France
Publishing / Education Supply
Free Download
Lire Demain Database Allegedly Leaked, 5,974 School and Local Authority Client Records Published
A forum user posting as 0xSec has published what they describe as the database of Lire Demain, the schools and institutions network of the French children's publisher Auzou, which supplies books, kamishibai theatres, and educational materials to schools, early years settings, and local authorities. The release comprises five CSV files covering client records, orders, invoices, a mailing list, and a product catalogue. The client file lists 5,974 institutions including middle schools, primary schools, town halls, and local education departments, with named staff contacts, institutional email addresses, telephone and fax numbers, budget dates, and delivery scheduling. A separate 476-line mailing file contains individuals at residential addresses. The data is offered as a free download. The claim is unverified.
▣Post details
France!Allegedly included
- Institution names & types
- Institution addresses
- Phone & fax numbers
- Institutional email addresses
- Named staff contacts
- Staff email addresses
- Sales representative names
- Order records & references
- Invoice numbers & amounts
- Payment status & chasing history
- Budget availability dates
- Delivery day preferences
- Individual names & home addresses
- Product catalogue & pricing
◱Screenshots
⚠Potential impact
Two points of scope should be established before the risk, because both cut against alarm. This is a small dataset, and the great majority of it is institutional rather than personal: school addresses, switchboard numbers, and academy email addresses are largely public information already. Second, and more importantly given the sector, nothing in the published schema indicates that pupil or child data is present. The client file describes purchasing institutions and their staff contacts, and the product file is a book catalogue. The genuine exposure is commercial fraud against public institutions. Taken together the files provide order references, invoice numbers, amounts, payment status, chasing history, named sales representatives, and the specific staff member responsible for purchasing at each school. That is a complete toolkit for invoice fraud and business email compromise: a fraudulent payment demand quoting a real invoice number, a real order, and the correct representative's name, sent to the person who actually approves it, defeats nearly every check a school office would apply. French schools and local authorities have been recurrent targets of exactly this type of fraud, and the budget availability and closure dates in the client file indicate when institutions are actively spending. The 476 residential records are the clearest personal data in the set and warrant individual notification. One further detail is worth flagging to affected institutions rather than dwelling on: the client file records which days and half-days each site accepts deliveries, which is relevant to premises that manage access to their grounds. The claim is unverified.
iStatus
UnverifiedThe post includes header rows and record samples from each of the five files, which is more granular substantiation than most listings provide, and the structure is internally consistent with an export from a business management system rather than an assembled list. Dates in the samples run from 2020 to 2026, suggesting either a long-lived dataset or a recent export of historical records. The account has a moderate posting history and standing on the forum. Neither the file contents nor the origin of the data has been independently corroborated. The claim is unverified and neither Lire Demain nor Auzou has publicly addressed it. Schools and local authorities that purchase through the network should be alert to payment requests referencing genuine order or invoice references, and should verify any change of bank details through a known contact route rather than one supplied in the message.
DARK WEB INFORMER - THREAT INTELLIGENCE