Zenfirst Dataset Claim Includes User, Lead and Invoice Records
A forum actor posting as Alduin has published what they claim is user and invoice data belonging to Zenfirst, a French management-software platform for businesses and freelancers that supports invoicing and cash-flow tracking. The post references several JSON files, including users.jsonl, leads.jsonl and invoices.jsonl. Visible field lists include names, email addresses, phone numbers, company names, company IDs, Stripe user and subscription identifiers, plan information, SIRET values, promotion codes, invoice file names and URLs, OCR and extracted-text fields, taxes, currency, due dates, invoice totals, invoice numbers, issue dates and status values. The largest file shown is invoices.jsonl at 84,619 KB, while the download is hidden behind a forum reply requirement. The claim is unverified.
▣Post details
!What the post claims
- User records
- Lead records
- Invoice records
- Names
- Email addresses
- Phone numbers
- Company names and IDs
- Stripe user identifiers
- Stripe company identifiers
- Stripe subscription identifiers
- Subscription schedule identifiers
- Plan information
- SIRET values
- Promotion codes
- Invoice file names and URLs
- OCR raw text
- Extracted invoice text
- Taxes and currency
- Invoice due dates
- Invoice totals
- Invoice numbers
- Issue dates and status fields
- Download hidden behind forum reply
◱Screenshots
☷Mapped techniques
The post does not describe how the data was obtained. The technique below is inferred from the structured user, lead and invoice records shown in the listing.
- Collection T1213 Data from Information Repositories Inferred The files contain structured account, lead, subscription and invoice records, which is consistent with collection from internal business information repositories or application databases.
⚠Potential impact
If authentic, the leak could expose customers and business contacts to targeted phishing, invoice fraud, payment impersonation and business email compromise. Names, phone numbers, company information and Stripe-related identifiers could help attackers create convincing billing or subscription-themed messages. The invoice data is especially sensitive because the visible fields include invoice numbers, due dates, totals, taxes, currency, file URLs and OCR-extracted invoice content, which could reveal supplier relationships, payment details and other commercial information useful for fraud.
iStatus Unverified
The forum post provides file names, file sizes, field lists and visible samples for users, leads and invoices. However, it does not explain how the data was obtained, when any alleged unauthorized access occurred or whether the files shown represent the full scope of the incident. Dark Web Informer has not independently verified the authenticity, completeness or origin of the alleged Zenfirst data.
Dark Web Informer // Threat Intelligence