Skip to content

A French GDPR Compliance Provider's Client Records Shared on a Forum

Breach Report France GDPR Compliance Shared Free

A French GDPR Compliance Provider's Client Records Shared on a Forum

A forum user posting as 0xSec has published what they describe as the database of metabase.dipeeo.fr. Dipeeo is a French company that supplies outsourced Data Protection Officers and compliance software to organisations subject to the GDPR. The release is eleven JSON collections covering client company accounts, named legal officers, user accounts with roles and a password field, subcontractor registers with audit status, data processing analyses, and trust centre client lists and visitor requests. No record counts are given and no data sample is published, only the field structure of each collection. The files are unlocked for a nominal forum fee. The claim is unverified.

CollectionsEleven
FormatJSON
RecordsNot stated
Actor0xSec

Post details

Targetmetabase.dipeeo.fr
CountryFrance
SectorCompliance services
ListingNominal forum fee
VolumeNot stated
FormatJSON, eleven files
Observed
Actor0xSec

!What the post claims

  • Eleven JSON collections
  • No record counts given
  • No data sample published
  • Client company accounts
  • Named legal officers
  • Legal officer emails
  • Commercial contacts
  • Employee counts
  • Drive and calendar links
  • Accounting platform references
  • User accounts and roles
  • Password field present
  • Phone numbers and last login
  • Subcontractor registers
  • Subcontractor contacts
  • Audit status and history
  • Data processing analyses
  • Trust centre visitor requests

Screenshots

Forum post publishing Dipeeo data, observed 25 August 2026.

Mapped techniques

The post describes no intrusion method. All entries are inferred from the artefacts, not stated.

  • Initial access T1190 Exploit public facing application Inferred The named host is a business intelligence front end rather than the product itself. Self hosted instances of that software have carried pre authentication flaws, which makes an internet reachable analytics tool a plausible route. This is inference from the hostname alone.
  • Collection T1213 Data from information repositories Inferred Eleven collections exported together, including migration and audit logs, indicates whole database access rather than a targeted query.
  • Exfiltration T1567 Exfiltration over web service Inferred Distribution runs through forum hosting behind a points wall. The route out of the environment is not described.

Potential impact

The obvious point is that a company selling GDPR compliance has been named in a data leak. The more useful point is what a compliance provider's database actually contains, which is not really its own data but a structured record of its clients' weaknesses. Subcontractor registers list which vendors each client organisation uses and which of those relationships were audited, rejected, or left unresolved. Processing analyses record what was assessed and what failed. Read across all clients, that is a map of where personal data sits in dozens of organisations and which of those handovers nobody has checked, which is exactly the reconnaissance an attacker would otherwise spend months building. The account records name the legal officer for each client with their direct email, and a message from a company's own DPO asking for records is close to the most credible pretext available in a European organisation. Two further items deserve checking against the files themselves: the password field in the user collection, whose storage format is not shown, and the links to external drive, calendar and accounting platforms, which matter a great deal more if any credential or token accompanies them.

iStatus Unverified

This post is weaker on evidence than the same actor's earlier one today. There are no record counts, no file sizes and, most importantly, no sample rows at all, only field names. Field structure is genuinely hard to invent convincingly, and the naming here is coherent across eleven collections in a way that suggests a real document database was examined, but structure alone shows a schema was seen rather than that any data was taken. No intrusion method, date or access route is given. The account is established, with a long history and a paid rank, and this is its second French target published within an hour, which suggests either a productive run or a backlog being released. Dark Web Informer has not retrieved the files and is not linking them. Dipeeo has not publicly addressed the claim. Given the nature of the business, any client organisation named in these files would have its own notification obligations to consider.

Dark Web Informer // Threat Intelligence

Latest