> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Zenfirst Dataset Claim Includes User, Lead and Invoice Records
- URL: https://darkwebinformer.com/zenfirst-dataset-claim-includes-user-lead-and-invoice-records/
- Published: 2026-09-17T17:04:26.000Z
- Updated: 2026-09-17T17:04:26.000Z
- Author: Dark Web Informer
- Tags: Data Breaches

Breach Report France User, Lead & Invoice Data 4.4K 

## Zenfirst Dataset Claim Includes User, Lead and Invoice Records

A forum actor posting as **Alduin** has published what they claim is user and invoice data belonging to **Zenfirst**, a French management-software platform for businesses and freelancers that supports invoicing and cash-flow tracking. The post references several JSON files, including **users.jsonl, leads.jsonl and invoices.jsonl**. Visible field lists include **names, email addresses, phone numbers, company names, company IDs, Stripe user and subscription identifiers, plan information, SIRET values, promotion codes, invoice file names and URLs, OCR and extracted-text fields, taxes, currency, due dates, invoice totals, invoice numbers, issue dates and status values**. The largest file shown is **invoices.jsonl at 84,619 KB**, while the download is hidden behind a forum reply requirement. The claim is **unverified**.

Severity HIGH 

Sponsored

[ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) 

Users file1,802 KB

Invoices file84,619 KB

Leads file95 KB

Listing4.4K

### ▣Post details

TargetZenfirst

CountryFrance

SectorBusiness management software

ListingUser / lead / invoice leak

FormatsJSON / JSONL

Largest file84,619 KB

ObservedSep 17, 2026

ActorAlduin

### !What the post claims

- User records
- Lead records
- Invoice records
- Names
- Email addresses
- Phone numbers
- Company names and IDs
- Stripe user identifiers
- Stripe company identifiers
- Stripe subscription identifiers
- Subscription schedule identifiers
- Plan information
- SIRET values
- Promotion codes
- Invoice file names and URLs
- OCR raw text
- Extracted invoice text
- Taxes and currency
- Invoice due dates
- Invoice totals
- Invoice numbers
- Issue dates and status fields
- Download hidden behind forum reply

### ◱Screenshots

[ ![Forum post claiming a Zenfirst data leak involving user, lead and invoice records, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/52739859728635987623897623598762359876234987.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/52739859728635987623897623598762359876234987.png) [ ![Forum post showing alleged Zenfirst lead and invoice data samples, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/52739859728635987623897623598762359876234988.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/52739859728635987623897623598762359876234988.png) 

Forum post claiming the release of Zenfirst user, lead and invoice data, observed 17 September 2026.

### ☷Mapped techniques

The post does not describe how the data was obtained. The technique below is inferred from the structured user, lead and invoice records shown in the listing.

- Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from Information Repositories Inferred The files contain structured account, lead, subscription and invoice records, which is consistent with collection from internal business information repositories or application databases.

### ⚠Potential impact

If authentic, the leak could expose customers and business contacts to **targeted phishing, invoice fraud, payment impersonation and business email compromise**. Names, phone numbers, company information and Stripe-related identifiers could help attackers create convincing billing or subscription-themed messages. The invoice data is especially sensitive because the visible fields include **invoice numbers, due dates, totals, taxes, currency, file URLs and OCR-extracted invoice content**, which could reveal supplier relationships, payment details and other commercial information useful for fraud.

### iStatus Unverified

The forum post provides file names, file sizes, field lists and visible samples for users, leads and invoices. However, it does **not explain how the data was obtained**, when any alleged unauthorized access occurred or whether the files shown represent the full scope of the incident. Dark Web Informer has **not independently verified the authenticity, completeness or origin of the alleged Zenfirst data**.

Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=zenfirst-2026-09-17&utm%5Fcontent=threat-feed) and search there for this alert.

[View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=zenfirst-2026-09-17&utm%5Fcontent=pricing-button) 

[Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=zenfirst-2026-09-17&utm%5Fcontent=footer) // Threat Intelligence