started · updated
Micromania customers' data breached via third-party provider
Micromania has notified its customers of a security incident involving the theft of personal data. The breach occurred through a technical service provider responsible for parcel tracking and delivery notifications. The unauthorized access took place between July 31 and August 17, 2026.
While Micromania did not initially name the partner, reports identify the provider as Shipup, a French company specializing in post-purchase customer experience. The cyberattack exploited a global security vulnerability (CVE-2026-72898) in Metabase, an open-source data analysis and visualization software used by the provider.
The compromised information includes customer names, first names, email addresses, and telephone numbers. Micromania stated that passwords and banking details were not affected, as this sensitive information is not shared with the third-party provider. The company has notified the CNIL in accordance with regulatory requirements.
Entities
CNIL · Metabase · Micromania · Shipup