Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
underground-data-leakmass-credential-exposureleaked-secret-api-keyfinancial-sector-threat

Dark Web Leak Claims Target Colis Privé and Multiple Online Services

Updated 3mo agoFirst seen Jan 20, 20262 sources

Dark web monitoring reports described unverified data leak claims involving several organizations, including French parcel delivery firm Colis Privé. One post on BreachForums allegedly offered an upload of 22,564,381 records attributed to Colis Privé, described as .jsonl files totaling ~4.1 GB; no specific threat actor attribution or company confirmation was cited, and the notice characterized the situation as informational while scope is assessed. If authentic, the scale and format of the dataset would materially increase risk of identity theft, credential stuffing, and targeted phishing against customers.

Separate dark web forum posts also alleged database exposures affecting JobsGO (Vietnam recruitment platform), MyVete (veterinary management platform), PIXPAY (Senegalese payment service), and Groupe Fondasol (France-based engineering). The claimed datasets reportedly include CV/personal records, and in some cases API credentials and employee metadata, with example figures including ~2.3 million records for JobsGO and ~5.57 million records for MyVete (verification not indicated). Across the claims, the primary business risk is downstream abuse of exposed personal and operational data for social engineering, recruitment fraud, and account takeover, rather than immediate exploitation of a specific software vulnerability.

Share:
Dark Web Leak Claims Target Colis Privé and Multiple Online Services
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Jan 30, 20265mo ago

MyVete ransom deadline is set for end of January

The actor behind the alleged MyVete leak reportedly set January 30, 2026 as the deadline for payment of a $100,000 ransom before selling the data. This marked an escalation from a leak claim to an extortion demand with a stated cutoff date.

Jan 19, 20265mo ago

UpGuard flags Colis Privé incident as informational

UpGuard published a notice on the alleged Colis Privé breach and categorized it as informational while the scope and exposed data types were still being assessed. The report noted potential downstream risks such as phishing, credential stuffing, unauthorized account access, and identity theft.

SOCRadar reports multiple new leak claims

SOCRadar's Dark Web Team published a roundup identifying new leak claims involving JobsGO, MyVete, PIXPAY, and Groupe Fondasol. The report said some samples were shared to support the allegations, but the claims remained unverified.

Employee dataset leak is alleged for Groupe Fondasol

A dark web post alleged that France-based Groupe Fondasol had an employee CSV dataset exposed containing records for 888 employees. The claimed data included contact details and access-related metadata that could support targeted social engineering.

Dark web claims surface against PIXPAY

A dark web leak claim alleged that Senegalese payment service PIXPAY exposed JWTs, API keys, access tokens, and database credentials. The actor used the LAPSUS$ name for attribution, but this was not independently verified.

Jan 15, 20265mo ago

Colis Privé breach claim is disclosed on BreachForums

On January 15, 2026, a BreachForums user allegedly uploaded a dataset tied to French parcel delivery service Colis Privé. The post claimed to contain 22,564,381 records in .jsonl files totaling about 4.1 GB, though the exposed data types and responsible actor were not confirmed.

Jan 12, 20265mo ago

MyVete data dump is allegedly posted

A dark web claim dated January 12, 2026 alleged that veterinary management platform MyVete had a data dump of about 5.57 million records totaling roughly 30 GB. The actor reportedly threatened to sell the data unless a $100,000 ransom was paid.

Jan 1, 20266mo ago

JobsGO leak claim emerges on dark web

A dark web post alleged that Vietnam-based recruitment platform JobsGO suffered a data leak in early January 2026 affecting about 2.3 million records. The claimed data reportedly included detailed personal and professional information that could enable phishing, recruitment fraud, and identity abuse.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
Threat actors
1 linked
Organizations
5 linked
SOCRadarJobsGOPIXPAYMyVeteGroupe Fondasol
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.