← BlgCloud

2026 BlgCloud — platform breach; 13 client instances exfiltrated (5 with significant docs)

2026 Unknown records affected Share on X

Data compromised

Company: professional names/emails/phones, commercial message history on 13 instances; significant document exfiltration on 5; actor claims 159 instances (unverified)

Technical writeup

BlgCloud confirmed a late-July 2026 cyberattack on its French cloud ERP platform, notifying CNIL and customers (August 2026 press release). The vendor identified 13 client instances with data exfiltration — primarily professional contact fields and commercial messaging history — and significant document loss on 5 instances. Entry involved exploitation of a specific extranet account-creation request when legacy and new extranet versions coexisted, plus misconfigured account rights; three additional instances saw internal account takeover via June 2026 credential leaks. BlgCloud disputes actor marketing of 159 compromised tenants. ERP availability and WORM backups were not affected per the company. recordsAffected 0 (no person census); companyConfirmed true for platform incident.

Root cause

Extranet account-creation flaw plus misconfigured rights on instances running old and new extranet versions; separate credential-stuffing on 3 instances

References