← LOREAL

2026 L'Oréal — Alinto SMTP relay metadata exposure in French email-provider leak

2026 40.0M records affected Share on X

Data compromised

SMTP transaction metadata (sender, recipient, timestamps, relay IPs)—not message content per Krebs-on-security-adjacent trade summaries echoed by TechRadar and Cybernews

Technical writeup

April 2026 specialist reporting traced a 40-million-record Elasticsearch leak at French email vendor Alinto to open SMTP logging metadata that indexed high-volume business correspondents—including L'Oréal, Renault, French government ministries, and diplomatic mailflows—without researchers finding full message bodies in the exposure. Security journalists emphasized spear-phishing and infrastructure-mapping risk flowing from relay topology rather than classic HR table dumps at L'Oréal itself. Consolidated SMTP-index figures in sector reporting hovered near ~40 million raw rows with approximately 4.5 million deduplicated email correspondents inferred by analysts surveying the leaked cluster—not equivalent to standalone L'Oréal HR breaches.

Root cause

Internet-exposed analytics cluster operated by a messaging supplier (misconfiguration / inadequate access control on SMTP telemetry)

References