Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Hackers Claim Planity Data Leak Exposing Information of 465,000 Users, but Breach Unconfirmed

Hackers Claim Planity Data Leak Exposing Information of 465,000 Users, but Breach Unconfirmed

By: Morgan Cipher Senior Privacy Journalist

Last updated: July 29, 2026

Human Written
Hackers Claim Planity Data Leak Exposing Information of 465,000 Users, but Breach Unconfirmed
  • A hacker is publicizing a database, stating it belongs to Planity on a dark web site and declaring that they were able to break the system and obtain about more than one million records related to at least 465,000 people.

  • The total of the records consists of 999,451 names, 327,000 phone numbers, 176,000 emails, and ID numbers with business-specific details, while no credit card and password information are provided.

  • The database is yet to be confirmed as real and the seller account almost has no history of posts, but the format of the information and data reflects the claims.

Recently, a cybercriminal placed a database for sale on a dark web forum, with claims that it belongs to Planity, a French online booking platform.

The platform specializes in beauty and wellness appointments. The vendor asserts that they were responsible for hacking the service and accessing the information.

As stated by the advertisement, the database consists of 1,088,463 entries. The entries comprise roughly 465,828 independent people. The data allegedly links to 1,276 distinct establishments using the platform.

Planity is an appointment booking service that has active usage in France. The website allows its users to search for and book services provided by different specialists like hairstylists, barbers, beauty and nail salons.

Also, professionals use this platform for managing their appointments and calls. There are approximately 15 million active users and 60,000 beauty salons registered on the website across France, Belgium, and Germany.

What Data Appears in the Alleged Leak

The seller has provided a sample of the database to confirm the personal details of countless individuals. The personal information included various levels of detail. For example, names are present in 999,451 records.

Phone numbers are available in 327,000 records. Emails are available in 176,000 records. Gender information is available in 111,507 records. Postal code information is available in 2,202 records.

The sample contains technical metadata as well. This includes business identifiers linked to establishments, internal record identifiers, object identifiers, and creation timestamps. Also, some records show deletion timestamps. Others show import status flags. Not every record contains all these fields. For instance, some records have phone numbers but no email addresses.

Further, the structure of the data reveals an important detail. The presence of business identifiers suggests the database links customer records to specific establishments.

A customer can appear in multiple records if they visited different salons. This explains the gap between 1.08 million records and approximately 465,828 unique individuals.

Additionally, the same person may appear several times across different establishment records. This could mean a customer who booked appointments at multiple salons would have separate records for each.

Records Marked as Deleted and Imported

The statistics show 22,121 records marked as deleted. A field called deletedAt appears in the sample. This suggests the system retains records even after deletion. Soft deletion is a common engineering practice.

However, there are some doubts regarding data retention, and according to GDPR, organizations must delete any personal data when it is no longer necessary.

The data also shows 274,210 records marked as imported. A field called wasImported indicates this status. This suggests the data came from an import process.

However, the available information does not clarify the origin, date, or mechanism of this import. It remains unclear whether these records came from a legitimate source.

The Claims of the Seller and Verification Status

The person offering the data claims to have compromised the target personally and they asked for $2,500 in Bitcoin for the dataset. Moreover, the account appears to be new – it has almost no posting history. This factor weighs against the credibility of the listing.

Further, the sample structure appears internally consistent. It uses identifier formats and field naming consistent with hosted database services. The stated file size of 261MB matches the record count. The seller has edited the post twice since publication; however, the authenticity of the entire database remains unverified.

No passwords or payment methods appear in the sample. No bank card details or identity documents are visible. The extent of any potential system compromise remains unknown. The method used to obtain the data is also unclear.

Risks for Potentially Affected Individuals

If the database is legitimate, the exposed information can enable a variety of criminal practices. Putting names, phone numbers, and email addresses together allows for phishing, fraudulent text messages, and fraudulent phone calls.

Also, the business identifier linking customers to specific establishments adds a dangerous element. Attackers could personalize fraud attempts by naming the actual salon a person uses.

The risks are even higher when specific demographics are targeted, as a hacker has claimed to leak data of 10,000 LGBTQ+ individuals, highlighting the dangers of group-specific data exposure.

Dark Web Informer emphasizes that the post is a contact dataset, and not a credential one. The fraud risk is correspondingly limited compared to credential leaks.

However, the value to a potential buyer resides in the quality of the data instead of the depth of it. A confirmed mobile number combined with the real name of a person for roughly a million French consumers remains valuable for SMS-based fraud.

The presence of deletion timestamps raises a question about GDPR compliance. If individuals exercised their erasure rights, their data should not remain in exports.

The sample also contains at least one address on the platform’s corporate domain. This indicates staff or test records are mixed into the customer set.

Share this article

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.