a formal FAQ, registered letter, or regulator filing appears, the accurate public sentence remains: unverified sale claim; GDH investigating.

Who could be at risk if the dataset is authentic

Current and former tenants in GDH-managed units whose contact data appears in intervention tickets. Occupants and household members referenced in occupants_info or comment fields. Suppliers and contractors named on billing lines. GDH staff or handlers listed as interlocutors on requests. Risk stays conditional on authenticity, but French social-housing residents should still harden against maintenance-themed fraud while verification continues.

Industry and campaign context in France, October 2026

French breach trackers and forums simultaneously carried other consumer and public-sector dataset sales — fitness chains, education-adjacent CSVs, insurance-adjacent leaks — often with clear unverified labels. Housing landlords sit in a regulated, politically visible lane: a named GDH claim draws regional press (La Marseillaise) and specialized monitors (FrenchBreaches) faster than anonymous combo dumps. That attention increases phishing velocity even when the underlying sale is unproven.

Compare this incident type to verified 2026 breaches with AG or company notices: those rows can cite attested field lists and notification timelines. This row cannot yet. Readers evaluating Grand Delta Habitat breach 2026 search results should weigh evidence tier first, actor marketing second.

Regulatory and notification posture (GDPR / CNIL)

If GDH later confirms unauthorized exposure of personal data, French GDPR implementation would expect documented risk assessment, possible CNIL notification depending on likelihood and severity of harm to data subjects, and direct communication when high risk to individuals is identified. None of that flows automatically from a mica forum post. CNIL and data subjects should watch for primary GDH communications, not screenshot threads.

Tenant associations and municipal partners may ask whether subcontractors held copies of intervention exports — a common gap in housing IT estates. That question is investigative, not answered here.

Action items for tenants and partners

  1. Treat unexpected calls about “urgent GDH maintenance” or unpaid invoices as suspicious until verified through official GDH channels (website phone numbers, tenant portal, or known office contacts).
  2. Never share passwords, IBANs, or card details in response to SMS or email links tied to repair tickets.
  3. If a message references a real-sounding intervention, hang up and call GDH back on a number you already trust — do not use callback numbers supplied in the message.
  4. Warn household members, especially elderly residents, about fake technician visit scheduling.
  5. Contractors named in public samples should watch for impersonation attempts targeting their GDH relationship.
  6. Rotate passwords if you reused a personal email password on any housing portal — precautionary, not confirmation that portals were breached.
  7. Monitor GDH’s official site and postal mail for a confirmed notice; ignore “download your leak file” come-ons.
  8. Report suspected phishing to French authorities via Cybermalveillance.gouv.fr pathways when appropriate.
  9. Follow the canonical BreachHistory record for label updates: Grand Delta Habitat 2026 claim (/grand-delta-habitat/grand-delta-habitat2026).

Action items for GDH-scale housing IT and security teams

Even while claims remain unverified, peer landlords should rehearse this scenario: bulk export of work-order tables with comment fields, supplier joins, and occupant linkage. Controls that reduce blast radius include role-based export limits, DLP on large CSV/SQL dumps, MFA on contractor VPNs, short-lived tokens for integrators, and comment-field training so staff do not paste medical or financial narratives into tickets.

Logging matters for disproving or confirming forum claims: database SELECT spikes, off-hours ETL jobs, SFTP pushes to unknown endpoints, and SaaS admin downloads should retain enough retention to compare against actor-stated date ranges (May 2018–Sep 2026 claimed in earlier analysis). If samples surface, compare cryptographic hashes and internal primary keys — not just company logos in filenames.

Phishing scenarios to expect if samples are real

Fraud templates likely to reference:

  • Plumbing or leak interventions “requiring immediate co-payment”
  • Electrical safety checks with a link to “confirm appointment”
  • Charge regularization or rent adjustment after fake maintenance
  • Requests to “update tenant dossier” after a claimed GDPR export
  • Supplier payment redirection for firms that appear on genuine billing rows

Each template exploits trust in housing bureaucracy. The defense is channel verification, not paranoia about every real repair visit.

How BreachHistory labels this Grand Delta Habitat incident

Title, root cause, and technical writeup use unverified language. Share hooks use CLAIM — UNVERIFIED when the company has not attested exposure. We retain the actor count 188010 because scale helps defenders prioritize monitoring; we refuse to present it as GDH’s official census. companyConfirmed stays false until a primary notice or equivalent attestation under our verified-breach policy.

Evidence standards: sale listing vs. confirmed breach

A forum sale demonstrates someone wants buyers to believe they hold GDH-shaped data. It does not prove exfiltration path, completeness, or freshness. Samples can be partial, stitched from older leaks, or fabricated with plausible column names. Independent verification requires GDH or trusted third parties to validate schema, record integrity, and access logs — steps publicly reported as in progress, not completed, at indexing time.

Journalists and OSINT collectors should cite FrenchBreaches, La Marseillaise, and Undercode News rather than republishing raw PII from alleged dumps. Redistribution harms residents and complicates law-enforcement preservation.

Geographic footprint and why locals search “was I affected”

GDH’s public footprint spans multiple départements beyond Vaucluse. Tenants in smaller communes (Mallemort, Pont-Saint-Esprit, etc.) may assume national news will not reach them — yet forum sales are global. Local press already bridged that gap in September; October mica reposts rekindle search interest for Grand Delta Habitat breach 2026 and locataires Vaucluse fuite données. Until GDH publishes cohort criteria (date ranges, services affected), the honest answer to “was I affected?” is: unknown; watch official channels; assume maintenance-themed fraud risk elevated.

Free-text fields: the hidden PII multiplier

Structured columns get privacy reviews; comment threads often do not. A technician noting “tenant uses wheelchair, bathroom leak urgent” converts a billing row into health-adjacent inference. A resident typing door codes or workplace schedules into a request description adds credential-adjacent risk even when passwords were never in scope. That is why intervention exports can hurt more than bare name/address lists — and why data minimization in ticket templates is a security control, not just compliance paperwork.

Third-party and supply-chain angles

Housing landlords integrate electricians, plumbers, elevator vendors, and SaaS portals. FrenchBreaches notes files might originate from a provider tool rather than GDH core ERP — still potentially GDPR-relevant if GDH is controller and personal data describes its tenants. Procurement and DPA teams should ask vendors about export auditing without waiting for confirmation. If the claim fizzles as a hoax, those audits still pay rent.

Comparison to verified social-sector breaches

Verified public-sector and housing incidents elsewhere in 2026 typically progressed from actor noise to company PDF FAQs, sometimes regulator dockets with field enumerations. This GDH story is still in the pre-FAQ phase: serious corporate tone, no attested field list, no replacement offer for identity monitoring unless later announced. Readers should not extrapolate Equifax-scale credit monitoring from a forum screenshot.

Media literacy for residents sharing WhatsApp warnings

Regional Facebook groups amplify unverified leak news faster than bailleurs can draft statements. Sharing actor counts as confirmed facts panics elderly tenants and drives scam calls. Prefer linking official GDH guidance once available; until then, share caution about fraud tactics rather than alleging everyone’s dossier is online.

Technical indicators defenders can hunt (hypothesis-level)

Security teams with no GDH affiliation can still use the claimed schema as a tabletop: Do our work-order exports include occupants_info joins? Are 272 MB dumps emailable? Do contractors download CSVs to unmanaged laptops? Would Dark Web monitors under French housing keywords have fired? Answers improve resilience regardless of mica’s authenticity.

Updates and correction policy

BreachHistory will amend the catalog row and this post if Grand Delta Habitat confirms exposure, publishes corrected counts, or credibly denies authenticity with technical substantiation. We will also update if CNIL or a préfecture-linked process produces a verifiable document tied to this dataset. Until then, every mention of the Grand Delta Habitat data breach in this article remains qualified as an unverified cybercrime forum sale claim tied to actor handles mica / fdp, with 188,010 marketed records and GDH verification ongoing.

Canonical record and authoritative sources

BreachHistory canonical page: https://breachhistory.com/grand-delta-habitat/grand-delta-habitat2026 — relative path /grand-delta-habitat/grand-delta-habitat2026.

Primary open sources used:

No Breachsense links are used. Do not purchase or spread alleged dump contents — report fraud, await verified notice, and re-read the opening sentence: unverified claim.