Skip to content

Zenfirst Dataset Claim Includes User, Lead and Invoice Records

Breach Report France User, Lead & Invoice Data 4.4K

Zenfirst Dataset Claim Includes User, Lead and Invoice Records

A forum actor posting as Alduin has published what they claim is user and invoice data belonging to Zenfirst, a French management-software platform for businesses and freelancers that supports invoicing and cash-flow tracking. The post references several JSON files, including users.jsonl, leads.jsonl and invoices.jsonl. Visible field lists include names, email addresses, phone numbers, company names, company IDs, Stripe user and subscription identifiers, plan information, SIRET values, promotion codes, invoice file names and URLs, OCR and extracted-text fields, taxes, currency, due dates, invoice totals, invoice numbers, issue dates and status values. The largest file shown is invoices.jsonl at 84,619 KB, while the download is hidden behind a forum reply requirement. The claim is unverified.

Sponsored
Users file1,802 KB
Invoices file84,619 KB
Leads file95 KB
Listing4.4K

Post details

TargetZenfirst
CountryFrance
SectorBusiness management software
ListingUser / lead / invoice leak
FormatsJSON / JSONL
Largest file84,619 KB
Observed
ActorAlduin

!What the post claims

  • User records
  • Lead records
  • Invoice records
  • Names
  • Email addresses
  • Phone numbers
  • Company names and IDs
  • Stripe user identifiers
  • Stripe company identifiers
  • Stripe subscription identifiers
  • Subscription schedule identifiers
  • Plan information
  • SIRET values
  • Promotion codes
  • Invoice file names and URLs
  • OCR raw text
  • Extracted invoice text
  • Taxes and currency
  • Invoice due dates
  • Invoice totals
  • Invoice numbers
  • Issue dates and status fields
  • Download hidden behind forum reply

Screenshots

Forum post claiming the release of Zenfirst user, lead and invoice data, observed 17 September 2026.

Mapped techniques

The post does not describe how the data was obtained. The technique below is inferred from the structured user, lead and invoice records shown in the listing.

  • Collection T1213 Data from Information Repositories Inferred The files contain structured account, lead, subscription and invoice records, which is consistent with collection from internal business information repositories or application databases.

Potential impact

If authentic, the leak could expose customers and business contacts to targeted phishing, invoice fraud, payment impersonation and business email compromise. Names, phone numbers, company information and Stripe-related identifiers could help attackers create convincing billing or subscription-themed messages. The invoice data is especially sensitive because the visible fields include invoice numbers, due dates, totals, taxes, currency, file URLs and OCR-extracted invoice content, which could reveal supplier relationships, payment details and other commercial information useful for fraud.

iStatus Unverified

The forum post provides file names, file sizes, field lists and visible samples for users, leads and invoices. However, it does not explain how the data was obtained, when any alleged unauthorized access occurred or whether the files shown represent the full scope of the incident. Dark Web Informer has not independently verified the authenticity, completeness or origin of the alleged Zenfirst data.

Dark Web Informer // Threat Intelligence

Latest