← Blog

Allobébé Breach Claim: 1.1M Parents, Digicodes

Share on X

Unverified claim — August 21, 2026: Dark Web Informer reports that forum actor ChimeraZ advertised customer databases from two French baby retailers the same morning: Allobébé (allobebe.fr) with about 1.14 million people / 2.18M records including building entry codes, and Made in Bebe (madeinbebe.com) with about 960,000 people. Neither retailer had confirmed at indexing. Canonical Allobébé row: allobebe-chimeraz2026.

French parents do not expect a stroller order to become a map of which apartment door code opens their building. That is the alleged shape of the Allobébé listing — delivery notes with interphone instructions next to names, phones, and two decades of purchase history. Treat every count below as an actor-attested, unverified claim until the companies or CNIL say otherwise.

What the Allobébé data breach claim says

According to Dark Web Informer’s August 21 write-up, ChimeraZ offered an 850MB package of two JSON files labeled as Allobébé customer data: roughly 1,136,058 people, 2.18 million records, history claimed from 2006 to 2026, samples across nine mirrors, XMR-only sale. Field lists include names, titles, emails, mobile and landline phones, full street addresses, address complements, building entry codes, interphone instructions, postal codes, order numbers and totals, purchased product details, and payment method type.

No passwords or full card numbers appear in DWI’s summary of the sample. The sensitivity is physical: door codes and “leave parcel here” notes for households that buy baby goods.

The same-morning Made in Bebe claim

Hours earlier the same actor advertised Made in Bebe — about 960,106 people, 1.36M invoice lines, 1.45GB JSON, $600 asking price — with billing and delivery addresses, invoice metadata, item descriptions, and payment method type. Again: no cards/passwords in the published sample framing, but a confirmed-looking list of French households with infants at delivery addresses.

Two baby retailers in one morning is either a shared-platform story (ChimeraZ has also been tied to shared French business platforms in other dumps) or parallel retail targeting. Neither vendor had spoken publicly at indexing. BreachHistory indexes both rows as unverified.

Why baby-retail PII cuts deeper than a normal shop dump

A fashion-store leak is annoying. A baby-store leak with door codes is a physical-security problem. Parents cannot rotate a building’s digicode the way they rotate a password. Interphone instructions tell strangers which button rings which flat. Order dates imply when a newborn arrived. Combined with phones and emails, that package supports “your delivery is stuck — confirm the code” phishing and, in the worst cases, targeted burglary of homes known to have young children and recent packages.

The twenty-year Allobébé span compounds it. People who ordered a crib in 2008 may have moved three times. Children in those orders are adults. Stale digicodes may still open doors if buildings never rotated them.

Timeline of what we know

  • August 21, 2026 (morning): DWI documents ChimeraZ Made in Bebe sale listing (~960k people).
  • August 21, 2026 (same morning): DWI documents ChimeraZ Allobébé listing (~1.14M people, entry codes).
  • At indexing: No Allobébé or Made in Bebe customer letter, no CNIL public enforcement notice tied to these specific posts, and no company confirmation located in sources reviewed.

BreachHistory sets Allobébé recordsAffected at 1136058 and Made in Bebe at 960106 as actor people-counts, labeled unverified.

What data was allegedly exposed (Allobébé)

  • Identity and contact: names, emails, mobile and landline phones
  • Delivery context: full addresses, complements, digicodes, interphone notes
  • Commerce: order numbers, totals, product details, payment method type
  • Retention: claimed 2006–2026 history

What we do not have: independent dump authentication, a company census, or proof every digicode field is populated on every row.

Who is at risk

Current and former Allobébé customers in France — especially anyone who typed a building code into a delivery note. Made in Bebe customers face parallel address/invoice phishing. Building neighbors share digicode risk even if they never shopped. Parents who moved may still have old addresses and notes in the archive if the claim is authentic.

How this fits ChimeraZ’s 2026 French retail wave

ChimeraZ already appears on BreachHistory for French retail and platform dumps such as Bebeboutik and shared-platform releases like Bergerat Rent / BlgCloud. Baby retail is a new angle: high emotional leverage, physical access fields, and long retention. That pattern matters for French e-commerce CISOs even while these two rows stay unverified.

What the companies and regulators have said

As of August 21 indexing, Allobébé and Made in Bebe had not published matching customer notices. Watch for CNIL filings, retailer status posts, or French trade press (Cyberattaque.org / French Breaches) authenticating samples. Any confirmation would move these rows and revise counts.

Action items if you shopped Allobébé or Made in Bebe

  1. Change your building digicode if you ever wrote it in a delivery note — coordinate with the syndic / neighbors.
  2. Assume phishing will cite a real order number, baby product, and address. Do not click “suivre mon colis” SMS links; open the retailer’s site from a bookmark.
  3. If you reuse passwords on those shops, change them and enable MFA on the email inbox that receives order mail.
  4. Tell household members that unexpected couriers asking for the digicode by phone are a red flag.
  5. Monitor bank statements only if you stored cards on file; samples summarized publicly did not show full PANs.
  6. Do not download alleged JSON dumps “to check if you’re in them.”
  7. Keep the Dark Web Informer URLs; ignore aggregators that strip the unverified label.
  8. If a letter claiming to be from Allobébé arrives, verify the domain and call the published customer-service number before enrolling in paid monitoring.

Phishing patterns to expect

French retail breach cycles produce SMS that look like Colissimo / Chronopost failures: “Votre poussette est en attente — confirmez le code d’immeuble.” Attackers do not need the dump to be real for that playbook. They need the public claim. Save the retailer’s real phone number. Call it. Never read a digicode to an inbound caller.

Email variants attach a fake invoice PDF matching a real product name. Real invoices arrive from domains you already trust in your order history — not from a free mailbox asking you to “re-validate IBAN after the piratage.”

For French baby retailers and delivery partners

Stop storing digicodes in free-text delivery fields if you can move them to ephemeral courier apps. Minimize retention of address complements. Inventory which SaaS OMS or ERP holds twenty years of customer JSON. If ChimeraZ’s shared-platform theory applies to your stack, ask vendors in writing whether your tenancy appears in any forensic scope.

Courier partners should brief drivers that customers will be jumpy about digicode requests after this headline. A laminated card with the retailer’s verification process beats improvisation on the doorstep.

How BreachHistory will update this story

We will revise allobebe-chimeraz2026 and made-in-bebe-chimeraz2026 if either retailer confirms, denies, or publishes a census; if CNIL posts; or if reputable French press authenticates dumps. Until then, search results for “Allobébé data breach” or “Made in Bebe fuite” should keep the unverified label up front.

Bottom line for parents landing on “Allobébé piratage 2026”: the claim is large, includes building entry codes, and is still unverified; digicode hygiene and delivery phishing defenses are still worth doing today; and the twin Made in Bebe listing the same morning is part of the same ChimeraZ retail wave, not proof either dump is authentic.

Parents who never heard of Allobébé but shopped a white-label marketplace should ask which brand fulfilled the order. Reseller networks sometimes share OMS backends. If the answer is Allobébé or Made in Bebe, apply the digicode and phishing steps above.

Journalists should avoid republishing sample rows that contain real addresses and door codes. Describing field categories is enough. Amplifying digicodes helps burglars more than readers.

If you are a syndic or building manager: expect residents to request digicode rotation after this news cycle. Plan a controlled reset rather than leaving every household to invent a new code in a WhatsApp panic.

Security teams comparing this to verified French health and telecom incidents — Cegedim Santé, SFR fibre — should remember the evidentiary bar. Company letters and CNIL notices change a row. Forum screenshots do not. Allobébé is not in the confirmed category yet.

Finally, do not let “unverified” become complacency. ChimeraZ listings have been detailed before. They have also been wrong. The responsible posture is the one this page takes: name the claim, label it, give parents concrete actions, and update when Allobébé speaks.

For expatriates who ordered French baby gear while living in Paris and later left the country: watch the email you used in 2015–2020. Stale digicode fields may be useless abroad, but invoice phishing still works in any language.

Gift shoppers who shipped to a friend’s address may have put someone else’s digicode in the note. Tell that friend. Shared risk is easy to miss when only the payer gets marketing mail.

Payment-method fields without PANs still help social engineers (“your CB ending in — wait, confirm the expiry”). Hang up. Use the app.

Cross-link for researchers: Bebeboutik’s earlier ChimeraZ seller-portal claim is a different French baby marketplace with a different schema story. Do not merge the three rows into one incident without evidence of a shared breach path.

If Allobébé later confirms a smaller census — or denies entirely — this blog’s catalog pointers will move with the row. Until then, the honest search snippet is: unverified ChimeraZ claim, ~1.14M people, digicodes alleged, twin Made in Bebe listing same day.

Delivery notes are not “low sensitivity”

Retailers treat “digicode / digicode immeuble / instructions livreur” as logistics metadata. Attackers treat them as keys. A JSON field that says “Digicode 4821, 3e gauche, sonner Durand” is a burglary assist kit packaged next to proof the flat recently received a cot or car seat. That is why this Allobébé data breach claim — still unverified — deserves a longer public walkthrough than a routine email-only shop leak.

French apartment buildings often share one code among dozens of households. One customer’s delivery note can expose an entire stairwell. Syndics that never rotate codes after tenant turnover make forum dumps more dangerous for years.

How refund and Colissimo lures will sound

Expect WhatsApp voice notes that open with a baby-product SKU from a real invoice style: “Bonjour, votre commande poussette [marque] est bloquée en agence — donnez le code pour la seconde livraison.” The social-engineering trick is urgency plus specific merchandise. Parents who just bought gear are primed to cooperate with anyone who sounds like logistics.

Email subjects will mirror Allobébé or Made in Bebe order confirmations. Hover every link. Type allobebe.fr or madeinbebe.com yourself. If a page asks for a carte bancaire “re-validation after the cyberattaque,” close it. Public sample framing did not show full card numbers; scammers will invent that ask anyway.

What CNIL timelines would look like if confirmed

If either retailer later confirms, French notification rules push customer letters and a CNIL report when risk is high. Digicode exposure should count as high risk for physical safety, not merely “commercial inconvenience.” Watch for letters that mention codes explicitly — and for letters that bury the issue under generic “coordonnées” language. Ask customer service which fields were in scope.

Until confirmation arrives, treat CNIL rumor screenshots on Telegram as unverified. BreachHistory will cite primary notices, not forwarded PDFs from unknown accounts.

Grandparents who ordered gifts shipped to a child’s home should also rotate codes and warn the household. Gift checkouts are easy to forget when the payer never lived at the delivery address.

Marketplaces that white-label Allobébé or Made in Bebe inventory should ask vendors whether OMS exports were shared. A “we use a different brand name on the storefront” answer does not prove a separate database.

Researchers comparing ChimeraZ’s Bebeboutik seller-portal claim to these customer-table dumps should keep the schemas distinct: seller portals and consumer invoice archives are different trust boundaries even when the vertical is “baby.”

If you already changed your digicode after a prior building incident, change it again after this headline if you ever typed the old code into a baby-retail checkout. Stale notes in a 2006–2026 archive are exactly what long-retention breaches weaponize.

Police and municipal prevention campaigns in France already warn about fake delivery SMS. Add one line for 2026: after a baby-retail leak claim, never dictate a digicode on an inbound call — even if the caller knows your baby’s first name from an order field.

One more practical check for couples who share a checkout account: both partners should know which digicode strings were typed into Allobébé or Made in Bebe notes. The partner who never placed the order is still exposed if they live behind the same door. Sit down once, list the buildings you used for delivery, and rotate those codes with the syndic where you can.

If you are a landlord renting to new parents, expect tenants to ask whether the building digicode was ever shared with retailers. You will not have a perfect answer. Offer a rotation schedule anyway. Cheap goodwill beats arguing about whose breach it is while a forum post circulates.

BreachHistory’s job ends at the chronology and the caveats. Your job, if you shopped these brands, starts with the digicode and the phishing filters — today, while the claim is still labeled unverified.