-
Cyberattack on delivery tracking service Shipup has revealed the names, emails, and phone numbers of the customers of Micromania and Easypara.
-
The unauthorized access to the system happened between July 31 and August 17, this year, as a result of software vulnerabilities.
-
Other major retail clients like Carrefour and L’Occitane face potential risks, but investigations show no confirmed data impact for them.
A recent cybersecurity incident with logistics tracking firm Shipup has revealed personal information of customers from big retail companies. Hackers broke into private customer databases, obtaining sensitive details about customer contacts.
The incident happened between July 31 and August 17 this year and came through weaknesses in third-party applications. Following the exposure, the affected users could face more risks from targeted phishing campaigns.
Logistics Provider Breach Exposes Retail Customer Data
Shipup provides automated delivery tracking services to more than 700 global retailers and ecommerce brands. Because the logistics company handles delivery notifications, its database holds substantial volumes of personal contact details. Consequently, an intrusion into the delivery systems of the provider creates severe supply chain risks for online merchants.
The security incident has compromised customer records from the French gaming retailer Micromania and the health store Easypara. According to reports, the compromised records contain customers’ information, such as names, email addresses, and phone numbers. Furthermore, attackers accessed detailed package delivery information linked directly to these individual profiles.
While Micromania and Easypara confirmed data exposure, several other major clients remain under close monitoring. Brands such as Carrefour, L’Occitane, Courir, and Printemps currently use the affected logistics service. However, investigators have found no direct evidence that attackers accessed records from these additional retailers.
This incident follows a separate breach involving Intermarché, one of France’s largest supermarket chains. A cyberattack on Intermarché’s drive service exposed the personal data of 287,605 customers, including names, addresses, phone numbers, and order details.
Software Vulnerabilities Enable Extended System Intrusion
Preliminary assessments of the security situation linked the intrusion to different vulnerabilities in third-party software integrated into the server system. In particular, the attackers exploited weaknesses in Metabase, a free analytics tool used for internal database queries. Criminals took advantage of serious defects to eliminate standard security barriers and query customer databases directly.
The unauthorized access was active for more than two weeks until the security teams detected the crime and limited the access. To be able to fix the problems, computer programmers developed emergency software fixes. Therefore, companies must audit integrated analytics platforms continuously to catch unpatched security flaws before bad actors exploit them.
This incident reflects a wider practice of cybercriminals: the attackers target third-party service providers. Instead of breaching well-protected retail establishments, they focus on the unprotected partners of those retailers. This results in the loss of sensitive customer data of the clients of many independent companies at once.
Rising Threats of Delivery Scams and Smishing Tactics
The exposure of personal customer data provides the perfect ground for fraudulent activities and social engineering scams. These criminals often use the compromised data in their smishing campaigns. Scammers can send out phony notifications about some deliveries requiring either identity confirmation or payment of delivery fees.
Seeing that victims are awaiting their orders from these retailers makes them more vulnerable to clicking on the malicious tracking links since they tend to open them more willingly.
As such, through the links, the victims will move to the fake webpage, which aims to steal their credit card information and login credentials. Furthermore, attackers can customize fake notifications using actual victim names and recent order dates, making fraud attempts harder to spot.
Security experts advise shoppers to ignore text messages containing urgent payment requests or suspicious web links. Customers should inspect order statuses solely through official retail applications or official store websites. Moreover, users should refrain from disclosing passcode information or banking details on unverified third-party websites.
Responses from the Companies and Recommended Steps for Incident Management
Both Micromania and Easypara began issuing formal data breach notifications to affected individuals following the discovery. The notifications detail the exact types of exposed personal information and outline protective measures for consumers. Additionally, affected retailers reported the security incident to regulatory data protection authorities in compliance with privacy laws.
Retailers using third-party logistics vendors must enforce strict data minimization strategies across all external systems. Vendors should store only the basic information strictly necessary to process delivery tracking updates. Consequently, reducing long-term data retention on tracking servers limits consumer exposure when perimeter breaches occur.
Organizations should take measures to ensure that every partner access portal is configured to require two-factor authentication. It is vital regularly to assess security, to use automated scanning technology to identify vulnerabilities, and to launch an immediate response.
Moreover, retailers should always check the security practices of their suppliers. This helps them to maintain customer trust and protect their internal networks from supply chain intrusions.