Yves Rocher has been the victim of a data breach following a hacking attack on French consulting firm Aliznet. Personal information belonging to clients of companies that work with French firm Aliznet, including 2.5 million customers of cosmetics and beauty giant Yves Rocher, fell into the hands of hackers.
The Paris-based consultancy has previously served IBM, Salesforce, Sephora, Louboutin and Inwi. It should be noted that the most sensitive data belongs to Canadian customers of Yves Rocher.

The exposed database was discovered by vpnMentor on an unprotected Elasticsearch server after researchers working for the VPN review site discovered an unprotected API interface for an Aliznet application created for Yves Rocher. The researchers said the API gave them access to an explorer that hackers could use to add, delete, or modify data in the company's database.
Parallel to the customers' names, phone numbers, email addresses, birth dates and postal codes, the files contained the customers' identifiers, which could be used in combination with six million older Yves Rocher customer orders to locate further customers based on their purchases. The files also include the names of the employees who processed each order and the store location.

The researchers said that the leaked customer records could be exploited by hackers to carry out phishing schemes, ransomware , and bypass two-factor authentication. Cybercriminals could also gather the information to commit credit card and identity theft.
The leaked data also showed traffic , turnover, order volumes, product prices and promotional codes, alongside Aliznet's corporate information, including job postings and employee profiles.
The researchers added that the breach could be the beginning of evil and that there may be other unsecured databases and applications belonging to other Aliznet customers. It is not known whether the hackers managed to access the data or use it for malicious purposes.
