> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Comptoir de Location Data Published as the Fourteenth Leak From One Platform
- URL: https://darkwebinformer.com/comptoir-de-location-data-published-as-the-fourteenth-leak-from-one-platform/
- Published: 2026-08-26T17:35:03.000Z
- Updated: 2026-08-26T17:35:03.000Z
- Author: Dark Web Informer
- Tags: Leaks

Breach Report France Equipment Rental Published Free 

## Comptoir de Location Data Published as the Fourteenth Leak From One Platform

A forum actor posting as **NikolaT** has published what they describe as the database of **Comptoir de Location**, a French company renting equipment to the construction, public works, materials handling and industrial sectors, giving a size of **13.48 GB across 323,388 files**. This is the **fourteenth entry in a running series drawn from a shared platform the actor calls BlgCloud**, and it lands on **exactly the target named in advance two days ago**. Samples again cover three layers: **CRM records with company details and credit terms, document metadata for invoices, work orders and conformity certificates, and staff user accounts**. A fifteenth target has been named. The data is **not for sale**. The claim is **unverified**.

Severity HIGH 

[ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) 

Size13.48 GB

Files323,388

SeriesLeak 14

ActorNikolaT

### ▣Post details

TargetComptoir de Location

CountryFrance

SectorEquipment rental

ListingFree, reply to unlock

Volume13.48 GB, 323,388 files

Stated sourceShared platform

ObservedAug 26, 2026

ActorNikolaT

### !What the post claims

- 13.48 GB of data
- 323,388 files
- Fourteenth in the series
- Fifteenth target announced
- CRM company records
- Registered addresses
- Company and VAT numbers
- Site coordinates
- Bank account fields
- Payment terms and limits
- Solvency and tariff codes
- Invoices and work orders
- Conformity certificates
- Stored file hashes and paths
- Staff user accounts
- Corporate email addresses
- Access and reset timestamps
- Password fields empty in sample

### ◱Screenshots

[ ![Forum post publishing data attributed to Comptoir de Location as the fourteenth in a series of platform leaks, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/79826359782635978623598762398572987635987.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/79826359782635978623598762398572987635987.png) [ ![Second section of the same post covering document metadata and user accounts, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/79826359782635978623598762398572987635988.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/79826359782635978623598762398572987635988.png) 

Forum post publishing Comptoir de Location data, observed 26 August 2026.

### ☷Mapped techniques

Mapped from the actor's own account. Claimed, not confirmed.

- Initial access [T1199](https://attack.mitre.org/techniques/T1199/) Trusted relationship Stated The data is attributed to a shared platform serving many companies. The samples contain the platform vendor's own administrative and support records sitting inside the customer's data, which is consistent with a multi tenant system.
- Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Stated CRM objects, document records and user tables are exported together from one application, in the same shape as the previous entry in the series.
- Collection [T1530](https://attack.mitre.org/techniques/T1530/) Data from cloud storage Inferred Document entries carry storage paths and file hashes, and 323,388 files far exceeds what a database export alone would produce.
- Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Distribution is through forum hosted links. The route out of the environment is not described.

### ⚠Potential impact

As with the previous entry, the exposure runs **outward from the named company into its trading network**. The CRM layer here is richer than usual because equipment rental is a credit business: alongside addresses and company numbers sit **payment terms, outstanding balance limits, solvency classifications and tariff codes** for named customer firms. That is **commercially sensitive information about third parties** who never dealt with the platform themselves, useful to a competitor and useful to anyone assessing which contractors are financially stretched. The document layer supplies the raw material for invoice fraud, with real work orders, invoices and conformity certificates to quote from, and construction sector payment chains are already a favourite target for that. The most important point remains the series. The actor **named this company as the next target two days ago and has now delivered it**, which moves the shared platform claim from assertion toward pattern. Every other client of that platform should be treating this as a live matter, and the company named for the fifteenth release has **a short and quantifiable amount of warning**.

### iStatus Unverified

The single most significant development here is that **a prediction was made and then met**. Leak thirteen named this company as the next target, and leak fourteen is that company, on schedule and in the same format. That does not prove the platform account is correct, but it does demonstrate **knowledge of which companies are reachable before they are published**, which is difficult to explain if the data were assembled from unrelated sources. The samples support the same reading, since **the platform vendor's own support and administrative entries appear inside this customer's records**, exactly as they would in a multi tenant system. Still absent is any account of **how the access was obtained**, and the platform itself has no obvious public footprint under the name used. Distribution is free, so there is no price to defend, though a numbered series builds standing. Dark Web Informer has **not retrieved the files and is not linking them**. Neither the company nor any platform provider has publicly addressed the series.

Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=comptoir-de-location-2026-08-26&utm%5Fcontent=threat-feed) and search there for this alert.

[View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=comptoir-de-location-2026-08-26&utm%5Fcontent=pricing-button) 

[Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=comptoir-de-location-2026-08-26&utm%5Fcontent=footer) // Threat Intelligence