Unverified claim: In late January 2026, French breach trackers Fuites Infos and FrenchBreaches reported that attackers were circulating a roughly 98 GB dump tied to FranceCasse (francecasse.fr), one of France’s largest used auto-parts marketplaces. The advertised set covered about 1 million customer profiles plus platform source code.
If you saw a “3.3 million” FranceCasse headline, that figure belongs to a different French e-commerce claim—Le Petit Vapoteur—not FranceCasse.
What the actors alleged
According to Fuites Infos, the corpus was PrestaShop-structured and may have stemmed from an unauthenticated API endpoint around June 2025. Claimed fields include names, emails, postal addresses, dates of birth, hashed passwords, order history, SIRET/business fields, and Mangopay payment identifiers.
What was not confirmed
FranceCasse had not published a matching customer notice at indexing time. Treat counts and field lists as actor/tracker claims.
Action items
- If you shopped on FranceCasse, change that password and any reuse elsewhere.
- Watch for fake “order refund” or garage-partner phishing that cites the site.
- Business buyers: review Mangopay/wallet notifications carefully.
Canonical record
https://breachhistory.com/francecasse/francecasse-forum2026 — Fuites Infos, FrenchBreaches.