← TeleCoop

2026 TeleCoop — Metabase auth bypass Aug 18–19; customer PII access confirmed (bank/ID disputed)

2026 Unknown records affected Share on X

Data compromised

Company: some customer personal data potentially accessed; company says bank data, passwords, and ID documents not in scope — actor claims 16,182 emails + IBAN/transactions/ID docs (unverified)

Technical writeup

Verified cooperative telecom notice with later actor claim — Cyberattaque.org August 25, 2026. TeleCoop confirmed its Metabase data-visualization platform was compromised August 18–19, 2026 after authentication was bypassed; French state services alerted the co-op the afternoon of August 19; a fix was deployed August 20. TeleCoop notified customers before the actor post and said banking data, passwords, and identity documents were not involved. Actor diable’fire (X-VDP-X) later claimed 15 databases / 2,661 tables / ~335MB including 16,182 emails, IBANs, bank transactions, OAuth tokens, passwords, and national ID documents — contradicting the company field list. recordsAffected 0 pending co-op census; companyConfirmed true for the Metabase incident.

Root cause

Metabase visualization platform authentication bypass Aug 18–19, 2026; state services alert Aug 19; patch Aug 20; X-VDP-X/diable’fire later claimed broader haul

References