France
E-commerce / Renewable Energy
Free Download
Allo.Solar Database Allegedly Leaked, 101,349 French Customers and 208,000 Solar Equipment Orders Exposed
A forum user posting as ChimeraZ has published what they describe as the database of Allo.Solar, a French e-commerce platform selling photovoltaic and renewable energy equipment. The post claims 208,694 order lines covering 101,349 individuals, released as a 222MB JSON file. The posted sample shows full names, phone numbers, street addresses, cities, and postcodes for both billing and delivery parties, together with order totals, payment method, the processor used, the last four digits of the payment card, and complete itemised contents of each order down to product references, quantities, and prices. The actor claims the intrusion occurred roughly two weeks ago and explicitly frames the release around the wildfire emergency in Gironde. The data is offered as a free download. The claim is unverified.
▣Post details
France!Allegedly included
- Full names
- Phone numbers
- Street addresses
- Cities & postcodes
- Separate delivery addresses
- Order identifiers
- Order totals (incl. tax)
- Payment method & processor
- Card last four digits
- Itemised product lists
- Product references & codes
- Quantities & unit prices
- Delivery charges
- Country of order
◱Screenshot
⚠Potential impact
No passwords or full card numbers appear in the sample, so account takeover and direct card fraud are not the primary concerns. What this dataset does instead is describe a property. An itemised solar order identifies a specific address as holding a photovoltaic installation, names the components, and states what was paid, which in the sample runs to several thousand euros for a single order. That is an inventory of valuable, resaleable, externally mounted equipment tied to a street address and a working phone number, and solar hardware theft is an established problem across Europe. The same combination is close to ideal for fraud aimed at homeowners: France already has a persistent problem with fraudulent solar sales and maintenance approaches, and a caller who can cite a customer's real installer, actual components, order value, and card last four digits has defeated nearly every check a householder would apply. The timing raises a further concern that cannot be separated from the data. Gironde and neighbouring Landes are currently subject to the largest peacetime evacuation in modern French history, with hundreds of thousands of residents displaced. Publishing residential addresses annotated with high-value equipment, into a population that includes households who may be away from their homes under evacuation orders, carries an obvious risk irrespective of what the actor intended. The separate delivery addresses compound this by distinguishing where equipment was installed from where the buyer is billed. The claim is unverified.
iStatus
UnverifiedThe post includes a full record sample and places the download behind a reply gate, with the actor stating they hold no Telegram presence and are contactable only via an encrypted messenger, which Dark Web Informer is not reproducing. The actor claims access was obtained around two weeks before publication and directly attributes the timing of the release to the Gironde wildfires, using language that treats the emergency as an opportunity. That framing is the actor's own. The account is established on the forum with a substantial posting history and elevated standing. Neither the record count nor the dataset has been independently corroborated. The claim is unverified and Allo.Solar has not publicly addressed it. Customers should be aware that unsolicited contact referencing their installation, however accurate the details, may originate from this data rather than from the retailer.
DARK WEB INFORMER - THREAT INTELLIGENCE