Carrefour has informed some of its customers that their personal information, including first and last names, email addresses, and phone numbers, was leaked due to a security breach at a third-party provider. The company did not name the provider, but two specialized websites suggest it may be Shipup, a company previously linked to similar data leaks involving Micromania and Easypara. In an email titled "Important Information Regarding Your Personal Data," Carrefour confirmed that the breach occurred at one of its third-party providers. It clarified that passwords or financial details were not compromised in the incident. The breach is linked to Metabase, a software that provides parcel tracking services for many online retailers, including Shipup. According to Cyberattaque.org and FrenchBreaches, the vulnerability was found in Metabase, a tool used for analyzing database systems. This specific vulnerability, labeled as CVE-2026-72898, allowed an attacker to access a system without needing any login credentials. The breach occurred between July 31 and August 17, 2026, at other Shipup clients, but Carrefour has not specified the time frame or the number of customers affected in its case. The exact amount of data accessed remains unknown. Carrefour stated that its own website, customer accounts, and internal systems were not compromised. The breach only involved data shared with the third-party provider, which claims to have taken the necessary steps to address the situation. Shipup collaborates with more than 700 brands, meaning that a single vulnerability can affect multiple retailers without them being directly hacked. Other companies affected by similar breaches include Printemps, Citadium, Aroma-Zone, and Afpa, according to FrenchBreaches. In September, a similar incident involving Afpa exposed up to 1.7 million files due to a vulnerability at a third-party publisher. While the leaked data cannot be used to access a Carrefour account directly, it can make phishing attempts more convincing. A fraudster with your name, email, and phone number could impersonate the retailer or a delivery service and trick you with references to an order or refund. Earlier in the month, a fake letter mimicking the design of the DGFiP (France’s tax authority) targeted people affected by the Colis Privé data leak. A single QR code was enough to direct victims to a phishing site. Customers with questions can contact Carrefour at droitsdespersonnes@serviceclients-carrefour.com.