← Back to News
Fraud

Easypara and Frères Toque breaches point to analytics tools

Breach notices from two French online merchants, made public August 29, both trace the leak to analytics software. No card data leaked, but names, phone numbers and order histories are exactly what authorized push payment scammers need.

Breach notifications from two French online merchants, Easypara and Frères Toque, were made public on August 29, 2026, and both point to a data analytics tool. Easypara says the breach happened at Shipup, the provider that sends its delivery-tracking messages, through a previously unknown vulnerability in Metabase, the analytics tool Shipup uses. Frères Toque, on the same day, cited “an external tool used to analyze its data,” without naming the software or any provider.

Both merchants say no payment data was involved, in different words. Easypara says “no banking data is affected.” Frères Toque says “no banking information, no login credentials and no passwords were compromised.” That rules out card fraud, but not the scams in which customers are talked into sending money themselves.

July 31–Aug. 17
exposure window reported by Easypara
Cyberattaque.org, August 29, 2026
10 out of 10
CVSS score of Metabase flaw CVE-2026-72898
The Hacker News, August 8, 2026
2,500
Metabase instances reachable from the internet
Wiz, cited by The Hacker News, August 8, 2026
136
customer records taken from n8n
The Hacker News, August 8, 2026

A tracking provider sat between Easypara’s customers and the flaw

The Easypara breach runs through three links. The merchant collects contact details at checkout. Shipup, which sends the shipping updates, receives the customer’s first and last name, email address and, where one was given, phone number, along with the order’s delivery details. Shipup uses Metabase to query that data. The flaw was in Metabase, it was exploited at Shipup, and it exposed Easypara’s customers. Frères Toque describes no such intermediary, and its notification lists other categories of data, including order history and postal address.

Easypara’s customers have no contract with Shipup or with Metabase’s developer. Under the GDPR, the merchant remains the data controller and answers to its customers for the breach, while Shipup is its processor under Article 28. Metabase adds no link to that contractual chain: it is analytics software that Shipup runs, and the flaw sits in the software. The merchant’s payment service provider appears nowhere in the chain, which is why no card data was among the exposed records.

🔑
“No banking data” does not mean no payment fraud risk
Without card numbers, fraudsters cannot pay in the cardholder’s place. The breach does nothing to prevent authorized push payment fraud, in which customers send the transfer themselves after being persuaded to. That kind of fraud runs on verifiable details about a customer’s life, not on payment credentials.
A person looks at a data dashboard on a large computer screen.
Companies install Metabase, a data visualization tool, on their own servers to query their production databases.

Attackers used SQL injection on Metabase’s password-reset endpoint

SQL injection slips a fragment of a database query into a field meant to hold a value, so the database runs it as code. The Metabase flaw, tracked as CVE-2026-72898 according to The Hacker News, sits in the /api/session/reset_password endpoint. That endpoint has to be reachable without logging in, since it serves users who can no longer log in. Attackers inject SQL there and gain administrator access without ever presenting credentials, which is why the flaw carries a CVSS score of 10 out of 10.

July 31, 2026
Exposure window opens at Shipup
Easypara says unauthorized access to its customers’ contact details began on this date.
August 2, 2026
First publicly dated incident
Software maker Kilo Code says the intrusion lasted about four hours that day and that it was alerted four days later.
August 8, 2026
Exploitation becomes public
n8n reports that 136 customer records were taken, Framework that customer data was accessed, and Kilo Code that Slack tokens were exposed.
August 11, 2026
CISA adds the flaw to its Known Exploited Vulnerabilities catalog
The US agency sets August 14 as the patch deadline for federal agencies.
August 17, 2026
Exposure window closes at Shipup
Access is shut off nine days after the flaw became public.
August 29, 2026
Notifications made public
Both notifications are reported the same day. Frères Toque says it notified the CNIL, France’s data protection authority.

The timeline shows how broad the campaign was. Security firm Wiz estimates that about 2,500 Metabase instances are reachable from the internet: roughly 13% of cloud environments run a self-hosted Metabase, and about a quarter of those are fully exposed. What neither French notification discloses is the number of people affected.

Order histories hand scammers a ready-made script

Order history is among the data Frères Toque says was exposed. A genuine purchase history tied to a phone number supports two authorized push payment scams. The first is the fake refund. The caller poses as the merchant’s customer service team, cites the exact order with its date and amount, reports a delivery problem and offers a refund that requires a few steps in the customer’s banking app. Those steps send a credit transfer to an account the fraudster controls.

The second is the fake delivery notice. A text or email claims customs or redelivery fees on a parcel the recipient really is expecting and includes a payment link. These campaigns work because the message matches what the recipient expects: they know a parcel is coming because they ordered it. Stolen tracking data supplies that match.

Card payment dataContact details and order history
Can it be revoked?A card on Cartes Bancaires CB, France’s domestic scheme, can be blocked and reissued within days.A name, a phone number and a past order cannot be revoked.
Useful lifeUntil the card is blocked: hours to days.Several months, with credibility fading as the order ages.
Fraud routeUnauthorized transaction, made without the cardholder.Authorized transaction, initiated by a customer who was talked into it.
Customer recourseRefund of the unauthorized transaction under Article L. 133-18 of the French Monetary and Financial Code.No general right to a refund, since the customer consented.
Two kinds of data, two kinds of risk
Close-up of a person on a phone call, handset held to the ear.
A scam call borrows its credibility from the order details the caller can recite.

French law refunds unauthorized payments, not scams customers approve

Under Article 33 of the GDPR, the data controller must report a breach to the supervisory authority within 72 hours. Article 34 requires it to inform the people affected when the risk to their rights and freedoms is high. Frères Toque has notified the CNIL. The Easypara notification reported on August 29 does not mention a filing.

French payment law treats the two situations differently. An unauthorized transaction entitles the payer to a refund from its payment service provider under Article L. 133-18 of the Monetary and Financial Code. A transfer the customer authorized, even under manipulation, falls outside that regime. Since October 9, 2025, Regulation (EU) 2024/886 has required verification of payee, which compares the name the payer enters with the account holder’s name and flags a mismatch without blocking the transfer.

⚠️
Gaps in both notifications
Frères Toque has not named the tool involved, the date of the intrusion or how the attacker got in. Neither company has said how many customers were affected. For Frères Toque, the link to the Metabase campaign rests only on the matching timing and method.

Provenance

Published August 30, 2026

4 sources, 3 distinct domains

↗ Cyberattaque.org, “Easypara: Metabase flaw at its provider exposes some customers’ contact details” (in French), August 29, 2026 · cyberattaque.org↗ Cyberattaque.org, “Frères Toque: customer data and order histories exposed after cyberattack” (in French), August 29, 2026 · cyberattaque.org↗ FrenchBreaches, data breach archive (Easypara and Frères Toque, August 29, 2026) · frenchbreaches.com↗ The Hacker News, “Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication,” August 8, 2026 · thehackernews.com
← All news