Breach notifications from two French online merchants, Easypara and Frères Toque, were made public on August 29, 2026, and both point to a data analytics tool. Easypara says the breach happened at Shipup, the provider that sends its delivery-tracking messages, through a previously unknown vulnerability in Metabase, the analytics tool Shipup uses. Frères Toque, on the same day, cited “an external tool used to analyze its data,” without naming the software or any provider.
Both merchants say no payment data was involved, in different words. Easypara says “no banking data is affected.” Frères Toque says “no banking information, no login credentials and no passwords were compromised.” That rules out card fraud, but not the scams in which customers are talked into sending money themselves.
A tracking provider sat between Easypara’s customers and the flaw
The Easypara breach runs through three links. The merchant collects contact details at checkout. Shipup, which sends the shipping updates, receives the customer’s first and last name, email address and, where one was given, phone number, along with the order’s delivery details. Shipup uses Metabase to query that data. The flaw was in Metabase, it was exploited at Shipup, and it exposed Easypara’s customers. Frères Toque describes no such intermediary, and its notification lists other categories of data, including order history and postal address.
Easypara’s customers have no contract with Shipup or with Metabase’s developer. Under the GDPR, the merchant remains the data controller and answers to its customers for the breach, while Shipup is its processor under Article 28. Metabase adds no link to that contractual chain: it is analytics software that Shipup runs, and the flaw sits in the software. The merchant’s payment service provider appears nowhere in the chain, which is why no card data was among the exposed records.
Attackers used SQL injection on Metabase’s password-reset endpoint
SQL injection slips a fragment of a database query into a field meant to hold a value, so the database runs it as code. The Metabase flaw, tracked as CVE-2026-72898 according to The Hacker News, sits in the /api/session/reset_password endpoint. That endpoint has to be reachable without logging in, since it serves users who can no longer log in. Attackers inject SQL there and gain administrator access without ever presenting credentials, which is why the flaw carries a CVSS score of 10 out of 10.
The timeline shows how broad the campaign was. Security firm Wiz estimates that about 2,500 Metabase instances are reachable from the internet: roughly 13% of cloud environments run a self-hosted Metabase, and about a quarter of those are fully exposed. What neither French notification discloses is the number of people affected.
Order histories hand scammers a ready-made script
Order history is among the data Frères Toque says was exposed. A genuine purchase history tied to a phone number supports two authorized push payment scams. The first is the fake refund. The caller poses as the merchant’s customer service team, cites the exact order with its date and amount, reports a delivery problem and offers a refund that requires a few steps in the customer’s banking app. Those steps send a credit transfer to an account the fraudster controls.
The second is the fake delivery notice. A text or email claims customs or redelivery fees on a parcel the recipient really is expecting and includes a payment link. These campaigns work because the message matches what the recipient expects: they know a parcel is coming because they ordered it. Stolen tracking data supplies that match.
| Card payment data | Contact details and order history | |
|---|---|---|
| Can it be revoked? | A card on Cartes Bancaires CB, France’s domestic scheme, can be blocked and reissued within days. | A name, a phone number and a past order cannot be revoked. |
| Useful life | Until the card is blocked: hours to days. | Several months, with credibility fading as the order ages. |
| Fraud route | Unauthorized transaction, made without the cardholder. | Authorized transaction, initiated by a customer who was talked into it. |
| Customer recourse | Refund of the unauthorized transaction under Article L. 133-18 of the French Monetary and Financial Code. | No general right to a refund, since the customer consented. |
French law refunds unauthorized payments, not scams customers approve
Under Article 33 of the GDPR, the data controller must report a breach to the supervisory authority within 72 hours. Article 34 requires it to inform the people affected when the risk to their rights and freedoms is high. Frères Toque has notified the CNIL. The Easypara notification reported on August 29 does not mention a filing.
French payment law treats the two situations differently. An unauthorized transaction entitles the payer to a refund from its payment service provider under Article L. 133-18 of the Monetary and Financial Code. A transfer the customer authorized, even under manipulation, falls outside that regime. Since October 9, 2025, Regulation (EU) 2024/886 has required verification of payee, which compares the name the payer enters with the account holder’s name and flags a mismatch without blocking the transfer.