Maison Gannac Customer Data Quietly Surfaced on Dark Web Last October
Sometime in October 2024, a dataset containing customer records from Maison Gannac -- a French eCommerce food and citrus products website operating at lamaisonducitron.com -- appeared in underground data circles. There was no headline announcement, no public disclosure, and no breach notification that reached the affected customers. The data simply surfaced: 11,001 records containing email addresses, first names, and last names. Quietly and without fanfare, the personal information of over eleven thousand people changed hands.
Why This Is Dangerous
Silent breaches are often more damaging than publicized ones. When customers are not notified, they cannot take protective action. They continue using the same passwords, the same email addresses, and the same accounts -- unaware that their details are already circulating on dark web forums. For a French-language eCommerce platform, the exposed name-and-email combinations are particularly valuable for actors running localized phishing campaigns in French, which are harder for recipients to identify as fraudulent.
What Was Exposed
- Email addresses -- used for phishing, account targeting, and credential stuffing across other services
- First names -- used to personalize phishing messages and social engineering attempts
- Last names -- combined with email and first name to build full identity profiles and impersonate individuals
Why This Matters
The combination of full name and email address is more dangerous than it may appear. Attackers use this data to:
- Craft convincing phishing emails addressed by name, appearing to come from Maison Gannac or affiliated services
- Attempt account takeovers on any platform where the same email is registered
- Build identity profiles by merging this dataset with other leaked records containing addresses or payment data
- Enable fraud by impersonating customers in customer service contexts or account recovery flows
How a Database Breach Works
A database breach occurs when attackers gain unauthorized access to the backend systems storing customer data and extract records in bulk. For eCommerce platforms, common attack methods include SQL injection, compromised administrative credentials, and unpatched software vulnerabilities in content management or shopping cart systems. The structured nature of the Maison Gannac leak -- containing consistent, clean fields of name and email -- points to a direct database table extraction rather than opportunistic web scraping. Once exported, such datasets are typically distributed through private channels or posted to underground forums with no public announcement.
Check If You Are Affected
HEROIC's dark web monitoring database indexes over 400 billion exposed records from breaches around the world, including quiet incidents like the Maison Gannac leak that never made public headlines. If your email or name appeared in this dataset, you deserve to know. Search the HEROIC database now -- and if you are listed, update your passwords and watch your inbox for suspicious messages.
Breach Breakdown
11,001 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds