Skip to content

YouFid Loyalty Profiles on 1.9 Million French Customers Offered for 1,000 Euros

Breach Report France Loyalty Platform 1,000 EUR

YouFid Loyalty Profiles on 1.9 Million French Customers Offered for 1,000 Euros

A forum user posting as Lagui1337 is selling what they describe as the user database of YouFid, a French customer loyalty platform used by restaurant and retail merchants. The listing gives a precise figure of 1,899,454 rows in JSONL format and, unusually, publishes field fill rates alongside the field list, putting email at around 99 percent, phone at 49 percent, names at 33 percent, dates of birth at 23 percent and street addresses at 0.2 percent. Loyalty specific fields including QR card code, scan count and registration date are stated as complete, with the first merchant visited present on around 87 percent of records. A 1,000 line sample is published. The asking price is 1,000 euros in cryptocurrency. The claim is unverified.

Rows1,899,454
Email fill99%
Price1,000 EUR
ActorLagui1337

Post details

TargetYouFid
CountryFrance
SectorCustomer loyalty
ListingSelling, crypto only
Volume1,899,454 rows
FormatJSONL
Observed
ActorLagui1337

!What the post claims

  • 1,899,454 rows
  • JSONL format
  • First and last names
  • Email addresses
  • Phone numbers
  • Dates of birth
  • Street, city, postal code
  • QR loyalty card codes
  • First merchant visited
  • Number of scans
  • Registration dates
  • Email fill about 99%
  • Phone fill about 49%
  • Name fill about 33%
  • Date of birth fill about 23%
  • Address fill about 0.2%
  • Loyalty fields near complete
  • 1,000 line sample published

Screenshot

Forum post offering the YouFid loyalty database for sale, observed 24 August 2026.

Mapped techniques

The post describes no intrusion method. Both entries are inferred from the artefacts, not stated.

  • Collection T1213 Data from information repositories Inferred A row count to the unit and per field fill rates point to a complete export from a single store rather than a partial or scraped set.
  • Exfiltration T1567 Exfiltration over web service Inferred Samples are distributed through a public paste host. The route out of the environment is not described.

Potential impact

Loyalty data reads as low stakes and is not, because of what sits next to it. There are no passwords and no payment details here, and the address field is effectively empty, so this is not an identity theft set. What it is instead is an almost complete email list of nearly 1.9 million French consumers, half of them with a phone number, and each one attached to the merchant they actually visited and how often they scanned. That combination is what makes it valuable, because a lure referencing the right chain, in French, quoting a real loyalty card code and a plausible points balance is a different proposition to generic spam. The QR card codes being stated as complete is the part worth watching, since loyalty codes are frequently the only thing presented at a till, and if they can be replayed the fraud is against the merchants rather than the customers. The low asking price relative to volume also matters: at this price the data will circulate widely, which usually means it ends up free within months.

iStatus Unverified

The listing is specific in the ways that are cheap to fake and vague in the ways that matter. Publishing per field fill rates is unusual and suggests the actor has actually handled the file, since those numbers are awkward to invent consistently and easy to disprove against the published sample. Against that, no intrusion method is described at all, there is no date for the compromise, and nothing indicates whether the data is current or several years old. The account is new, with a single thread, and the post opens with group branding and bravado rather than evidence. The named restaurant chains are the actor's characterisation of who uses the platform, not a claim that those companies were themselves breached, and should not be read as one. A 1,000 line sample is publicly downloadable and would settle the field question, though Dark Web Informer has not retrieved it and is not linking it, nor the contact address. YouFid has not publicly addressed the claim.

Dark Web Informer // Threat Intelligence

Latest