Security · October 2, 2026
Also published in Português (Brasil)
Carrefour confirms customer data exposure following Shipup breach
Carrefour has confirmed that personal data belonging to some of its customers was exposed due to a security incident at its delivery tracking provider, Shipup. The retailer notified affected individuals that their names, email addresses, and phone numbers were compromised in the breach. The company stated that no banking information or passwords were accessed, and there is no evidence of an intrusion into Carrefour's own information systems. This incident follows similar data exposures reported by other retailers, including Micromania, Easypara, and Printemps, all linked to the same vulnerability at Shipup.
The breach at Shipup, a French provider of post-purchase tracking and delivery notification services used by more than 700 brands, resulted from the exploitation of a critical vulnerability in Metabase. Metabase is an open-source platform for data analysis and visualization widely used in corporate environments. The specific flaw allowed a remote attacker to access vulnerable instances without requiring prior authentication. Cybersecurity monitoring specialists, including FrenchBreaches and Cyberattaque.org, attributed the incident to this specific software weakness, which enabled unauthorized access to the data stored by the service provider.
The incident highlights the cascading effects of software vulnerabilities in shared service environments. A single compromise at a shared software as a service provider can expose the data of hundreds of client companies simultaneously, even if none of those companies were directly targeted by the attack. This scenario illustrates the limitations of traditional security perimeters, where investments in protecting internal infrastructure may be bypassed when data is entrusted to external partners handling essential business functions such as logistics or customer relations. Carrefour acknowledges in its risk management documentation that the complexity of interconnected systems with suppliers and partners can amplify the impact of cyberattacks and lead to personal data leaks.
The retailer indicated that it relies on a global security operations center, a vulnerability management program, and a cybersecurity governance framework based on the NIST reference standard. The broader trend of cybercriminals targeting intermediate digital service providers allows attackers to access data from dozens or hundreds of client companies in a single operation. For Carrefour, the primary ongoing risk is the potential exploitation of the exposed information in targeted phishing campaigns. Attackers possessing a customer's name, email address, and phone number can construct highly credible fraudulent messages by impersonating the retailer or a transport carrier.