-
A threat actor has reportedly released a dataset tied to Autobacs France, a French auto parts and servicing retailer.
-
The leaked data allegedly includes customer names, phone numbers, emails, vehicle registration numbers, and workshop appointment details.
-
Autobacs France has not publicly confirmed any breach of its systems.
A threat actor has allegedly dumped customer data linked to Autobacs France, a French retailer that sells automotive parts, equipment, and workshop services. The claim has not been confirmed by the company, but cybersecurity sources have begun analyzing what appears to be a released dataset.
The actor initially claimed the dataset contained roughly 34,017 customer records. These records allegedly include names, phone numbers, email addresses, vehicle registration numbers, and workshop appointment details.
Numbers Tell Two Different Stories
The figures around this incident do not all agree. French cyber-threat monitoring platform Cyberattaque.org reported on September 23 that around 34,000 workshop appointments were exposed. But a separate review by cybersecurity researcher Sébastien Forte told a different story.
According to Forte’s publicly shared analysis, the dataset may contain as many as 70,370 rows. After removing duplicate entries, that number reportedly drops to around 57,561 individual people. The data allegedly covers customer orders from 2021 to 2024 and appointments stretching into 2026.
The gap between the two figures matters. A single dataset can hold more than one record for the same customer. It can also include older or repeated entries. So the true number of people affected, if the leak is real, remains unclear. These figures should be treated as reported estimates, not confirmed counts.
The scale of alleged data exposures can vary significantly between initial claims and later analysis. Hacker claims massive France education ministry breach exposed 346 million records covers another reported French data-breach claim involving a much larger number of allegedly exposed records.
What the Alleged Leak Contains
According to the available reporting, the released data allegedly includes customer names, email addresses, phone numbers, vehicle registration numbers, and service or appointment details.
Autobacs France’s own privacy policy confirms that the company does collect this type of information. It states that the company gathers names, email addresses, phone numbers, and other customer-related details through its online services and workshop booking system.
The combination of personal details and vehicle information is what makes this type of leak particularly risky. A bad actor could use a person’s vehicle registration number or service history to craft a fake message that looks real. For example, someone might receive a message referencing their car model or a recent appointment.
That kind of detail can make a phishing attempt seem more trustworthy. Customers who get unexpected messages mentioning their vehicle, past service visits, or upcoming appointments should be careful. They should be especially cautious if the message asks for passwords, payment details, or any sensitive information.
It is also worth noting that the dataset’s authenticity has not been independently verified. Its origin, accuracy, and how current the information is all remain open questions. The full scope of the alleged exposure is still uncertain.
What Autobacs Has (and Has Not) Said
As of now, Autobacs France has not released any public statement confirming a cyberattack or a breach of its systems. There is no official acknowledgment from the company that customer data was taken.
The available reporting rests on a threat actor’s claim and the analysis of allegedly leaked material. That is an important distinction. A threat actor releasing a dataset does not automatically mean the company’s systems were broken into. The data could have come from a third-party source, an older exposure, or could be partially or fully fabricated.
Until Autobacs France speaks publicly, this incident should be described as an alleged data leak, not a confirmed breach. Customers of the retailer should stay alert. If Autobacs or any related service reaches out asking for personal or payment information, verify the message through the company’s official website before responding.