Comptoir de Location Data Published as the Fourteenth Leak From One Platform
A forum actor posting as NikolaT has published what they describe as the database of Comptoir de Location, a French company renting equipment to the construction, public works, materials handling and industrial sectors, giving a size of 13.48 GB across 323,388 files. This is the fourteenth entry in a running series drawn from a shared platform the actor calls BlgCloud, and it lands on exactly the target named in advance two days ago. Samples again cover three layers: CRM records with company details and credit terms, document metadata for invoices, work orders and conformity certificates, and staff user accounts. A fifteenth target has been named. The data is not for sale. The claim is unverified.
▣Post details
!What the post claims
- 13.48 GB of data
- 323,388 files
- Fourteenth in the series
- Fifteenth target announced
- CRM company records
- Registered addresses
- Company and VAT numbers
- Site coordinates
- Bank account fields
- Payment terms and limits
- Solvency and tariff codes
- Invoices and work orders
- Conformity certificates
- Stored file hashes and paths
- Staff user accounts
- Corporate email addresses
- Access and reset timestamps
- Password fields empty in sample
◱Screenshots
☷Mapped techniques
Mapped from the actor's own account. Claimed, not confirmed.
- Initial access T1199 Trusted relationship Stated The data is attributed to a shared platform serving many companies. The samples contain the platform vendor's own administrative and support records sitting inside the customer's data, which is consistent with a multi tenant system.
- Collection T1213 Data from information repositories Stated CRM objects, document records and user tables are exported together from one application, in the same shape as the previous entry in the series.
- Collection T1530 Data from cloud storage Inferred Document entries carry storage paths and file hashes, and 323,388 files far exceeds what a database export alone would produce.
- Exfiltration T1567 Exfiltration over web service Inferred Distribution is through forum hosted links. The route out of the environment is not described.
⚠Potential impact
As with the previous entry, the exposure runs outward from the named company into its trading network. The CRM layer here is richer than usual because equipment rental is a credit business: alongside addresses and company numbers sit payment terms, outstanding balance limits, solvency classifications and tariff codes for named customer firms. That is commercially sensitive information about third parties who never dealt with the platform themselves, useful to a competitor and useful to anyone assessing which contractors are financially stretched. The document layer supplies the raw material for invoice fraud, with real work orders, invoices and conformity certificates to quote from, and construction sector payment chains are already a favourite target for that. The most important point remains the series. The actor named this company as the next target two days ago and has now delivered it, which moves the shared platform claim from assertion toward pattern. Every other client of that platform should be treating this as a live matter, and the company named for the fifteenth release has a short and quantifiable amount of warning.
iStatus Unverified
The single most significant development here is that a prediction was made and then met. Leak thirteen named this company as the next target, and leak fourteen is that company, on schedule and in the same format. That does not prove the platform account is correct, but it does demonstrate knowledge of which companies are reachable before they are published, which is difficult to explain if the data were assembled from unrelated sources. The samples support the same reading, since the platform vendor's own support and administrative entries appear inside this customer's records, exactly as they would in a multi tenant system. Still absent is any account of how the access was obtained, and the platform itself has no obvious public footprint under the name used. Distribution is free, so there is no price to defend, though a numbered series builds standing. Dark Web Informer has not retrieved the files and is not linking them. Neither the company nor any platform provider has publicly addressed the series.
Dark Web Informer // Threat Intelligence