France
Business Software / Agriculture
Free Download
Chupin Data Allegedly Leaked in Sixth Release Targeting Tenants of a Shared Business Platform
A forum user posting as ChimeraZ has published what they describe as the database of Chupin, a French dealer in agricultural equipment, spare parts, and garden machinery, comprising 16GB across 70,974 files. The release is labelled as the sixth in a numbered series, and identifiers throughout the samples point to a shared business management platform as the common origin rather than six separate company compromises. The material spans full email content, CRM contact records with addresses and coordinates, and financial documents including invoices. The actor has publicly named their next target, another French equipment retailer, for release the following day. The claim is unverified.
▣Post details
France!Allegedly included
- Full email message content
- Sender and recipient details
- Email attachments
- CRM contact records
- Business and personal names
- Postal addresses
- Geographic coordinates
- Contact email addresses
- Company relationships
- Account credentials fields
- Banking detail fields
- Invoices and PDFs
- Document file hashes
- Internal reference codes
◱Screenshot
⚠Potential impact
This is predominantly business rather than consumer data, which limits the mass privacy harm, but the composition is unusually complete for a single company. Full email content exposes commercial terms, pricing, and supplier and customer correspondence, while the CRM records tie named contacts to addresses with precise coordinates, and the document set includes invoices. Together these support invoice fraud and business email compromise against the company and its trading partners, since a fraudulent demand can quote genuine references and correspondence. The more consequential point is structural: the numbering and platform identifiers indicate other tenants of the same provider face the same exposure, with releases continuing on a stated schedule.
iStatus
UnverifiedSamples are published from three distinct systems and are internally consistent with a genuine platform export. Platform identifiers appear inside records belonging to the named company, which suggests a single upstream compromise rather than six unrelated ones, though the provider has not been confirmed as the source. Dark Web Informer is not reproducing the download location or contact route. The same actor published an unrelated French database weeks earlier. The claim is unverified and neither Chupin nor the platform operator has publicly addressed it.
DARK WEB INFORMER - THREAT INTELLIGENCE