A threat actor using the alias "misere" is offering what they claim is Bureau Vallée customer data allegedly obtained from a third-party supplier rather than the retailer itself. The seller claims the supplier exported customer data for each store daily to an unprotected external server or FTP service hosted outside France, yielding 13,725,669 total records and 4,819,927 unique records. A 10,000-record sample was reportedly published, but no field list was disclosed and the claims remain unverified.
The actor further alleges they exploited injection flaws on internet-facing systems to achieve command execution and maintain persistent access for about a month, with access still active at the time of posting. If confirmed, the incident would reflect a trusted-relationship/supply-chain compromise in which a downstream organization is exposed through a service provider’s insecure workflow, a pattern seen in broader intrusions involving managed service providers, cloud partners, and software suppliers such as SolarWinds, where compromise of an intermediary enabled access to multiple customer environments.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
On August 21, 2026, the "misere" forum listing offering alleged Bureau Vallée customer data was observed. The seller claimed 13,725,669 total records, reduced to 4,819,927 unique records, and reportedly published a 10,000-record sample.
The SolarWinds Orion supply-chain attack was disclosed in December 2020. Reporting described trojanized Orion builds, SUNBURST activity, and broad downstream impact across U.S. government and private-sector victims.
The SolarWinds Orion compromise began being exploited in spring 2020, using trojanized Orion software updates to deliver the SUNBURST backdoor to victims. The campaign affected government and private-sector organizations worldwide.
A forum user using the alias "misere" claimed to have exploited injection flaws in a third-party supplier environment, gained command execution, and maintained persistent access for about a month. The actor alleged the supplier exported Bureau Vallée customer data daily to an unprotected external server hosted outside France.
SUPERNOVA was identified in Orion artifacts as a webshell enabling arbitrary code execution on affected machines. Microsoft assessed it was likely the work of a different adversary than the actor behind the FireEye and U.S. government intrusions.
SolarWinds released Orion version 2020.2.1 HF 2 as a fix for the compromised update chain affecting specific Orion versions. The release was presented as the remediation for the supply-chain compromise.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
darkwebinformer.com
Open sourcedarkwebinformer.com
Open sourcecyfirma.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.