Journaux.fr Delivery Records Shared Alongside an Unpatched Credit Flaw
A forum actor posting as Alduin has published what they describe as the billing data of journaux.fr, a French site selling newspapers and magazines by issue or subscription in print and digital form. The release is given as JSONL covering roughly 270,000 records, containing paired delivery and billing details: names, street addresses, building and additional address lines, postcodes, cities, countries, company names where present, and order identifiers. Alongside the data, the post publishes an API request the actor says lets an authenticated customer set their own account credit balance up to a stated ceiling. Dark Web Informer is not reproducing that request. The claim is unverified.
▣Post details
!What the post claims
- 270,000 records
- JSONL format
- Stated size of 184 KB
- Delivery names
- Delivery addresses
- Building and complement lines
- Postcodes and cities
- Delivery country
- Billing names
- Billing addresses
- Company names where present
- Salutation codes
- VAT fields
- Order identifiers
- Requested order identifiers
- An API flaw disclosed openly
- Account credit said to be settable
- A stated ceiling on the amount
◱Screenshot
☷Mapped techniques
Mapped from the actor's own account. Claimed, not confirmed.
- Initial access T1190 Exploit public facing application Inferred The actor demonstrates detailed knowledge of the site's API and of at least one endpoint that fails to check authorisation, which is a plausible route to the records as well.
- Collection T1213 Data from information repositories Inferred Paired delivery and billing objects with sequential order identifiers suggest records pulled in bulk rather than one account at a time.
- Impact T1657 Financial theft Stated The published request, if it works as described, allows an account holder to grant themselves store credit and obtain goods without paying for them.
⚠Potential impact
The records themselves are ordinary as personal data goes. Names and delivery addresses for a few hundred thousand French households, with no passwords, no card numbers and no account credentials. The realistic harm is targeted postal and telephone fraud, helped along by the fact that a subscription address is a confirmed, currently occupied delivery address rather than a form field somebody typed once. The more pressing problem belongs to the company. If the published request behaves as described, any account holder can grant themselves store credit, which is straightforward theft of goods and is now public, unpatched and trivially repeatable by anyone reading the thread. That flaw also reframes the leak, because an API that fails to check who is authorised to change a balance may well be failing to check who is authorised to read other people's orders, which would explain how the records were obtained without any conventional intrusion. For the retailer this is an incident response matter measured in hours rather than days.
iStatus Unverified
There is an arithmetic problem worth resolving before anyone reports the headline figure. The post claims roughly 270,000 records but gives the file size as 184 KB, and each record in the sample runs to several hundred bytes across two address blocks. A file of that size holds a few hundred records of this shape, not a quarter of a million, so either the size refers to a sample, the file is compressed, or the record count is wrong. The sample content is otherwise convincing, with real French postcodes matched to the correct communes and the ragged mixture of blank and populated fields that genuine order data carries. The account is recent, created within the last two months, with few posts and a purchased forum rank, so its standing carries little weight. Distribution is free, so no price is being defended. Dark Web Informer has not retrieved the file and is not linking it, and is not reproducing the API request. Journaux.fr has not publicly addressed the claim.
Dark Web Informer // Threat Intelligence