2026 Vanden Borre (Belgium) — alleged dark-web customer dataset (~264k rows; authenticity disputed)
Data compromised
Emails, contact info, order and support-ticket artefacts per forum/OSINT summaries—scope disputed
Technical writeup
In May 2026, Belgian retail-security chatter on X/Twitter and specialist breach trackers described a criminal-forum listing marketing a Vanden Borre customer dataset on the order of ~264,000 rows, with claimed fields such as contact details, email addresses, job titles, order history, and support-ticket content. BreachHistory indexes the OSINT marketing figure while stressing that Vanden Borre had not issued a detailed public forensic bulletin matching every field class in indexed English/French summaries at catalog time—overlap with older retail leaks or repackaged databases must be ruled out before treating the dump as a fresh 2026 intrusion. Consumers should still watch for Belgian-language phishing referencing recent electronics orders.
Root cause
Alleged external exfiltration or reseller dump per underground marketing; corporate confirmation pending