Skip to content

Lire Demain Database Allegedly Leaked, 5,974 School and Local Authority Client Records Published

Breach Report France flagFrance Publishing / Education Supply Free Download

Lire Demain Database Allegedly Leaked, 5,974 School and Local Authority Client Records Published

A forum user posting as 0xSec has published what they describe as the database of Lire Demain, the schools and institutions network of the French children's publisher Auzou, which supplies books, kamishibai theatres, and educational materials to schools, early years settings, and local authorities. The release comprises five CSV files covering client records, orders, invoices, a mailing list, and a product catalogue. The client file lists 5,974 institutions including middle schools, primary schools, town halls, and local education departments, with named staff contacts, institutional email addresses, telephone and fax numbers, budget dates, and delivery scheduling. A separate 476-line mailing file contains individuals at residential addresses. The data is offered as a free download. The claim is unverified.

Client records5,974
Files5 CSV
PriceFree
Actor0xSec

Post details

TargetLire Demain (Auzou)
CountryFrance flagFrance
SectorPublishing / Education supply
ListingFree — reply to unlock
Clients5,974 institutions
Individuals476 residential records
Observed
Actor0xSec

!Allegedly included

  • Institution names & types
  • Institution addresses
  • Phone & fax numbers
  • Institutional email addresses
  • Named staff contacts
  • Staff email addresses
  • Sales representative names
  • Order records & references
  • Invoice numbers & amounts
  • Payment status & chasing history
  • Budget availability dates
  • Delivery day preferences
  • Individual names & home addresses
  • Product catalogue & pricing

Screenshots

Potential impact

Two points of scope should be established before the risk, because both cut against alarm. This is a small dataset, and the great majority of it is institutional rather than personal: school addresses, switchboard numbers, and academy email addresses are largely public information already. Second, and more importantly given the sector, nothing in the published schema indicates that pupil or child data is present. The client file describes purchasing institutions and their staff contacts, and the product file is a book catalogue. The genuine exposure is commercial fraud against public institutions. Taken together the files provide order references, invoice numbers, amounts, payment status, chasing history, named sales representatives, and the specific staff member responsible for purchasing at each school. That is a complete toolkit for invoice fraud and business email compromise: a fraudulent payment demand quoting a real invoice number, a real order, and the correct representative's name, sent to the person who actually approves it, defeats nearly every check a school office would apply. French schools and local authorities have been recurrent targets of exactly this type of fraud, and the budget availability and closure dates in the client file indicate when institutions are actively spending. The 476 residential records are the clearest personal data in the set and warrant individual notification. One further detail is worth flagging to affected institutions rather than dwelling on: the client file records which days and half-days each site accepts deliveries, which is relevant to premises that manage access to their grounds. The claim is unverified.

iStatus

Unverified

The post includes header rows and record samples from each of the five files, which is more granular substantiation than most listings provide, and the structure is internally consistent with an export from a business management system rather than an assembled list. Dates in the samples run from 2020 to 2026, suggesting either a long-lived dataset or a recent export of historical records. The account has a moderate posting history and standing on the forum. Neither the file contents nor the origin of the data has been independently corroborated. The claim is unverified and neither Lire Demain nor Auzou has publicly addressed it. Schools and local authorities that purchase through the network should be alert to payment requests referencing genuine order or invoice references, and should verify any change of bank details through a known contact route rather than one supplied in the message.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest