2026 L'Oréal — Alinto SMTP relay metadata exposure in French email-provider leak
Data compromised
SMTP transaction metadata (sender, recipient, timestamps, relay IPs)—not message content per Krebs-on-security-adjacent trade summaries echoed by TechRadar and Cybernews
Technical writeup
April 2026 specialist reporting traced a 40-million-record Elasticsearch leak at French email vendor Alinto to open SMTP logging metadata that indexed high-volume business correspondents—including L'Oréal, Renault, French government ministries, and diplomatic mailflows—without researchers finding full message bodies in the exposure. Security journalists emphasized spear-phishing and infrastructure-mapping risk flowing from relay topology rather than classic HR table dumps at L'Oréal itself. Consolidated SMTP-index figures in sector reporting hovered near ~40 million raw rows with approximately 4.5 million deduplicated email correspondents inferred by analysts surveying the leaked cluster—not equivalent to standalone L'Oréal HR breaches.
Root cause
Internet-exposed analytics cluster operated by a messaging supplier (misconfiguration / inadequate access control on SMTP telemetry)
References
- https://www.techradar.com/pro/security/french-email-provider-accidentally-leaked-40-million-records-loreal-renault-french-government-data-exposed
- https://cybernews.com/security/alinto-email-data-leak-exposes-traffic/
- https://www.scworld.com/brief/misconfiguration-spills-over-40m-smtp-records-linked-to-major-firms