← Alinto

2026 Alinto — Elasticsearch exposure ~40M SMTP metadata rows (~4.5M emails; Renault/L'Oréal/DHL/etc. correspondent risk)

2026 40.0M records affected Share on X

Data compromised

SMTP transaction metadata—sender/recipient envelopes, timestamps, relay IPs—with message-body content characterized as absent in researcher sampling

Technical writeup

Cybersecurity reporting in April 2026 traced a misconfigured Elasticsearch instance operated in connection with French email vendor Alinto to roughly forty million SMTP transaction metadata rows—indexes built from enterprise relay telemetry rather than mailbox bodies—while independent analyses circulated figures such as ~4.5 million unique mailbox addresses traversing relays that included major FMCG/logistics ministries and diplomats. Exposure primarily elevates phishing, BEC, relationship-mapping, and network-reconnaissance risk for downstream brands (e.g., L'Oréal, Renault, DHL-themed correspondents summarized in journalism) versus a singular corporate HR-database leak at those brands; BreachHistory also cross-links issuer-oriented rows for marquee correspondents.

Root cause

Misconfigured/exposed Elasticsearch analytics store for SMTP logging (open index / inadequate boundary controls per trade press)

References