2026 Declic Services — ZeroBytes; 6.27M rows / ~15k emails + IBANs; site defaced
Data compromised
Actor: identities, contacts, addresses, IBAN/RIB, password hashes, billing/service history, infra refs. ~14,947 unique emails / ~6,451 unique IBANs cited amid 6,271,531 raw rows (not one person per row).
Technical writeup
French personal-services cooperative Declic Services (declicservices.fr) experienced an information-system intrusion between August 10 and 14, 2026 per public reporting of the company notice. Actor ZeroBytes claimed ~6,271,531 raw SQL rows (~14,947 unique emails, ~6,451 unique IBANs, ~561 unique password hashes) and defaced the production website with sample data while accusing delayed CNIL notification. Chronologies differ on phishing-admin vs WordPress/ERP entry. recordsAffected uses the actor raw-row figure; unique-person counts are far lower. companyConfirmed true for the intrusion notice.
Root cause
Intrusion Aug 10–14, 2026 (company notice); ZeroBytes claims WordPress→ERP→DB path + production site defacement