-
A threat actor known as ChimeraZ claims to have leaked a 127 MB JSON dataset containing 511,661 records from 21,402 stores operating on French e-commerce platforms WiziShop and Dropizi.
-
The dataset allegedly includes invoice numbers, supplier details, store names, customer identifiers, transaction dates, and physical billing or shipping addresses.
-
Security researchers have not independently verified the authenticity or exact origin of the dataset, and platform operators have not confirmed a direct system breach.
A cybercrime forum seller operating under the online handle ChimeraZ claims to have leaked a massive database connected to WiziShop and Dropizi. WiziShop and Dropizi are French e-commerce platforms that allow firms to create, manage, and grow their online retail stores. Particularly, Dropizi focuses mainly on automated dropshipping processes.
The cybercriminal uploaded the database to an underground cybercrime forum. They also provided many download links along with a small sample of the data file. However, independent cybersecurity researchers and the platform administrators haven’t yet verified the authenticity, source, or the total quantity of data records of the alleged leak.
Structural Breakdown of the Exposed E-Commerce Dataset
According to the forum post, the leaked dataset contains 511,661 total records collected across 21,402 distinct merchant stores operating on the platforms. The actor claims the entire database measures approximately 127 megabytes in size. Also, they use JavaScript Object Notation (JSON) format to organize store data.
The exposed JSON files reportedly contain specific transactional and operational details connected to online storefront sales. This dataset contains details about invoice identification numbers, suppliers, customers and names of stores.
Others include addresses for billing and shipping, names of cities, their postal codes, and countries. It also gives information about actual transaction dates, history of orders placed, and invoices.
Consequently, security analysts who reviewed the posted file samples noticed that the dataset focuses on business logistics and order details rather than raw user credentials.
The visible sample does not list payment card numbers, plain account passwords, or banking access codes. Therefore, the immediate financial threat involves customer privacy loss and business intelligence exposure rather than direct bank account theft.
Business Intelligence Risks and Supply Chain Exploitation
Although financial passwords remain unexposed in the visible records, leaking structured store invoices creates significant operational threats for online merchants. Competing retail operators or malicious actors could analyze the 127 megabyte file to extract sensitive commercial information. The disclosure of identities of supplier, order volumes, and customer buying patterns makes confidential business information available to third parties.
Also, cybercriminals may take advantage of detailed invoice numbers and shipping addresses for targeted business email compromise attacks. Fraudsters can pretend to be shipping companies or legitimate suppliers and send fake invoices to business owners.
They may require immediate payment by electronic transfer. In addition, criminals can research the shipping addresses of customers and use information from external phone databases to launch convincing delivery fraud calls.
Moreover, dropshipping businesses operating through Dropizi face unique operational risks from supply chain exposure. The dropshipping model uses the delivery system and final touchpoints from sellers to keep up with profitability and fulfillment schedules.
Whenever criminal organizations reveal the identities of suppliers and product prices, competitors are able to conduct price undercutting or cause disruptions in wholesale deals. Consequently, small business owners face severe commercial disadvantages if rivals gain access to their private vendor networks.
Phishing Concerns for Online Shoppers and Store Clients
The exposure of customer names, addresses, and order information can put these retail customers at risk of falling prey to elaborate social engineering schemes. Criminals make use of stolen shopping logs sold on the dark web to steal identities of specific people.
They may even create believable profiles pretending to be them. Also, scammers can send them SMS messages or phishing emails with their exact order details, such as order date and invoice number.
For example, a scammer might send a fake delivery message informing the customer of an additional shipping fee to pay for delivery from a chain store. Since the message has the right order date, store name, and home address, the recipient is likely to trust the person sending the message. Therefore, people may provide their card number information to the phishing site of fraudsters and get robbed instantly.
SafePal confirmed that an authorization flaw exposed personal and order data of 39,798 customers, including names, contact details, shipping addresses, and purchases. The company warned that criminals could use the information for targeted phishing scams and said it removed more than 30 fake websites and phishing links tied to the breach.
Security experts recommend that online customers to be vigilant when getting unexpected updates about deliveries or requests for payment. It is advisable for customers not to click on links from text messages. Instead, they should check the order status via the official website of the shop.
Incident Verification Status and Technical Guidance
At this moment, both WiziShop and Dropizi executives have not released any security warnings regarding an internal network breach. Experts in threat intelligence have claimed that cybercriminals are known to falsely claim larger data breaches than they really are.
Sometimes, they rebrand previously known data leaks to gain attention. Thus, investigators need to look into system logs, API connections, and database points. This helps to find out whether the leaked documents were from a main server or a third-party program.
At the same time, e-commerce companies using WiziShop or Dropizi must check their security measures to secure their businesses. Business owners need to change admin passwords and implement multi-factor authentication on all accounts.
Also, they should check for unusual activity in the API keys. Businesses ought to look through the latest order logs to see if there was any unauthorized data export or suspicious access to their accounts.
Meanwhile, digital forensic teams continue to analyze the leaked JSON sample files. However, platform users should closely monitor official communications from WiziShop technical support. With a clear incident response plan, a small business is able to respond in a timely manner at the time of a data breach.
Moreover, merchant platforms ought to have strict encryption policies in place regarding all sales records kept for future reference. This helps to mitigate the risk of exposure of data in the next security incident.