← Blog

Relais Colis Claim: RandomRussian Posts ~6.2M Lines

Share on X

Unverified claim: On 24 September 2026, Dark Web Informer reported that an actor using the handle RandomRussian posted a French-language dump framed as a Relais Colis dataset — roughly 6.2 million lines of email addresses, phone numbers, and other personal data in the body text, with a rounded 6 million figure in the title and a separate heading that lists 12,976,743 lines. Relais Colis, a major French parcel pickup and delivery network, had not confirmed any breach, notice, or regulator filing at indexing time. Treat the dump as an actor marketing claim until the company or CNIL says otherwise.

Canonical BreachHistory row: relais-colis-randomrussian2026. Primary monitoring source: Dark Web Informer — Actor Claims to Leak 6.2 Million Relais Colis Records. This article does not promote downloading the dump, and it does not treat forum screenshots as company-confirmed fact.

What RandomRussian posted on 24 September

The public thread DWI summarized is a classic forum dataset drop with messy numbers. RandomRussian’s body copy markets about 6.2 million lines tied to Relais Colis. The post title rounds that to 6 million. Above the sample, a separate heading claims 12,976,743 lines — nearly double the body figure. Those three numbers cannot all be a clean census of unique French customers. They may mix raw file rows, metadata lines, duplicate objects, or simple exaggeration. Until Relais Colis attests a count, BreachHistory indexes the actor’s body figure (~6.2M) as the catalog’s recordsAffected value and labels the entire row unverified.

The poster credits another handle, Miaouriarty, and explicitly denies carrying out the original scraping. That dispute framing matters. Dataset traders often recycle older scrapes, merge retail CRM exports, or rebrand someone else’s haul while arguing about credit. A denial of original scraping is not proof the data is fake — and it is not proof Relais Colis systems were breached in September 2026. It is a signal that the acquisition story is contested even among criminals.

DWI also notes that download visibility was hidden until a forum reply was posted, and that the poster promoted the material for spam. Hidden downloads and spam pitches are standard for contact-list dumps. They are not the same as a ransomware leak-site countdown with a named affiliate brand and a locked archive filename.

What the sample allegedly shows

According to the Dark Web Informer write-up and accompanying screenshot description, the visible sample mixes index metadata with personal-data objects. Field types called out in monitoring include:

  • First and last name fields
  • Mobile phone numbers
  • Email addresses in some entries
  • Street addresses in some entries
  • Postal codes, city, department, region, and country fields
  • FR country values in the sample
  • Record IDs prefixed with relaiscolis.com

That inventory sounds like customer or pickup-point contact data — the kind of material useful for SMS parcel scams and email phishing. What it does not prove is that every one of the 6.2 million (or 12.9 million) lines is a unique living person with a complete address, that payment card numbers were included, or that Relais Colis production databases were the source. Domain-prefixed record IDs are easy to forge in a dump marketed against a brand. A sample that “looks French” is not a Have I Been Pwned load.

DWI is explicit on methodology: it did not independently verify origin, authenticity, scale, or a connection to a Relais Colis compromise; the hidden download was not accessed for the public alert; and raw line counts cannot be read as unique people because the sample alternates metadata and personal-data objects. That caution is the right default for readers too.

What we know vs what we do not

Supported by DWI / actor text: RandomRussian named Relais Colis; claimed a multi-million-line dataset; used conflicting volume figures (~6M title, ~6.2M body, ~12.98M heading); showed a sample with names, mobiles, and location-style fields; credited Miaouriarty; denied original scraping; promoted spam use; referenced Telegram handles in the screenshot; dated the post around 24 September 2026.

Not supported at indexing: Relais Colis confirmation; CNIL reprimand or French AG-style notice with an attested census; independent proof the dump is fresh Relais Colis production data; reconciliation of the 6.2M vs 12.9M figures; proof every line is a unique customer; payment-card or password exposure; a published ransom demand; forensic evidence of how the data was collected (API scrape, partner leak, older breach recycle, or fabrication).

To be clear: this is not a confirmed Relais Colis data breach. It is an unverified forum leak claim against a recognizable French logistics brand. Amplification on social media does not upgrade the claim. Secondary posts that say “Relais Colis breached for 13 million users” without a company notice are editorial inflation of actor marketing.

Why a Relais Colis contact dump is dangerous even unverified

Relais Colis sits in the everyday path of French ecommerce. Shoppers pick up parcels at partner shops, track deliveries by SMS, and re-schedule drop-offs when they miss a courier. That workflow is already a favorite playground for fraudsters who send “votre colis est en attente” texts with malicious tracking links. A mega-list that allegedly pairs names, mobiles, emails, and addresses — whether authentic Relais Colis rows or a stitched contact corpus — is rocket fuel for those campaigns.

The social-engineering wave does not require the dump to be real. It only requires the brand name to trend. Within hours of a Dark Web Informer headline, expect clone SMS messages that cite “suite à la fuite Relais Colis,” fake support chatbots asking for digicodes, and emails that claim your pickup point was “compromised” and you must “re-validate” an IBAN or card. Those scams work on people who never used Relais Colis and on people who did. Treat the claim as a phishing-season trigger, not as automatic proof you are in a stolen CRM.

If the sample fields are genuine for even a subset of customers, the stakes are concrete. Mobile numbers enable SMS phishing and SIM-swap reconnaissance. Street addresses and digicode-adjacent context (even when digicodes are not listed) help attackers sound local. Emails enable credential stuffing against merchant accounts that reuse Relais Colis login patterns. None of that needs card PANs to hurt households.

Who might be at risk if the claim were true

Until Relais Colis speaks, treat the audiences below as hypothetical risk groups suggested by the actor sample and by how French parcel networks operate — not as confirmed victims.

Customers waiting for or collecting parcels

Anyone who regularly uses Relais Colis pickup points is the primary phishing audience. Watch for texts that reuse your real name, city, or a plausible tracking number. Do not approve unexpected “redelivery fees.” Do not install apps from SMS links. Open the Relais Colis app or site you already trust, or check the merchant that shipped the order.

Shop and relay-point partners

Local shops that host Relais Colis lockers or counters may see spoofed “network security” emails asking them to reset partner portals, upload ID scans, or wire a “compliance deposit.” Finance and counter staff should verify any urgent change out-of-band through known Relais Colis partner channels — not through a forum screenshot forwarded on WhatsApp.

Ecommerce merchants that ship via Relais Colis

Merchants sometimes hold overlapping customer contact data. A public Relais Colis dump claim can be used to pressure merchants (“we have your buyers too — pay or we spam them”). That is extortion theater until proven. Still, merchant security teams should hunt for unusual export jobs on their own side and warn support desks about refund scams citing the Relais Colis rumor.

People who never used Relais Colis

Contact spam lists are often mashed together. If your email appears in a recycled corpus marketed under a famous brand, you can still get phishing that name-drops Relais Colis. The brand is the hook. Your presence in the file — if any — may have nothing to do with that company’s systems.

How to read the conflicting line counts

Forum dumps love impressive numbers. Here is a practical way to hold the three figures without collapsing them into one fake “facts” paragraph:

  • ~6 million (title): marketing round number.
  • ~6.2 million (body): the figure DWI leads with and the figure BreachHistory uses as the unverified catalog count.
  • 12,976,743 (heading above sample): unresolved conflict — possibly raw lines including metadata, a different file version, a tracker misread, or inflation.

People asking “was I affected by the Relais Colis data breach” deserve an honest answer: we do not know, because Relais Colis has not said who — if anyone — is in scope, and the actor’s own line counts do not agree. Volume without a verified schema and without company attestation is not a victim list. Cataloguing the claim is not the same as confirming it.

Industry context: French logistics and contact-list markets

France has seen a steady drumbeat of large contact and customer-data claims through 2026 — some verified, many not. Healthcare and public-sector stories grab headlines, but parcel and last-mile brands are equally attractive because delivery SMS is already trusted by consumers. Compare this RandomRussian Relais Colis marketing to other logistics-adjacent incidents in the BreachHistory catalog, such as CEVA Logistics customer-impact stories and other French unverified dumps. The common thread is not one actor family. It is the economics of spam and parcel fraud: names plus phones plus addresses sell, and brand names sell better.

GDPR still matters if personal data from Relais Colis were confirmed stolen. Notification clocks, CNIL engagement, and clear customer letters are heavy obligations — which is another reason silence so far should be read carefully rather than filled with invention. Confirmed French logistics breaches usually produce paper. Unverified forum posts often produce only monitoring blogs like this one.

Also note what this claim is not. It is not a named ransomware affiliate countdown with a locked archive and a cryptocurrency wallet demand in the sources reviewed here. DWI describes a dataset release claim promoted for spam, with a credit dispute and a hidden download gate. Collapsing every French leak headline into “ransomware hit Relais Colis” misstates the public record.

What Relais Colis and regulators have said

As of this article’s createdAt timestamp, public sources reviewed for cataloguing did not include a Relais Colis customer notice, status-page incident, CNIL decision, or other company attestation confirming RandomRussian’s dataset. Absence of a notice is not proof of innocence and not proof of guilt. Logistics operators sometimes investigate quietly before speaking. Until they speak — or a regulator files with substance — the Relais Colis RandomRussian claim remains an unverified actor / forum leak listing.

Readers should ignore mirrors that rewrite DWI’s alert as “Relais Colis confirms 13 million records stolen.” Amplification is not confirmation. BreachHistory’s policy is explicit: catalog named September 2026 leak claims with clear unverified labels, keep actor counts labeled as such, and update the row if Relais Colis later confirms, denies with evidence, or a regulator attests a census.

Timeline readers can actually use

  • 24 September 2026: RandomRussian’s Relais Colis dataset claim appears in monitoring (DWI public alert dated the same day). Body ~6.2M lines; title ~6M; heading ~12,976,743; sample shows names/mobiles/location-style fields; Miaouriarty credited; original scraping denied; spam use promoted; download gated behind a reply.
  • 24–27 September 2026: Secondary social posts and screenshots circulate. No Relais Colis confirmation located in sources used for this catalog row.
  • 27 September 2026: This BreachHistory blog indexes the claim as unverified, with recordsAffected set to the actor body count (6,200,000) and companyConfirmed: false.

If you only remember one sentence, remember this: RandomRussian claimed a multi-million-line Relais Colis contact dump on 24 September 2026; the company had not confirmed it.

Phishing and scam patterns to expect

Whether or not the dump is authentic Relais Colis data, the brand will attract fraud. Concrete examples to reject without clicking:

  • “Relais Colis Sécurité: suite à la fuite de 6,2M de dossiers — validez votre compte ici.”
  • SMS: “Votre colis est bloqué après la fuite RandomRussian — payez 2,99€ de frais.”
  • “Point Relais: votre digicode a fuité — confirmez le nouveau code sur ce lien.”
  • Merchant BEC: “Update bank details for Relais Colis refunds after the breach.”
  • Cold calls that paste DWI screenshots as “proof” you must enroll in paid credit monitoring.

Legitimate Relais Colis communications will not ask you to unlock a forum download, install remote-access tools, or wire money to a “remediation” vendor that cold-calls you. Tracking links in unsolicited SMS are hostile until proven otherwise.

What you should do

  1. Wait for official Relais Colis notices before changing banking details, pickup preferences, or merchant refunds based solely on forum screenshots.
  2. Treat the ~6.2M / ~12.9M figures as unverified actor counts. Do not forward them to customers or staff as confirmed fact.
  3. Parcel recipients: Prefer the official app/site or the merchant’s order page for tracking. Ignore “colis bloqué / fuite de données” SMS.
  4. Phone hygiene: Be skeptical of unexpected voice calls about Relais Colis “identity verification.” Hang up and call a published support number you look up yourself.
  5. Email hygiene: If you reuse passwords across shopping accounts, rotate the ones that matter; enable MFA where available.
  6. Relay-point shops: Verify partner-portal reset emails out-of-band; watch for invoice fraud citing the leak rumor.
  7. Merchants: Brief support teams on refund and redelivery scams; hunt unusual contact-data exports on your own systems.
  8. Credit / identity: If you later receive a company or CNIL-linked letter naming you, follow that letter. Do not buy panic products sold via ads under “Relais Colis breach 2026.”
  9. Security teams elsewhere: Use the claim as a hunting trigger for odd CRM exports and partner-API abuse — not as automatic evidence your tenant is next.
  10. Journalists and analysts: Quote RandomRussian as an alleged listing. Prefer primary Relais Colis language if it appears. Stick to company notices, CNIL filings, and reputable monitors such as the DWI alert cited here — not Breachsense mirrors.

None of those steps require you to believe the dump. They are the same hygiene you would apply after any high-profile French logistics leak rumor: slow down, verify out-of-band, and do not let a forum poster set the incident narrative.

Canonical record and sources

BreachHistory indexes this incident as an unverified RandomRussian forum / dataset-leak claim against Relais Colis observed 24 September 2026, with actor body volume about 6.2 million lines (emails, phones, and other PII in claim language), a conflicting 12,976,743-line heading, spam promotion, credit to Miaouriarty, denial of original scraping, and no Relais Colis confirmation at indexing. Full catalog entry: https://breachhistory.com/relais-colis/relais-colis-randomrussian2026.

Primary open source for the claim language: Dark Web Informer — Actor Claims to Leak 6.2 Million Relais Colis Records. Related French and logistics context on BreachHistory includes pieces such as Alaxione’s unverified 6.8M patient claim, DGFiP’s confirmed tax-record incident, and CEVA Logistics customer-impact reporting — useful for pattern, not as proof of this Relais Colis dump.

If Relais Colis publishes a confirmation, denial with substance, or a regulator posts an attested census, the parent catalog row should be updated — and the unverified label revisited. Until then, the accurate one-line summary stays simple: RandomRussian claimed a ~6.2 million-line Relais Colis contact dump in September 2026 (with a conflicting ~12.9M heading); Relais Colis had not confirmed it.