April 2026 trade coverage described an internet-exposed analytics store operated by French email-services firm Alinto that held roughly 40 million SMTP transaction rows—sender, recipient, timestamps, and relay detail—impacting high-volume customers’ mail footprints rather than full message bodies. Outlets including TechRadar Pro, Cybernews, and SC Media noted major brands and public-sector domains in the index, with L'Oréal frequently cited alongside other large correspondents.
Researchers and journalists framed the exposure primarily as spear-phishing and relationship-mapping risk driven by vendor misconfiguration, distinct from a conventional compromise of L'Oréal’s own corporate databases.
Canonical record: L'Oréal / Alinto SMTP metadata 2026 on BreachHistory.
Sources: TechRadar Pro, Cybernews, SC Media