Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > French Software Provider BlgCloud Says 13 Customer Environments Hit by Cyberattack

French Software Provider BlgCloud Says 13 Customer Environments Hit by Cyberattack

By: Morgan Cipher Senior Privacy Journalist

Last updated: August 10, 2026

Human Written
French Software Provider BlgCloud Says 13 Customer Environments Hit by Cyberattack
  • BlgCloud says 13 customer environments were affected by a flaw that could allow an outside user account to be created.

  • Attackers claimed access to 159 of about 230 environments, along with millions of documents and several terabytes of data.

  • The attack exposed data from at least two customer environments, raising concerns about fraud, phishing and targeted scams.

A cyberattack on French business software provider BlgCloud has exposed data from several customer environments, but the size of the breach remains disputed.

A cybercriminal claimed access to 159 BlgCloud environments. The attacker also claimed access to millions of documents and several terabytes of data.

BlgCloud has since challenged that figure. According to the media reports, the company found 13 affected customer environments tied to one software issue in its own review. Five of those had documents taken. The other eight did not have document theft.

As of now, security firms list the incident as a confirmed data breach dated August 8. They report currently about 2 TB of data linked to the incident.

BlgCloud Says the Impact was Smaller

BlgCloud said the main incident involved a route that could, under certain conditions, create an extranet user account.

A permissions problem then gave that account access to some customer data.

The company identified 13 customer environments affected by this method. Five had documents exfiltrated, while eight had access without document theft.

The exposed information included names, professional email addresses and business phone numbers. It also included other business contact details.

In the five environments where documents were taken, the files included equipment photos, product images, invoices and PDF quotes. BigCloud said credit card data remains intact.

The company also said that IBANs visible in the affected systems belonged to customer businesses. Those bank details were already available through customer extranets for invoice payments. BlgCloud said that attackers didn’t retrieve any information belonging to BlgCloud itself.

The company also identified a second issue involving three customer environments. In those cases, attackers allegedly used internal accounts tied to previously stolen credentials. BlgCloud said this was separate from the software flaw affecting the 13 environments.

The Attacker Claimed far Wider Access

The original cybercriminal claim was much larger. The attacker said BlgCloud had about 230 environments and claimed access to roughly 159 of them.

That does not necessarily mean 159 separate companies were breached. One customer can have multiple companies or environments inside a business software platform.

BlgCloud itself says its system supports multi-company operations. It’s a platform that brings several business functions into one system. The attacker claimed access to millions of documents and several terabytes of data.

Samples reportedly included CRM records, emails, business documents, contact information, IBANs and BICs. Those claims have not been independently verified in full.

Still, the threat actor published some data tied to BlgCloud customers. Security researchers list Roussel Agri 62 as an affected customer and say 9.33 GB of data was published.

Roussel Agri 62 is a French agricultural equipment dealer. Its public website shows that it sells and services agricultural, gardening and road equipment.

Security researchers also reported a separate publication involving Duvignau 40. That listing included CRM data, emails and documents.

Why the Data Matters

BlgCloud is not a general-purpose office tool. It is a business management platform that dealers, rental firms, repair shops and other equipment companies use.

The software handles CRM records, sales, rentals, stock, purchasing, finance and documents. BlgCloud says more than 28,000 users currently use its platform. It also says it has more than 400 customers. That makes the type of exposed information important.

A stolen business email alone may have limited value. However, an email accompanied by actual invoices, along with customer names, phone numbers, and banking details could prove far more valuable.

Attackers could use this information to formulate phishing emails and to pose as either suppliers, customers, or employees. The risk is especially serious for payment fraud.

A hacker with the knowledge of how a company normally issues invoices can come up with an authentic-looking message. A fake request to change bank details could then appear far more believable.

More Questions Remain Unanswered

The biggest unanswered question is the true number of affected environments.

BlgCloud’s findings point to 13 environments affected by the software flaw. Three more customer environments were linked to compromised internal accounts.

That is very different from the attacker’s claim of 159 environments. The amount of data actually stolen also remains unclear. The BlgCloud case echoes a similar pattern seen in other alleged breaches, a threat actor recently claimed to have leaked internal infrastructure documents from BlackRock, one of the world’s largest asset managers, though the authenticity and scope of that leak also remain unverified.

As per our findings, the attacker did not necessarily download everything available across all allegedly accessible environments. That makes it difficult to estimate the number of files, emails, bank details or people involved.

The technical details of the original flaw are also not publicly available. For now, the safest conclusion is that BlgCloud suffered a real security incident, while the full scale remains under investigation.

The published customer data shows that the incident is not simply an unverified forum claim. But there is still no solid evidence supporting the attacker’s claim about the compromise of 159 customer environments.

BlgCloud’s narrower account, involving 13 environments and a separate three-account incident, currently provides the clearest picture of what the company says it has confirmed.

Share this article

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.