> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Actor Claims to Leak 6.2 Million Relais Colis Records
- URL: https://darkwebinformer.com/actor-claims-to-leak-6-2-million-relais-colis-records/
- Published: 2026-09-24T17:16:41.000Z
- Updated: 2026-09-24T17:16:41.000Z
- Author: Dark Web Informer
- Tags: Leaks

Data Exposure Report France Dataset Leak Contact Data Sample Shown Unverified 

## Actor Claims to Leak 6.2 Million Relais Colis Records

Count in post title6M

Lines claimed in body6.2M

Lines listed above sample12.98M

Download destinationHidden

Severity HIGH 

### Overview

An actor using the handle **"RandomRussian"** claims to have released a dataset associated with **Relais Colis**, a [parcel delivery service](https://aide.relaiscolis.com/hc/fr/articles/12438102077725-Comment-envoyer-un-colis). The French-language post describes **6.2 million lines containing email addresses, phone numbers and other personal data**, while its title uses a rounded figure of 6 million.

The visible sample contains **names, mobile numbers and location fields**, with street addresses and email addresses in some entries. A separate heading lists **12,976,743 lines**. The poster frames the release as a dispute with another actor, credits **"Miaouriarty"** and denies carrying out the original scraping. **The dataset's origin, authenticity, scale and connection to a compromise of Relais Colis have not been independently verified.**

### Post details

OrganizationRelais Colis

Country France

SectorParcel delivery and logistics

Posting actor"RandomRussian"

Credited handle"Miaouriarty"

Claimed volume6.2M lines in body; 12,976,743 above sample

Download visibilityHidden until a reply is posted

Post date shownSep 24, 2026

### What the post claims

- Dataset associated with Relais Colis claimed released
- 6 million referenced in the title
- 6.2 million lines claimed in the body
- 12,976,743 lines listed above the sample
- First and last name fields visible
- Mobile phone number fields visible
- Email addresses in some sample entries
- Street addresses in some sample entries
- Postal codes and city fields
- Department, region and country fields
- FR country values in the sample
- Record IDs prefixed with relaiscolis.com
- Poster promotes the data for spam
- Poster denies performing the original scraping
- Another dataset release promised
- Download content hidden behind a reply requirement

The sample alternates **index metadata and personal-data objects**. A raw line count therefore cannot be read as a count of unique people. The visible material does not reconcile the different totals, establish deduplication or prove that every entry contains every field. **No asking price is visible.**

Sponsored

[ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel)

### Screenshots

[Screenshot 1Source screenshot![Relais Colis dataset leak claim showing conflicting line counts, a personal-data sample, Telegram references and a hidden download area](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/937285628379645987263598726359872.png) ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/937285628379645987263598726359872.png) 

Supplied screenshot showing the release claim, differing line counts, sample field structure and Telegram references. The download destination is hidden.

### IOCs & contact identifiers

Identifiers visible in the supplied screenshot. Attribution and contact references are recorded separately; they do not establish shared ownership or prove compromise.

| Type                      | Identifier          | Source                           |
| ------------------------- | ------------------- | -------------------------------- |
| Posting actor             | RandomRussian       | Screenshot 1, author             |
| Credited handle           | Miaouriarty         | Screenshot 1, body               |
| Telegram reference        | @deepf3nd           | Screenshot 1, body               |
| Telegram reference        | @datareaperfr       | Screenshot 1, signature          |
| Named organization domain | relaiscolis\[.\]com | Screenshot 1, sample ID prefixes |

The domain identifies the organization named in the claim, not malicious infrastructure. No Tox ID, Session ID, malware hash or attacker-controlled IP address is visible. Customer identifiers shown in the purported evidence are not included in this table. The Telegram references have not been verified as accounts controlled by the poster. URLs to any data will always be blurred out, but are available to subscribers on the threat feed or ransomware feed.

### Mapped techniques

**Claimed** identifies behavior explicitly described by the actor. **Inferred** identifies an analytical mapping supported by the supplied material. Neither label means the activity has been independently verified.

- Reconnaissance [T1589.002](https://attack.mitre.org/techniques/T1589/002/) [Gather Victim Identity Information: Email Addresses](https://attack.mitre.org/techniques/T1589/002/) Inferred The actor claims to hold and share a large contact dataset, shows email fields in the sample and promotes the data for spam. This supports an inferred mapping to gathering email addresses for targeting. The original acquisition method and any subsequent targeting activity are not established.

### Potential impact

If authentic, the combination of **names, mobile numbers, email addresses and location data** could support spam, targeted phishing, SMS delivery scams and impersonation. Street addresses could add personal context to fraudulent parcel or redelivery messages. The poster explicitly promotes the data for spam, but the screenshot does not demonstrate an active campaign. **The stated line counts do not establish the number of distinct affected people.**

### Status Unverified

Dark Web Informer has **not independently verified** the dataset, its age, ownership, completeness or record count. A visible sample and domain-prefixed record IDs do not establish that Relais Colis systems were compromised. The differing volume claims remain unresolved, and the screenshot does not show how the data was collected or whether it is new, recycled or combined from other sources. The hidden download was not accessed. No company confirmation or independent technical evidence of a breach is included in the supplied material.

Want everything on this threat? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=relais-colis-dataset-leak-2026-09-24&utm%5Fcontent=threat-feed) and search there for this alert.

[View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=relais-colis-dataset-leak-2026-09-24&utm%5Fcontent=pricing-button) 

[Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=relais-colis-dataset-leak-2026-09-24&utm%5Fcontent=footer)