Back to the news
Fraude

Easypara and Frères Toque notify customers: an analytics tool at the root, no banking data

Two breach notifications made public on 29 August 2026 both point to a data analytics tool, Metabase at Easypara’s service provider, an unnamed external tool at Frères Toque. Both merchants say no banking data was involved, which rules out card fraud and leaves authorised push payment fraud untouched.

Networks mentionedCB

Two French merchants had their breach notifications made public on 29 August 2026, and both point to a data analytics tool. Easypara names Shipp, the provider that sends delivery-tracking messages on its behalf. The merchant traces the incident to a previously unknown vulnerability in Metabase, the analytics tool Shipp uses. Frères Toque, on the same day, refers to "an external tool used to analyse its data", naming neither the software nor a provider. Both notifications rule out banking data, in different words. Easypara says "no banking data is affected"; Frères Toque says "no banking information, no login credentials and no passwords were compromised".

31 July – 17 August
exposure window declared by Easypara
Cyberattaque.org, 29 August 2026
10 out of 10
CVSS score of the Metabase flaw CVE-2026-72898
The Hacker News, 8 August 2026
2,500
Metabase instances reachable from the internet
Wiz, quoted by The Hacker News, 8 August 2026
136
customer records taken from n8n
The Hacker News, 8 August 2026

At Easypara, a provider between the buyer and the flaw

The chain in question at Easypara has three links. The merchant collects contact details when the order is placed. The notification provider, which handles shipping updates, receives the customer’s first and last name, the email address and, where it was given, the phone number, together with the delivery context of the order. The analytics tool that provider uses queries those records. The flaw sits in that tool, it was exploited at the provider, and it exposes the merchant’s customers. Frères Toque describes no such intermediary, and its notification lists other categories, including the order history and the postal address.

An Easypara buyer has no contract with Shipp or with the publisher of Metabase. Under the GDPR, the merchant remains the data controller and answers to its customers for the leak, while Shipp is its processor under Article 28. Metabase adds no further link to that contractual chain, because it is analytics software that Shipp uses, and the flaw sits in that software. The merchant’s payment service provider appears nowhere in the chain, which explains why no card data figures among the exposed records.

🔑
"No banking data", and what the sentence does not cover
The absence of a card number rules out fraud by stolen instrument, where the fraudster pays in the cardholder’s place. It leaves authorised push payment fraud untouched, where the customer sends the transfer after being talked into it. This second family feeds on verifiable details about the customer’s life rather than on payment credentials.
A person reviews a data dashboard displayed on a large computer screen.
Metabase is a visualisation tool that companies install on their own servers to query their production databases.

An SQL injection on the forgotten-password endpoint

SQL injection means slipping a fragment of a query into a field meant to hold a value, so the database runs it as code. The Metabase vulnerability, referenced CVE-2026-72898 by The Hacker News, affects the /api/session/reset_password endpoint. That endpoint stays reachable without authentication by design, because it serves the person who can no longer log in. The attacker injects SQL there and gains administrator access without ever presenting a credential, which earns the flaw a CVSS score of 10 out of 10.

31 July 2026
Exposure window opens at Shipp
Easypara says the access to its customers’ contact details began on this date.
2 August 2026
First publicly dated incident
Kilo Code places the intrusion within roughly four hours on that day, and says it was alerted four days later.
8 August 2026
Exploitation made public
n8n reports 136 customer records taken, Framework an access to customer data, Kilo Code exposed Slack tokens.
11 August 2026
Added to the US catalogue of exploited flaws
CISA sets 14 August as the remediation deadline for federal agencies.
17 August 2026
Window closes at Shipp
Nine days had passed since the flaw was made public.
29 August 2026
Notifications made public
Both notifications were relayed on the same day. Frères Toque says it reported the incident to the CNIL, the French data protection authority.

The calendar puts the event on a scale. Wiz counts about 2,500 Metabase instances reachable from the internet, across the 13% of cloud environments running the tool self-hosted, a quarter of which are fully exposed. The figure missing from both French notifications is the number of people affected.

What an order history is worth to a fraudster

The order history is one of the categories Frères Toque says were exposed. A genuine purchase history tied to a phone number feeds two authorised push payment scams. The first is the fake refund. The caller poses as the merchant’s customer service team, quotes the exact order with its date and amount, reports a delivery problem, then offers a refund that takes a few steps inside the banking app. Those steps send a credit transfer to an account the fraudster controls.

The second scam is the fake delivery notice. A message claims customs or redelivery charges on a parcel the recipient really is waiting for, with a payment link. These campaigns pay off because the message matches what the recipient expects, since the parcel is on its way and the recipient ordered it. Stolen tracking data supplies that match.

Card payment dataContact details and order history
RevocabilityA CB CB card number can be blocked and the card reissued within days.A name, a phone number and a past order cannot be revoked.
Useful lifeUntil the card is blocked, so hours to days.Several months, with credibility fading as the order ages.
Fraud routeUnauthorised transaction, executed without the cardholder.Authorised transaction, initiated by the customer who was talked into it.
Customer remedyRefund of the unauthorised transaction, Article L. 133-18 of the French Monetary and Financial Code.No general right to a refund, since the customer gave consent.
Two kinds of data, two risk regimes
Close-up of a person on a phone call, handset held to the ear.
The fraudulent call borrows its credibility from the accuracy of the order details the caller can quote.

The French legal framework

The GDPR requires the data controller to report a breach to the supervisory authority within seventy-two hours under Article 33. Article 34 requires it to inform the individuals concerned when the risk to their rights and freedoms is high. Frères Toque has filed with the CNIL. The Easypara notification relayed on 29 August mentions no such filing.

French payment law separates the two situations described above. An unauthorised transaction gives the payer a right to a refund from the payment service provider under Article L. 133-18 of the Monetary and Financial Code. A credit transfer the customer authorised personally, even under manipulation, falls outside that regime. Since 9 October 2025, Regulation (EU) 2024/886 has required verification of payee, which compares the name the payer types with the account holder’s name and flags a mismatch without blocking the transfer.

⚠️
What the notifications leave out
Frères Toque named neither the tool involved, nor the date of the intrusion, nor the access method used. Neither company disclosed how many customers were affected. Linking these cases to the Metabase campaign rests, for Frères Toque, on nothing more than a matching date and method.

Provenance

Published on 30 August 2026

4 sources, 3 distinct domains

Cyberattaque.org, “Easypara : une faille Metabase chez son prestataire expose les coordonnées de certains clients”, 29 August 2026 · cyberattaque.orgCyberattaque.org, “Frères Toque : données clients et historiques de commandes exposés après une cyberattaque”, 29 August 2026 · cyberattaque.orgFrenchBreaches, data-breach archive (Easypara and Frères Toque, 29 August 2026) · frenchbreaches.comThe Hacker News, “Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication”, 8 August 2026 · thehackernews.com
All news