Unverified claim — August 21, 2026: Dark Web Informer reports that forum actor Knox (forum owner) advertised what they describe as voter data for Iraq’s Independent High Electoral Commission covering about 31 million people and 28 million phone numbers. The commission had not confirmed at indexing. Canonical row: iraq-ihec-knox2026.
Electoral rolls are not “just another government database.” They are how a state knows who you are, where you live, and how to reach you on election day — and in contested regions that combination can become a safety issue, not only a privacy one.
Treat every figure below as an actor-attested, unverified claim until IHEC or Iraqi authorities publish a matching notice.
What the Iraq electoral data breach claim says
According to Dark Web Informer’s August 21 analysis of Knox’s listing, the advertised package covers roughly 31 million people with about 28 million personal phone numbers, offered for sale to “serious buyers only.” The actor claims a breach date of August 2026. Published field categories include:
- Full names
- Voter card numbers
- Family record numbers
- Mothers’ names
- Exact dates of birth
- Province and district of residence
- House numbers
- Registration centre numbers and names
- Registration status flags
- Personal phone numbers
DWI notes the sample looks structurally plausible (Arabic-language records aligning with stated columns) but emphasizes that a sample proves format, not volume. Knox is the forum owner — the “verified” badge on some posts reflects platform status, not independent authentication of 31 million rows.
Why this claim is high-signal even while unverified
Three reasons BreachHistory indexes large unverified government electoral claims when the victim is named and fields are concrete:
- Scale: 31 million is national-census territory for Iraq’s population.
- Irreversibility: Voter card numbers, family record numbers, and mothers’ names are not rotatable like passwords.
- Physical safety: Registration centre fields can imply locality in a country where political affiliation has historically carried violence risk.
That is different from a vague “Middle East gov dump” with no named commission and no field list.
How this compares to the 2019 IHEC row
BreachHistory already catalogs iraq-ihec2019 (~24.3M records in legacy metadata). The August 2026 Knox claim is a separate listing with a distinct actor, stated August 2026 timing, and a richer public field inventory (mother’s name, registration centres, phone density). Do not merge them without commission confirmation — either could be recycled material, a partial re-pack, or an unrelated hoax.
What we do not know
IHEC had not issued a public statement matching this Knox listing at indexing. No independent journalist had published dump authentication at the scale cited. The intrusion path (SQLi, insider, backup exposure, supplier) was not described in the DWI summary. BreachHistory sets recordsAffected at 31000000 as the actor people-count and keeps companyConfirmed: false.
Who is at risk if the dump is real
Registered voters across Iraqi provinces — especially those whose registration centre and house number appear together. Diaspora voters who maintained Iraqi registration. Family members referenced via mothers’ names in identity-verification flows used by banks and telecoms in the region. Political organizers and candidates whose registration status flags could be mined for targeting. Even people who last interacted with IHEC years ago may appear if rolls retain history.
Identity fraud and SIM-swap context
Mother’s name plus exact date of birth plus official card number is the classic triad for answering knowledge-based authentication questions at banks and mobile operators. Pair that with 28 million phone numbers and you have the ingredients for SIM-swap and account-recovery fraud at scale — without needing card numbers.
Registration centre names add geographic precision beyond province alone. Attackers can craft SMS in Arabic that cite a voter’s local centre and a plausible election-administrative pretext. That is more convincing than generic “your account is locked” spam.
What IHEC and Iraqi authorities have said
As of BreachHistory indexing on August 22, 2026, no matching IHEC press release or electoral-authority FAQ was located in sources reviewed. Watch for statements from IHEC, the Iraqi Communications and Media Commission, or international election-observation bodies. Confirmation would move this row from unverified toward verified and may revise the count.
Action items for Iraqi citizens and diaspora
- Treat unexpected SMS or WhatsApp messages citing your voter card number or registration centre as hostile until verified through official IHEC channels.
- Enable SIM PINs and carrier account locks where available; SIM swap is the fastest path from phone + KBV data to account takeover.
- Do not download alleged voter dumps from forums “to check if you’re in them.”
- Monitor bank and mobile-wallet accounts for recovery attempts you did not initiate.
- If you are a journalist or NGO worker covering elections, review physical security assumptions — leaked centre + address fields can aid surveillance.
- Ignore Telegram bots offering “IHEC leak lookup” — they are often secondary scams or malware.
- Keep the Dark Web Informer URL as chronology; do not treat Breachsense-style aggregators as primary sources.
- If IHEC later mails or SMSes voters, verify domains and call published commission numbers — not numbers in the message.
Phishing patterns to expect after an electoral headline
Even before confirmation, regional fraud operators piggyback on breach news. Expect messages claiming: “Your voter registration is suspended after the cyberattack — re-verify here,” or “Election commission refund / stipend — submit ID.” Real commissions rarely collect full card numbers over chat apps.
Arabic-language lures that spell your province and district correctly are especially dangerous. That specificity comes from leaked rows, not from mass spam. Slow down when a message feels “too accurate.”
For election administrators and OSCE-style observers
If you work with IHEC or provincial registration offices, treat August 21 as a tabletop exercise regardless of confirmation. Map which systems export full rolls, who receives daily backups, whether phone numbers belong in the same table as mother’s name fields, and how you would notify 31 million people if a census-class export left the building.
Minimize retention of mother’s name in online-facing systems if offline verification suffices. Segment exports so a single FTP misconfiguration cannot ship the entire country.
How BreachHistory will update this story
We will revise iraq-ihec-knox2026 if IHEC confirms, denies, or publishes a smaller attested census; if reputable trade press authenticates samples against live rolls; or if regulators issue formal notices. Until then, search results for “Iraq voter data breach 2026” or “IHEC leak” should keep the unverified label in the first screen.
Researchers comparing this claim to other 2026 government dumps — Bolivia health intern claims, Santa Cruz food-handler listings — should note the same actor-handle caution: similar targeting patterns are not proof.
Bottom line: a named national electoral commission, 31 million people cited, mothers’ names and phone numbers in the alleged schema — and zero public confirmation at indexing. The honest summary for readers is unverified but serious; prepare for KBV/SIM fraud either way.
Diaspora voters who maintain Iraqi mobile numbers should prioritize carrier security even if they have not lived in-country for years. Leaked rolls do not respect borders when your phone still rings in Amman or London.
Human-rights documenters should avoid republishing sample rows with real names and mothers’ names. Describing field categories is enough. Amplifying identifiable electoral records endangers individuals more than it informs the public.
If Knox’s listing is recycled 2019 material re-dated to August 2026, IHEC confirmation will collapse the count quickly. If it is fresh, notification timelines may lag weeks. Do not wait for a polished FAQ to harden SIM and banking recovery paths.
International partners funding Iraqi election infrastructure should ask implementers — in writing — whether full-roll exports to suppliers occur, and whether phone numbers must sit in the same database as family record numbers. Supplier-chain failures mirror the French retail misere threads cataloged the same week.
Finally, do not confuse this IHEC claim with unrelated “Iraq” forum dumps that lack a named commission and field list. BreachHistory indexes named victims with attested or clearly labeled actor claims. Anonymous “Middle East voter DB” posts stay out.
For searchers landing from “IHEC data breach 2026”: unverified Knox claim, ~31M people / ~28M phones alleged, commission silent at indexing, canonical record linked above, and practical steps focus on SIM/banking recovery fraud — not password rotation alone.
Political parties and civil-society groups should warn members that accurate voter-registration phishing may follow. Use official IHEC channels only. Document any suspicious contact for commission cyber units if they publish a reporting line.
Security vendors marketing “IHEC breach dark web monitoring” should be treated skeptically until sample authenticity and scope are established. Paid upsells based on unverified forum posts are a secondary scam category in every breach news cycle.
Compare scale to 2019 IHEC only as historical context — not as proof this dump exists. Two large numbers in the same catalog does not mean one incident.
If confirmation arrives, this blog will be updated and the catalog row’s companyConfirmed flag will move with primary-source citations. Until then, lead every paragraph with unverified where counts appear.
Why mother’s name fields change the fraud calculus
In many Middle Eastern banking and telecom flows, “mother’s maiden name” is not trivia — it is a verification answer. When it sits beside a government-issued voter card number, a family record number, and an exact date of birth, an attacker can pass automated and human KBV checks without ever stealing a password. That is why electoral dumps rank above generic email lists for downstream account takeover risk even when no payment cards appear.
Phone numbers at 28 million scale turn the same rows into a SIM-swap pipeline. Carrier shops in busy markets process walk-ins and call-center resets daily. A fraudster with accurate biographics and a recent phone match can social-engineer a replacement SIM faster than most victims notice their bars disappeared.
Registration centres and locality precision
Province and district alone are coarse. Registration centre numbers and names are fine-grained — they tell an adversary which neighborhood’s rolls you appear on. In disputed or high-tension areas, that granularity can inform harassment, intimidation, or targeted messaging designed to suppress turnout. Even absent malice, journalists and activists whose registration metadata leaks may need to reassess public meeting locations and home routines.
House number fields, when populated, complete a postal-style address skeleton. Combined with full name and phone, they approach directory precision without needing a separate cadastral database.
What responsible disclosure looks like
If IHEC confirms, expect phased notices: press statement, FAQ on whether phone numbers were stored with voter rolls, guidance on SIM locks, and possibly coordination with major carriers. If they deny, ask whether the sample is recycled 2019 material — Knox’s listing must be tested against that hypothesis, not assumed authentic because the count is large.
International election-assistance NGOs should avoid amplifying unverified row counts in fundraising mail the same week the claim drops. Hype helps nobody on the ground.
Technical questions security teams should ask vendors
Did any CRM, SMS gateway, or biometric voter-registration vendor receive full-roll exports? Were exports encrypted at rest on intermediary FTP or cloud buckets? Who had keys? Were phone numbers segmented from family record numbers in the schema, or co-located for convenience? Were mother’s name fields mandatory online or only captured at registration desks? Answers matter for scope even before a public count exists.
Compare to supplier-chain failures cataloged the same week in France — Bureau Vallée and Beauty Success misere threads allege daily third-party exports to exposed hosts. Electoral commissions face the same vendor-trust problem at national scale.
Media and OSINT hygiene
Do not geolocate individuals from alleged sample rows on live maps in YouTube explainers. Do not publish mothers’ names paired with sons’ or daughters’ full names from screenshots. Redact aggressively. The public interest is served by describing categories and scale, not by turning forum marketing into doxxing fuel.
Searchers comparing “Iraq data breach 2026” results should prefer primary commission channels and reputable wire services over copy-paste blogs that omit the unverified label in the title.
Carriers should pre-brief retail shops on elevated SIM-swap attempts after electoral breach headlines — even for unverified claims. The social-engineering scripts arrive before confirmation.
Finally, remember Knox also appeared on other high-sensitivity listings recently (including hospital imaging claims elsewhere in the catalog). Actor reuse is a research clue, not corroboration. Each row stands on its own evidence bar.
Diaspora community organizations can help by publishing one-page guides in Arabic and Kurdish on how to spot fake “voter re-registration” sites — official domains only, no attachments. That work helps even if the Knox dump is never confirmed, because the phishing template will spread anyway.
Law firms preparing class actions should wait for IHEC statements before soliciting clients with precise counts. Early complaint marketing based on forum actor math has burned plaintiffs’ counsel before in other jurisdictions.
BreachHistory indexes iraq-ihec-knox2026 with companyConfirmed: false and recordsAffected: 31000000 as the actor people floor. Updates will follow primary sources only.
Until IHEC speaks, the practical reader checklist is short: lock your SIM, distrust accurate-sounding election SMS, never read KBV answers to inbound callers, and treat 31 million as an unverified actor number — not a commission census. Share this page with family abroad who may be targeted by English-language WhatsApp forwards before official Arabic notices arrive. Bookmark the canonical breach record and check back only after official commission statements.