Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Firearm Owners’ Addresses and IDs Allegedly Exposed in French Gun Store Leak

Firearm Owners’ Addresses and IDs Allegedly Exposed in French Gun Store Leak

By: Morgan Cipher — Senior Privacy Journalist

Last updated: October 8, 2026

Human Written
Firearm Owners’ Addresses and IDs Allegedly Exposed in French Gun Store Leak
  • A hacker claims to have stolen 7,546 Armurerie Douillet files and put them up for sale. The files reportedly total about 4.65 GB.

  • The files allegedly contain very sensitive information, SIA numbers, shooting licenses, ID documents, addresses, plus firearm-related records.

  • The leak remains unconfirmed and there’s been no public statement regarding a data breach from Armurerie Douillet.

A threat actor using the name “ChimeraZ” is offering over 7,500 documents allegedly belonging to French gun store Armurerie Douillet. The alleged archive contains about 4.65 GB of data.

FrenchBreaches reported the claim on October 6, 2026. Another French cyberattack monitoring site also listed the incident the same day. Neither source could independently confirm every file in the claimed dataset.

This leak is notable because of the nature of the information contained. This information allegedly contains identity documents, shooting licenses, SIA numbers, residential addresses, and documents related to firearms.

Should those files turn out to be authentic, it’ll put those affected at risk of fraud, phishing, and unnecessary exposure.

Thousands of Documents Allegedly Exposed

The hacker claims the stolen archive contains 7,546 documents. The reported files include French shooting licenses issued through the French Shooting Federation, known as FFTir. They also reportedly contain SIA numbers and documents tied to firearm possession.

The alleged dataset includes copies of identity cards and passports as well. Other reported records include proof of address and administrative documents linked to firearms.

For now, the scope of this leak is still unclear, and no independent verification has confirmed if the files mentioned contain unique records. Sometimes one person’s name can appear in multiple documents. So, we aren’t certain if the 7,546 files translate to 7,546 victims.

SIA Data Makes the Claim more Serious

The reported SIA information raises particular concerns. SIA stands for Système d’Information sur les Armes, or Information System for Weapons. France uses the system to manage firearm records and related procedures.

French government guidance says many private firearm owners must create an SIA account. This includes people with a hunting license or a shooting federation license who own or want to acquire firearms.

The system also gives eligible owners access to a digital firearm record, known as a “râtelier numérique.”

French law shows how much information can exist around firearm records. The national system can hold details about firearms, suppliers, buyers, and owners. 

It can also contain names, dates and places of birth, and addresses. That makes any real exposure of SIA-related documents especially sensitive. A person’s name and email address can already support phishing. A name, home address, identity document, and firearm-related record can reveal far more.

Still, the current reports do not prove that criminals accessed the French government’s SIA database itself. That distinction matters. The claim concerns files allegedly taken from Armurerie Douillet. It does not show that the central SIA system suffered a breach.

Identity Documents Add Another Threat

The alleged archive also contains identity documents. Reports linked to the claim mention passports and identity cards. The files also include information regarding addresses as well as other personal documentation.

Bad actors can use these for identity fraud. They can also make their scams more credible. For instance, a criminal can use all the information related to the victim’s name, address, and documentation in an email.

However, there’s no proof yet that any of the alleged documents are legit. There’s also no evidence that attackers have used the data for any fraudulent operation. So, it’s all just mere allegations until independent verification confirms the authenticity of the files.

The Alleged Attack Method Remains Unclear

Early reports have discussed a possible weakness involving customer accounts. Some descriptions point to an IDOR, a type of website flaw that can expose another user’s information when the site fails to check access correctly.

However, this attack path has not been independently confirmed. That means it would be premature to say that an IDOR flaw caused the incident. The same applies to claims about a compromised account or missing two-factor authentication.

Those details may form part of the hacker’s account of the incident. They do not yet establish what happened inside Armurerie Douillet’s systems. The available evidence supports a narrower statement: a hacker claims to have obtained and offered a large collection of Armurerie Douillet documents for sale.

Armurerie Douillet Handles Regulated Firearm Sales

Armurerie Douillet runs an armory business in France, serving hunters and sport shooters. Firearms have also appeared in other dark web cases, including Irish Court giving suspended sentences to two men over dark web gun purchase.

Virtually everything the company sells requires gathering paperwork from customers. So, the listing claims of identity documents or firearm records on file is plausible.

French law mandates that certain firearm sales or transfers have to go through the SIA, which also supports online documentation and keeps digital records of firearms. That explains why an armory might store sensitive customer files.

Still, just finding these documents doesn’t prove the actor’s database definitely came from Armurerie Douillet’s own system. To be sure, investigators need to look through the files themselves, review account activity, access logs and the whole digital trail to confirm where the data really came from.

What’s Next?

So far, there is no public confirmation that verifies the entire 7,546-file archive. There is also no public evidence that confirms the alleged attack method. So, for now, the latest listing is just what it is: a dark web data listing, not a confirmed data breach incident. If Armurerie Douillet confirms a personal-data breach, French privacy rules could require action.

According to the CNIL, organizations must report a breach if it poses a threat to individuals’ rights and freedoms. Ideally, the first notification to the authorities should be sent within 72 hours of becoming aware of the breach. In some cases, high-risk situations also call for informing the individuals who are affected by the breach.

For now, the biggest concern is the alleged combination of data. Names, addresses, identity documents, shooting licenses, SIA details, and firearm records could create a detailed picture of affected people. That would make the incident more serious than an ordinary customer data leak.

But we can’t draw any conclusion until Armurerie Douillet, French authorities, or independent researchers confirm the files.

Share this article

You might also like

Hacker Claims 140 Garuda Advertising Files and Customer Data Were Leaked

Indian Cloud Phone Provider Garuda Advertising Faces Customer Data Leak Claim

A hacker claims to have leaked about 140 business files from Garuda Advertising, the firm that runs the Teleforce phone…

October 8, 2026
ZachXBT Claims Chinese Network Laundered More Than $1 Billion for North Korea

ZachXBT Says Chinese Cybercrime Network Laundered Over $1 Billion for North Korea’s Lazarus Group

ZachXBT says he put up $349,700 and took a planned 5% loss on every trade to get inside a Chinese…

October 6, 2026
Attackers Claim Control of Dread Onion Address After Private Key Leak

Attackers Claim Control of Dread Onion Address After Private Key Leak

Attackers claim they seized control of a Dread onion address and launched a replacement forum called Dread2. Dread’s administrator disputes…

October 6, 2026

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.